L100 Fixed Flashcards

(68 cards)

1
Q

An Application Owner can have multiple primary Certifiers and a single secondary Certifier.
T/F

A

FALSE

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

An Application Owner can have a single primary Certifiers and multiple secondary Certifiers
T/F

A

TRUE

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Single sign on is enabled in EIC using Azure Identity Provider. In this scenario, can the user log in using Azure and EIC native authentication?
T/F

A

FALSE

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Which of the following options support Authentication mechanisms in Saviynt?
A. None of the below
B. REST
C. LDAP
D. SAML 2.0
E. Database

A

C. LDAP
D. SAML 2.0
E. Database

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is not a valid status Type in Certification?
Preview, Launching, Discontinued, Delete

A

Delete

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Which of the following must be linked to the Active Directory Security System to automatically reconcile Accounts from AD into Saviynt?

A

AD Connection

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

what Job needs to run for the detective SOD?

A

RiskSODEvaluationJob

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Which of the following options can a Campaign Owner use to view the Entitlements Query that was used in a previously launched Campaign?
A. Campaign Export
B. Export option at the top right corner of the page, next to the Refresh Progress option
C. Campaign Summary
D. Reconfigure option

A

C. Campaign Summary

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Which of the following formats is suitable for downloading an Analytics report? (Select all that apply)
A. CSV file and Excel Sheet
B. Text file
C. CSV file only

A

A. CSV file and Excel Sheet

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Marty, an Administrator, reconciled Oracle Accounts into Saviynt. During the import, the incoming accounts were required to be mapped to the existing users in Saviynt. Which of the following Rules should be used to successfully associate Accounts to the correct users?
A. Account to User Rule
B. Account Name Rule
C. Technical Rule
D. User Account Correlation Rule

A

D. User Account Correlation Rule

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Which of the following Application types can be associated with the Automated Provisioning configuration turned OFF?
A. Service Desk Application
B. Hybrid Application
C. Connected Application
D. Disconnected Application

A

D. Disconnected Application

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

————– refers to any type of access that is associated with a managed system or application, such as groups, roles, permissions, or responsibilities.
A. Entitlements
B. Endpoints
C. Workflows
D. Accounts

A

A. Entitlements

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

As part of a recent organizational change, John, a Security Consultant, was moved from Department A to B.

To follow the Least Privilege Principle, there is a requirement to certify all existing entitlements of John by relevant stakeholders. Now, you have configured a User Update Rule to launch a certification when the department changes. Which of the following actions will you configure to support this scenario?
A. Launch Manager Campaign
B. Launch Service Account Campaign
C. Launch Entitlement Owner Campaign
D. Launch Organization Owner Campaign

A

C. Launch Entitlement Owner Campaign

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Which of the following SAV Roles grant users the privilege to edit UI Labels?
A. UIADMIN ROLE
B. ROLE_ADMINUI
C. ADMINULROLE
D. ROLE.UIADMIN

A

B. ROLE_ADMINUI

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

If you want an application to be available for requesting access (self or other), which of the following should be configured?
A. Proposed Accounts Workflow
B. Access Remove Workflow
C. Access Add Workflow
D. Emergency Access ID Request Workflow

A

C. Access Add Workflow

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What triggers a Request Rule?
A. When a user is imported
B. When Access Request is created and matches the conditions
C. When the Run Detective Rule job is run
D. When changes are detected in the import

A

B. When Access Request is created and matches the conditions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

Which of the following Account statuses is not considered in a User Manager Campaign certification?
A. Manually Suspended
B. Inactive
C. Suspended from Import Service
D. Manually Provisioned

A

D. Manually Provisioned

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

Which of the following Role types should be selected for a Role containing Entitlements that span across multiple applications?
A. Application Role
B. Transactional Role
C. Enabler Role
D. Enterprise Role

A

D. Enterprise Role

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

Which of the following configurations can be used to allow Certifiers to certify their own access?
A. Certify all users by default
B. Show consult for own access
C. Allow Self Certification
D. Certification reassignment

A

C. Allow Self Certification

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

Accounts, Entitlement types, and Entitlement data of an application are directly associated with:
A. Endpoints
B. Roles
C. Workflows
D. Security Systems

A

A. Endpoints

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

What is a Campaign?
A. Group of similar Endpoints
B. Group of User Groups
C. Group of Dashboards
D. Group of similar Certifications

A

D. Group of similar Certifications

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

Which is logical grouping of entitlements (access) that define the ability of users to perform business tasks.

A

Functions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

Which of the following Connections is used for integrating Saviynt with a ticketing system?
Service Ticket Connection
Ticket Connection
Service Desk Connection
Provisioning Connection

A

Service Desk Connection

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

Jane was managing an AD Group; however, she had to decommission this group and revoke access for all the users. Which of the following options should be used to perform the above task?
A. Segregation of Duties
B. Entitlement Update Rule
C. Mitigation Control
D. Entitlement Owner Certification

A

D. Entitlement Owner Certification

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Anitha, a manager, has a large number of users reporting to her, with most of them working remotely. Which of the following Campaign Types would you recommend for this scenario to reduce certification fatigue for Anitha? Launch User Manager Campaign and then Self Certification Campaign on certified items Launch Application Owner Campaign and then Self Certification Campaign on certified items Launch a Self-Certification Campaign and then User Manager Campaign on certified items Launch Service Account Campaign and then User Manager Campaign on certified items As an Admin, you are required to set up an Entitlement Owner Campaign for Entitlements belonging to an Oracle ERP Endpoint by the Internal Audit team. The Campaign should be launched at the beginning of every month, and only Accounts and Entitlements that meet the prerequisites should be included in the Campaign.
Launch a Self-Certification Campaign and then User Manager Campaign on certified items
26
Which of the following 2-key configurations would you recommend for achieving this? A. Use Campaign Template and the Schedule Later option B. Use Advanced Configurations and Preview mode and create the Campaign at the beginning of each month C. Use Advanced Configurations and set the Campaign expiry to 31 days D. Cannot be achieved
A. Use Campaign Template and the Schedule Later option
27
To help users make informed and quick decisions, Saviynt provides filters for retrieving Certification data in the User Manager Campaign and Service Account Campaign. Which of the following options cannot be regarded as a Smart Filter? A. User's Assigned Role counts B. Access with SoD Violations C. Out-of-Band Access for Entitlements D. Risk Level for Accounts
A. User's Assigned Role counts
28
Which of the following features best describe the Authorization mechanism for the EIC application? A. Security System B. SSO C.WSRETRY Job
A. Security System
29
As per the above mapping, USERNAME is the user attribute defined in Workday, and User_Name is the attribute defined in EIC. T/F
False
30
------------ allows detection of access rights granted outside the Saviynt platform. REST API B. RevokeOutOfBandAccessJob C. Bulk Upload D. ARS > Request Access for Others
B. RevokeOutOfBandAccessJob
31
ABC Company has set up a one-level workflow for an application, where the lone approver is the manager of the beneficiary. Margaret, who is Edward’s manager, raised an access request on behalf of Edward. Which of the following statements would be true/applicable? A. Manager's approval is auto-approved B. Manager's approval is auto rejected C. Manager must manually approve/reject the request D. None of the above
A. Manager's approval is auto-approved
32
________ filters the requestable applications under "Request New Access." A. Access Add Workflow B. Access Query C. Provisioning Connection D. Whom to Request
B. Access Query
33
Which of the following aspects in EIC is regarded as a unique identity of a person? A. Endpoint B. Employee C. Account D. User
D. User
34
Multiple indices can be selected while creating Analytics using the Elasticsearch Query. T/F
True
35
A Campaign Owner can create various types of a User Manager Campaign to save different settings for various categories of Manager Access Reviews. Options: A. Global Configurations B. Campaign Types C. Campaign Templates D. Campaign Previews
C. Campaign Templates
36
Which of the following connection types is best suited to expose Workday reports as a data service? Options: A. Workday-RAAS B. Workday-REST C. Workday-OAuth D. Workday-SOAP
A. Workday-RAAS
37
The Max Authentication Session parameter in Single Sign-On settings specifies the maximum duration, in seconds, for which an SSO session will remain valid. The default value is 3600 seconds. If the session logout value defined in IDP is 10,000 seconds and Max Authentication Session in Saviynt SSO is 5000 seconds, how long will the session last? Options: A.5000 seconds B.10,000 seconds C.3600 seconds D. None of the above
A.5000 seconds
38
Where can an Admin get the details of a successfully executed Rule? Options: A. Archived Rule Trail B. Archived Application Logs C. Current Rule Trail D. Action Trail
C. Current Rule Trail
39
Which of the following statuses is applicable for the "Add Access" task type when the task is successfully completed? Options: A. Provisioned B. Success C. Manually Provisioned D. Active
A. Provisioned
40
In the process of setting up Single Sign -On using SAML 2.0, the "SP Entity ID" acts as a unique identifier for the Saviynt SP. If "SP Entity ID" is set to the value of SaviyntSP, which of the following will be the correct Single Sign -On URL to log in to EIC? https//myorg.saviyntcloud.com/ECM/saml/SSO/SaviyntSP https//myorg.saviyntcloud.com/SaviyntSP https//myorg.saviyntcloud.com/ECM/saml/SSO/alias/SaviyntSP
https//myorg.saviyntcloud.com/ECM/saml/SSO/alias/SaviyntSP
41
(Paraphrasing) Which action is not allowed via a request form when setting up access requests in Saviynt? Add Entitlements Remove Entitlements Add Organization Entitlements Remove Organization Entitlements
Remove Entitlements
42
In Saviynt Segregation of Duties (SOD), what is a ruleset composed of?
A ruleset is a set of risks.
43
In Saviynt SOD, in what formats can you export existing rulesets?
CSV and Excel (.xls) file.
44
What triggers a Function Object Request in an SOD ruleset?
When the function owner adds, removes, or modifies one or more objects in the Function > Child Authorization tab.
45
For which ruleset types are Function Object Requests applicable?
Both SAP type rulesets and SAP Group rulesets.
46
What triggers a Function Entitlement Request in SOD?
When the function owner adds, removes, or modifies one or more entitlements in the Function > Entitlements tab.
47
When are risks associated to an organization in Saviynt SOD?
When any conflicting access is granted to a user or a group.
48
In Saviynt SOD, up to how many functions can be mapped to a single risk?
Up to 5 functions.
49
In Saviynt SOD, to what can each risk be mapped?
Each risk can be mapped into a business process area.
50
Who can manage risks in Saviynt SOD?
Only the risk owner can manage the risks.
51
In Saviynt SOD, what are functions?
Logical grouping of entitlements (access) that defines a user's ability to perform business tasks.
52
What Saviynt function types are available in SOD?
Non-SAP, SAP, and SAPGROUP.
53
Which logical operators are allowed for SAP-type functions in Saviynt?
AND and OR.
54
Which logical operators are allowed for Non-SAP-type functions in Saviynt?
AND, OR, and NOT.
55
Which logical operators are allowed for SAPGROUP-type functions in Saviynt?
AND and OR.
56
When does the Exclusion Query field appear in the function configuration?
Only when Non-SAP is selected as the Saviynt Function Type.
57
In what formats can you export existing functions in Saviynt SOD?
CSV, Excel, and Complete Export.
58
In Saviynt, what is a business process in the context of SOD?
A grouping of one or more functions and roles representing a collection of related, structured activities or tasks.
59
In what formats can you export existing Business process rulesets in Saviynt SOD?
CSV and Excel.
60
In SOD simulation, what are simulations based on in the Simulation workbench?
Security System and Endpoint.
61
In Saviynt, what can SAV roles be used to control with respect to dashboards?
Whether dashboards for individual modules are enabled or disabled.
62
In campaign status, what does the 'In Progress' status indicate?
Campaigns which are new or in process for review.
63
What does the 'Total Number of retries' field configure for e-Signature verification?
The maximum number of times a user can retry entering validation credentials (username and password); attempts beyond this are rejected and the certification cannot be locked.
64
What is the purpose of the 'Default Certifier' setting in a certification campaign?
To select a default certifier who can certify all the accounts belonging to an inactive or unavailable certifier (Manager or Secondary Manager).
65
Before configuring SAML single sign-on (SSO) for Saviynt EIC, where must the user exist?
In both EIC and the SAML 2.0-compliant identity provider (IdP).
66
What must users be assigned in EIC as a prerequisite for SAML SSO?
An appropriate SAV role.
67
What cryptographic and metadata artifacts are required as prerequisites for configuring SAML SSO in Saviynt EIC?
SAML metadata (.xml) files and an X.509 certificate with validity up to three years.
68
Which configuration items must be in place for user-account mapping when setting up SSO and provisioning in Saviynt?
A User Account Correlation Rule on the Endpoint and attribute mappings on the Connection.