Key details for this exam, checked against the published exam outline
Each question shows the correct answer and an explanation of why it is right
Adam, an Admin, created a rule to provide birthright access; however, the access should be deprovisioned when the condition fails. Which of the following options should be applied for this scenario?
To automatically deprovision birthright access when the defining condition fails, the correct option is C. Remove the birthright Access if the condition fails under the created Rule. Here's a detailed explanation:
Saviynt's Birthright Access (Automatic Provisioning): Saviynt allows administrators to define rules that automatically grant access (birthright access) based on user attributes or other criteria (e.g., new hires in a specific department automatically get access to certain applications).
Rule-Based Access Management: These rules are a core part of Saviynt's access management capabilities, allowing for dynamic and automated provisioning.
'Remove the birthright Access if the condition fails': This option, typically found within the birthright rule configuration itself, is crucial for ensuring that access is revoked when the conditions that granted it are no longer met.
Example: If a user is granted access to an application because they are in the 'Sales' department, and they are later moved to the 'Marketing' department, the condition for the birthright rule would fail, and Saviynt would automatically deprovision the access.
Saviynt's Continuous Monitoring: Saviynt continuously monitors user attributes and rule conditions. When a change occurs that causes a condition to fail, the deprovisioning action is triggered.
Other Options:
A . Remove the Access Rule: This would remove the entire rule, preventing it from granting access to anyone, not just the user whose condition has failed.
B . Apply a new Technical Rule to remove the Access: While technically possible, it's less efficient and more complex than using the built-in option within the birthright rule.
D . Use the Request Rule: Request Rules are for access requests, not for automatically provisioning or deprovisioning birthright access.
The Max Authentication Session parameter in Single Sign-On settings specifies the maximum duration, in seconds, for which an SSO session will remain valid. The default value is 3600 seconds. If the session logout value defined in IDP is 10,000 seconds and Max Authentication Session in Saviynt SSO is 5000 seconds, how long will the session last?
In Saviynt's SSO setup, the 'Max Authentication Session' parameter determines the maximum duration of an SSO session within Saviynt, overriding any longer durations set by the Identity Provider (IdP).
Session Duration Logic: Saviynt's internal session timeout setting takes precedence over the IdP's session timeout. This ensures that Saviynt can enforce its own security policies regarding session lifetimes.
Why other options are incorrect:
B . 10,000 seconds: This is the IdP's session logout value, but Saviynt's 'Max Authentication Session' setting overrides it.
C . 3600 seconds: This is the default value, but the question specifies a configured value of 5000 seconds.
Saviynt IGA Reference:
Saviynt Documentation: The documentation for configuring SSO settings within Saviynt explains the 'Max Authentication Session' parameter and its impact on session duration.
Saviynt Best Practices: Saviynt's best practices for SSO often recommend aligning session timeouts between the IdP and Saviynt to avoid confusion and potential security gaps.
As an Admin, you are required to set up an Entitlement Owner Campaign for Entitlements belonging to an Oracle ERP Endpoint by the Internal Audit team. The Campaign should be launched at the beginning of every month, and only Accounts and Entitlements that meet the prerequisites should be included in the Campaign.
Which of the following 2-key configurations would you recommend for achieving this?
To set up an Entitlement Owner Campaign for Entitlements belonging to an Oracle ERP Endpoint that launches at the beginning of every month, and includes only Accounts and Entitlements that meet the prerequisites, the 2-key configurations you should recommend are A . Use Campaign Template and the Schedule Later option. Here's a breakdown:
Campaign Template:
Purpose: Templates allow you to save a set of campaign configurations as a reusable template. This is ideal for recurring campaigns with consistent settings.
Benefits: Using a template saves time and ensures consistency across multiple campaign instances. You can define the scope (Oracle ERP Endpoint), Certifier type (Entitlement Owners), and other settings within the template.
Prerequisites: You can include logic within the template to filter for Accounts and Entitlements that meet the defined prerequisites.
Schedule Later option:
Purpose: This option allows you to schedule the campaign to launch at a specific date and time in the future.
Recurring Scheduling: You can configure the campaign to run on a recurring schedule, such as the beginning of every month.
Automation: This automates the campaign launch process, eliminating the need for manual intervention each month.
Why Other Options Are Less Suitable:
B . Use Advanced Configurations and Preview mode and create the Campaign at the beginning of each month: This approach is manual and prone to errors. It doesn't leverage the automation benefits of templates and scheduling.
C . Use Advanced Configurations and set the Campaign expiry to 31 days: While setting an expiry is important, it doesn't address the need for recurring monthly launches or using a template for consistent configuration.
D . Cannot be achieved: This is incorrect; the scenario can be easily achieved using Campaign Templates and the Schedule Later option.
What is the maximum file attachment limit for a request?
The maximum file attachment limit for a request in Saviynt is typically 10. Here's an explanation:
Saviynt's Access Request System (ARS): The ARS allows users to attach files to access requests to provide supporting documentation or justification.
Attachment Limits: To prevent excessive storage usage and potential performance issues, Saviynt imposes limits on the number and size of attachments allowed per request.
Default Limit: The default maximum number of attachments allowed per request in Saviynt is generally 10.
Configuration: While 10 is the common default, it's worth noting that this limit might be configurable within the ARS settings in some Saviynt deployments. However, significantly increasing this limit could impact performance.
File Size Limit: In addition to the number of attachments, there's also usually a limit on the individual file size and the total size of all attachments combined. This is also generally configurable. These file size limits are important for maintain system stability and performance.
Error Handling: If a user attempts to exceed the attachment limit, Saviynt will typically display an error message, preventing them from submitting the request until the number of attachments is reduced.
Accounts, Entitlement types, and Entitlement data of an application are directly associated with:
In Saviynt, Endpoints represent the systems or applications that Saviynt manages. Accounts, entitlement types, and entitlement data are all directly associated with these endpoints because they define how access is structured and granted within those specific systems.
Endpoints as the Foundation: Endpoints are the core objects in Saviynt's identity governance framework. They provide the context for managing access, as all entitlements and accounts exist within the context of a specific endpoint (application or system).
Why other options are incorrect:
Roles: Roles are collections of entitlements, but they are not the primary object that accounts and entitlements are directly linked to.
Workflows: Workflows are processes, not the systems or applications themselves.
Security Systems: While related to security, this term is too broad and doesn't specifically refer to the systems being managed.
Saviynt IGA Reference:
Saviynt Documentation: The section on Application Onboarding and Endpoint Management in Saviynt's documentation clarifies the role of endpoints as the central objects for managing access.
Saviynt User Interface: When configuring applications or systems in Saviynt, you define them as endpoints, and all related accounts and entitlements are managed within that endpoint's context.
60 questions covering all exam domains, starting from $20
Exam domains verified against: Official Saviynt SAVIGA-C01 exam guide, last checked September 2026.
Measures skills of Saviynt IGA Administrators. Covers understanding the ARS workflow, configuring access requests, and managing approvals. Candidates should be able to set up and customize ARS for organizational needs and implement effective access request processes.
Sample question from this domain above: Q2
Covers user management, role management, and system configuration. Administrators must demonstrate proficiency in administering the Saviynt IGA platform and managing core system functions.
Sample question from this domain above: Q1
Focuses on data modeling, identity reconciliation, and data synchronization. Candidates should understand how to design and maintain the identity warehouse that supports IGA operations.
Covers deployment strategies, integration with existing systems, and customization techniques. Candidates should be able to plan and execute implementation projects effectively.
Includes reporting, dashboards, and data analysis techniques. Candidates should be able to extract insights from system data and communicate results through appropriate tools.
Sample question from this domain above: Q4
Covers campaign management, reviewer workflows, and remediation procedures. Candidates should be able to set up and manage effective access review campaigns to ensure ongoing compliance.
Focuses on system components, integration points, and deployment models. Candidates should understand how Saviynt IGA components work together and how to architect solutions.
Covers installation procedures, upgrades, and ongoing maintenance tasks including Segregation of Duties (SoDs). Candidates should be able to manage the operational lifecycle of Saviynt IGA systems.
Includes project planning and requirements gathering. Candidates should be able to initiate and plan IGA implementation projects with clear objectives and scope.
Candidates should translate business needs into technical solutions. This domain bridges the gap between business requirements and technical implementation strategy.
Covers joiner-mover-leaver processes, role-based access control, and privileged access management. Candidates should be able to configure and manage the most common IGA scenarios.
Common questions about the exam itself