Knowledge Article

Identity Security Engineer Exam Prep Guide

Author

  • dania_mourtada

    SailPoint

Identity Security Engineer Exam Prep Guide

Introduction

Candidates for the Identity Security Engineer Certification exam will be configuring and deploying Identity Security Cloud. They will have a general understanding of Identity Governance and Administration (IGA), Identity and Access Management (IAM), Identity Security Cloud architecture, configurations, and best practices. Candidates should also demonstrate a thorough understanding of the various components of Identity Security Cloud, which will enable them to implement and configure the integrated components of a solution. This audience typically includes individuals working on Identity Security Cloud deployments, such as Identity architects, Cloud Deployment engineers, and IGA / IAM developers.

As this is a role-based certification exam, approximately 1-3 years of hands-on experience in the industry is recommended before taking this exam. All candidates are recommended to complete the Identity Security Engineer training path through Identity University prior to taking the exam.

Exam Information

The exam consists of 73 discrete option multiple-choice questions (DOMC). The exam is online and proctored. The exam seat time is up to 120 minutes, and you must complete the entire exam in one sitting. Upon exam submission, you will receive a Pass/Fail decision. You will automatically have one exam retake available.

The exam will automatically end once you have answered enough questions correctly or incorrectly, meaning all exam questions may not be presented to you. Once you reach the threshold of correct or incorrect number of questions answered, you will automatically receive a pass or fail result. Therefore, you might complete your exam in less than 120 minutes. Please note that you cannot go back and change your answers once a question has been submitted. You will not be able to flag questions for further review.

Exam Name

SailPoint Identity Security Engineer Certification

Total Seat Time

Up to 120 minutes

Number of Questions

Up to 73

Number of Attempts

2 attempts

Format

Online & Proctored

Discrete Option Multiple Choice (DOMC) Format

This exam contains Discrete Option Multiple-Choice questions. Such questions start by displaying a prompt for you to read. When you have finished reading the prompt, click “Show me an option.” A single option that contains some information will be presented to you. If you decide that the information is correct, click “Yes,” otherwise click “No.” You will not be able to change your answer after clicking “Yes or “No.”

You may be presented with additional options, one at a time, before the system moves to the next question. The number of options you see will vary from one question to the next, depending on a number of factors.

If this is your first time taking a DOMC exam, we strongly recommend you familiarize yourself with this testing format prior to taking the exam by reviewing this Compass page.

Preparing for the Exam

The exam blueprint below details all the topics assessed during the exam. Visit documentation.sailpoint.com to research the material covered in the exam blueprint below. We recommend you look up the terms found in the exam blueprint and study their documentation pages. Additionally, you can search for any upcoming or past Webinars and Events on any of the topics covered in the exam.

Please note that this is a role-based certification, and thus your professional work experience is crucial in order to pass this exam.

Additional Resources

Score Report

At the end of the exam, you will receive a score report. This score report will help you understand your strengths and weaknesses on the exam content. The percentage displayed is the number of questions you answered correctly in that exam section. The lower the percentage, the more incorrect questions you answered on that topic. If you are re-taking the exam, use this score report to guide you on which domains and objectives to focus on. You will also be able to print or email the score report.

Exam Blueprint

1. Identity and Lifecycle Management

1.1 Label the correct order of steps to implement an identity model for a given HR source.

1.2 Given a business use case, determine which lifecycle management design is valid.

1.3 Given a scenario containing both employees and non-employees along with their data sources, propose a solution on how to determine how many identity profiles are needed and their priority.

1.4 Given a scenario containing both employees and non-employees along with their data sources, determine which identity attributes need to be mapped, including the minimum attributes needed.

1.5 Given a scenario pertaining to Joiner (prehire, hire), and Leaver (term, post terminations), propose Lifecycle states and related actions that can be designed.

1.6 Configure manager correlations.

1.7 Propose a solution or recommendation for lifecycle state change requirements.

1.8 Map rules in identity attributes.

2. Provisioning

2.1 Deduce the resulting provisioning outcome given the current state of the access and a provisioning transaction.

2.2 Given a scenario, identify the best practices for developing a test for a provisioning.

2.3 Recognize best practices associated with provisioning with multiple accounts.

2.4 Troubleshoot provisioning errors.

2.5 Create provisioning policies and accounts on a source.

2.6 Understand provisioning and de-provisioning behavior when working with different types of role assignments.

2.7 Know provisioning best practices.

2.8 Recognize configuration and data requirements for Attribute sync and provisioning.

2.9 Understand requirements and options for different provisioning policies.

3. Access Management

3.1 Given a scenario, identify the best practices for developing a test for access management.

3.2 Know how to configure reminders and escalation patterns.

3.3 Know which use cases apply to using segments.

4. Virtual Appliances (VA)

4.1 Understand common VA functionality.

4.2 Troubleshoot virtual appliances errors.

4.3 Know the deployment options of the VAs and how they are configured.

4.4 Analyze the best practice around where to deploy VAs on-premise.

4.5 Know the steps of configuring and setting up the VA.

4.6 Discuss the advantages or disadvantages of deploying VA in HA DR patterns.

4.7 Know the purpose and location of logging files on the VA.

4.8 Know common commands and their purpose.

4.9 Troubleshoot a possible issue on the VA.

4.10 Know which keys the VA contains, how it generates these, and when they are set in the cluster.

4.11 Understand the VA networking configurations and their deployment options.

4.12 Given a specific scenario, discuss whether the configuration/installation of components/software on the VA are valid and why.

5. Sources

5.1 Describe possible service desk integration types and their purpose.

5.2 Determine configuration options based on specific scenario for connecting with Active Directory.

5.3 Determine configuration options based on specific scenarios for connecting to a database with a JDBC Connector.

5.4 Identify and explain connector types and when to use them.

5.5 Explain and recommend process flow for an aggregation of a given source.

5.6 Troubleshoot common errors with connectivity and determine the cause of them.

5.7 Analyze ways to control what data goes into the cloud and where it is stored.

6. General knowledge for Identity Security Engineer

6.1 Define and understand IGA.

6.2 Understand compliance.

6.3 Compare and contrast authentication and authorization.

6.4 Understand the concept of federation.

6.5 Know methods of authentication.

6.6 Specify advantages of using Microservice Architecture.

6.7 Know how to leverage general Rest APIs.

7. Platforms

7.1 Given a scenario, identify the best practices for developing a test for platforms.

7.2 Troubleshoot platform errors.

7.3 Identify components of API Gateway and how to authenticate against it.

7.4 Determine a given search criteria given an identity search model.

7.5 Match each authentication method to how it works.

7.6 Recommend a set of email configurations for a given environment.

7.7 Recommend best practices for system monitoring.

7.8 Given scrambled action steps, triggers, and end steps, recognize the correct order for the workflow.

7.9 Determine the correct access to grant an identity for a given task.

7.10 Describe where to find activity records when troubleshooting.

8. Supporting Governance

8.1 Recommend best practices in order to prepare for certifications.

8.2 Identify which certification type is best suited for a specific business requirement.

8.3 Identify the various approver options that can be selected for access request.

8.4 Know Separation of Duties (SoD) and when they should be applied.

8.5 Troubleshoot data issues that could arise during certifications.

9. Architecture

9.1 Understand security and encryption of data at rest and in transit.

9.2 Identify various Identity Security Cloud components and their redundancies.

9.3 Understand features of communication across systems that are beneficial to specific client scenarios.

9.4 Identify valid URLs.

9.5 Describe Multi-Tenant processing behavior.

10. Rules and Transforms

10.1 Given a data transformation scenario, recognize what is doable, and match the transforms that you might use to accomplish a scenario.

10.2 Identify the rules/customizations available in Identity Security Cloud.

10.3 Develop rule syntax and semantics.

10.4 Know best practices on selecting rules and transforms.

Digital Badge

Upon successfully passing the certification exam, you will earn the Identity Security Engineer certification, which will be awarded as a digital badge. You will be able to share your digital badge on your LinkedIn profile, where others can click on the badge and validate the certification’s validity and authenticity. Once earned, the Certification is valid for 2 years. You can expect to receive your badge within 24-48 hours upon successfully passing the exam. The badge will be delivered by email from Credly, so make sure your email provider does not block the following address: admin@credly.com.

For resources including the Program Policy Handbook and more, please check out the Professional Certification and Credentialing Program on Compass.



Related Content