C-CPI-2506 SAP Certified Associate Integration Developer Practice Questions
Prepare for C-CPI-2506 with more than an answer.
- Level
- Associate
- Valid for
- 12 months
Domains covered on the exam 4
- SAP Integration Suite Overview15%
- Managing APIs25%
- Implementing Cloud Integration35%
- SAP Event Mesh25%
- 1
Case Study
HealthFirst, a major healthcare provider, needs to build a secure API gateway using SAP API Management. This gateway will expose critical patient and billing information from their on-premise SAP S/4HANA system and a cloud-native microservice. They have two main consumer groups: internal applications developed by their own IT department and external applications from partner insurance companies.
Business & Technical Requirements:
- Authentication: All API calls must be authenticated. Internal apps must use OAuth 2.0 Client Credentials, while external partners must use a combination of an API Key and mTLS (client certificate authentication).
- Authorization: Access must be restricted. The 'Patient API' should only be accessible by consumers who are part of the 'Clinical' API Product, while the 'Billing API' should only be accessible to those in the 'Financial' API Product.
- Traffic Management: To protect the backend systems, external partners are limited to 1,000 calls per day. Internal applications have a much higher limit of 100,000 calls per day. Additionally, no consumer should be able to make more than 20 calls per second.
- Data Security: The response from the 'Patient API' contains sensitive data. A custom policy must be implemented to check for a specific HTTP header (
X-Audit-ID) in the request and log it. If the header is missing, the request must be rejected with a 400 Bad Request error.
Which combination of policies, applied in the correct sequence within the API Proxy, fulfills all of HealthFirst's requirements?
Show answer details
Correct answer: C
This solution correctly maps all requirements. The Spike Arrest in the Preflow applies universally. Conditional flows are the right way to handle different logic for internal vs. external consumers, each with the correct authentication and Quota policy. Enabling mTLS on the virtual host is the standard way to enforce client certificate validation for external partners. The authorization is handled by packaging the correct API proxies into different API Products ('Clinical', 'Financial'). Finally, using a Raise Fault policy with a condition
request.header.X-Audit-ID is nullis the most efficient way to enforce the presence of the audit header without needing a custom script. - 2
A developer needs to dynamically route a message to one of three different receivers based on the value of an XML element named
in the incoming payload. Which integration flow step is specifically designed for this purpose?Show answer details
Correct answer: B
The Router step is the standard component for content-based routing. It allows the developer to define multiple routing conditions, typically using XPath for XML payloads or JSONPath for JSON payloads, and directs the message down the first path whose condition evaluates to true. A default route can also be configured for messages that don't match any condition.
- 3
An integration flow is designed to poll a directory for new files. The business requirement is that the flow should only run during business hours (9 AM to 5 PM) on weekdays. How can this be implemented in the sender channel configuration?
Show answer details
Correct answer: C
The Scheduler configuration in timer-based sender adapters (like SFTP Polling or Timer Start) provides options to define a precise schedule. You can select specific days of the week (Monday to Friday) and define multiple time ranges (e.g., 09:00 to 17:00) during which the polling should be active. This is the standard, most efficient way to meet this requirement without custom scripting.
- 4
A developer is creating an API Proxy for a backend service. The backend requires the client's IP address to be passed in a custom HTTP header named 'X-Forwarded-For-Client'. Which policy and variable should be used to achieve this?
Show answer details
Correct answer: A
The
proxy.client.ipis the standard flow variable in API Management that holds the IP address of the client making the request to the API Proxy. The 'Assign Message' policy is the correct tool for creating, modifying, or deleting HTTP headers. By using this policy to set the 'X-Forwarded-For-Client' header to the value of{proxy.client.ip}, the requirement is fulfilled. - 5
What is the purpose of the Dead Message Queue (DMQ) feature in SAP Event Mesh?
Show answer details
Correct answer: D
The Dead Message Queue (or Dead Letter Queue) is a standard messaging pattern for error handling. When a consuming application repeatedly fails to process a message (e.g., due to malformed data), the message broker will move the message to a configured DMQ after a set number of retries. This prevents the 'poison message' from blocking the processing of subsequent valid messages in the main queue and allows for later analysis and manual intervention.
- 6
A company has a requirement to integrate with over 50 different third-party SaaS applications, each with its own unique API, authentication method, and data model. The integration team wants to standardize and simplify how their internal applications connect to these external services. Which capability of SAP Integration Suite is specifically designed to address this challenge?
Show answer details
Correct answer: C
Open Connectors provides a library of pre-built connectors to a wide range of non-SAP, third-party cloud applications. It abstracts the complexity of authentication (e.g., OAuth) and provides a harmonized, RESTful API with a standardized data model for each connected application. This significantly reduces the development effort needed to connect to many different SaaS providers.
- 7
An integration flow must enrich an incoming XML message containing multiple product items. For each individual product item, the flow must fetch its price from an external OData service and add the price into the corresponding item structure in the original message. Which approach correctly implements this per-item enrichment logic?
graph TD subgraph Input XML A(Item ProductID: 101) B(Item ProductID: 102) end subgraph OData Lookup OData(Price Service) end subgraph Output XML E(Item ProductID: 101, Price: 50) F(Item ProductID: 102, Price: 60) end A --> OData; B --> OData; OData --> E; OData --> F;Show answer details
Correct answer: B
The Content Enricher step enriches the entire message payload. To perform enrichment on individual sub-elements (like each product item), the standard pattern is to first use a Splitter (e.g., Iterating Splitter) to break the composite message into individual messages, one for each item. Then, the Content Enricher is used on each individual split message. Finally, a Gather step is used to reassemble the enriched individual messages back into a single composite message.
- 8
A financial services company is using SAP Event Mesh to broadcast real-time trade confirmations. A downstream auditing application needs to consume every message exactly once, even if the application is temporarily offline. A separate market data application needs to receive all messages but can tolerate occasional loss. Which configuration should be used?
Show answer details
Correct answer: C
This is the correct publish-subscribe pattern. Publishing to a topic allows multiple, independent consumers. The auditing application subscribes via a queue to ensure message persistence and guaranteed, exactly-once delivery (with QoS 1). The market data application subscribes directly to the topic with QoS 0 (at-most-once delivery), which is suitable for its non-critical requirement.
- 9
During a security audit of an API Proxy in SAP API Management, a consultant observes that a 'Verify API Key' policy is attached to the ProxyEndpoint Preflow. However, a requirement states that a specific resource path,
/public/status, should be accessible without an API key, while all other paths must be secured. How can this be achieved without creating a separate API Proxy?Show answer details
Correct answer: D
Policies in the Preflow apply to all requests. To create an exception, the security policy must be moved out of the Preflow. By placing the 'Verify API Key' policy in the default flow (which acts as a catch-all) and creating a specific conditional flow for
/public/statuswith no security policies, the requirement is met. The specific flow for/public/statusis matched and executed, and processing continues without hitting the default flow's security policy. - 10
A developer is building an integration flow that processes a batch of sales orders from an SFTP server. The source file is a large XML containing thousands of
elements. The flow must process each order individually, call an external OData service to enrich it with customer data, and then send it to a target system. To optimize performance and memory usage, which combination of iFlow steps is most appropriate?Show answer details
Correct answer: B
The Iterating Splitter is designed for large messages, as it processes splits sequentially without loading the entire message into memory, preventing memory-related errors. The Content Enricher is the correct step to call an external service to add data to the current message (the individual order). The Gather step is used to combine the enriched messages back into a single message if required, or can be omitted if orders are sent individually after enrichment.
