All Practice Exams

Free Practice Questions for IIQ Engineer

Exam-style questions and explanations by OpenExamPrep.

✓ No registration✓ No credit card
128+ Questions
100% Free

Loading practice questions...

Same family resources

Explore More SailPoint Certifications

Continue into nearby exams from the same family. Each card keeps practice questions, study guides, flashcards, videos, and articles in one place.

Exam Review

Key Facts: IIQ Engineer Exam

Up to 66

DOMC Questions

SailPoint Exam Prep Guide

Up to 90 min

Seat Time

SailPoint Exam Prep Guide

Pass/Fail

Result (threshold not published)

SailPoint Policy Handbook

$400

Enrollment Fee (2 attempts)

SailPoint Identity University

2 years

Certification Validity

SailPoint Policy Handbook

7

Blueprint Domains

SailPoint Exam Prep Guide

The IdentityIQ Engineer exam is an online, proctored, role-based exam of up to 66 DOMC questions in up to 90 minutes, reported only as Pass or Fail. It covers seven domains, from installation and Lifecycle Manager to development, debugging, and data modeling. A $400 enrollment includes two attempts, and the credential is valid for 2 years.

Sample IIQ Engineer Practice Questions

Try these sample questions to review concepts for the IIQ Engineer exam. Each question includes a detailed explanation. Start the interactive quiz above for the full 128+ question experience with AI tutoring.

1In SailPoint IdentityIQ, what is an 'Identity Cube'?
A.A hardware appliance that stores identity data on-premise
B.The aggregated identity record for a user that contains all accounts, entitlements, roles, and attributes sourced from connected applications
C.A reporting template that displays identity compliance metrics
D.A network segmentation policy that restricts identity provider communication
Explanation: The Identity Cube is SailPoint IdentityIQ's central data model for a user identity. It aggregates all identity information — accounts across all connected applications, entitlements, roles, attributes, policy violations, and certifications — into a single unified identity record. All IdentityIQ processes operate against these identity cubes.
2What is the purpose of 'Application Onboarding' in SailPoint IdentityIQ?
A.Installing IdentityIQ software on a new server application
B.Connecting a new authoritative or managed system to IdentityIQ so its accounts and entitlements are aggregated and governed
C.Granting a user access to a new application via the access request module
D.Creating a new role definition for application-specific entitlements
Explanation: Application Onboarding in IdentityIQ is the process of configuring a new system (HR system, Active Directory, Salesforce, SAP, etc.) as a connected source. It involves setting up the connector (type, host, credentials), configuring the account and entitlement schema, defining aggregation schedules, and establishing provisioning settings so IdentityIQ can manage access on that application.
3In IdentityIQ, what language is used for writing custom Rules?
A.Python 3
B.BeanShell (a Java scripting language)
C.JavaScript (Node.js)
D.PowerShell
Explanation: SailPoint IdentityIQ rules are written in BeanShell, which is a Java-compatible scripting language. BeanShell scripts can use the full Java API and IdentityIQ's SailPointContext to perform custom logic for provisioning rules, correlation rules, attribute transformations, approval workflows, and other customizations. Knowledge of BeanShell/Java is essential for IdentityIQ engineers.
4What is a 'Lifecycle Event' in SailPoint IdentityIQ?
A.A scheduled report generation triggered by calendar dates
B.A triggered business process (joiner, mover, leaver) that automatically provisions or deprovisions access when an identity attribute changes
C.A compliance policy that defines which roles trigger a Separation of Duties violation
D.A connector event raised when an application's account data schema changes
Explanation: Lifecycle Events in IdentityIQ are automated business process triggers that execute when identity attributes change. Classic examples are the 'Joiner' (new hire), 'Mover' (role/department change), and 'Leaver' (termination) events. When these conditions are met, IdentityIQ automatically provisions entitlements, revokes access, triggers approval workflows, or performs other configured actions.
5What is the difference between a 'Business Role' and an 'IT Role' in IdentityIQ?
A.Business Roles are created by HR; IT Roles are created by security engineers — there is no technical difference
B.Business Roles define groupings of entitlements from a business function perspective and are assigned to identities; IT Roles define technical entitlements on specific applications and are typically contained within Business Roles
C.Business Roles are for provisioning; IT Roles are for certification campaigns only
D.Business Roles require manager approval; IT Roles are auto-approved
Explanation: In IdentityIQ's role model hierarchy, Business Roles represent job functions (e.g., 'Sales Representative') and are assigned to identities based on their HR attributes. IT Roles contain the actual technical entitlements required on specific applications (e.g., Salesforce 'Read' access). Business Roles contain or reference IT Roles, providing a business-understandable abstraction over technical access grants.
6In IdentityIQ, what is 'Aggregation' and when does it occur?
A.The process of combining multiple IdentityIQ deployment nodes for high availability
B.The process of reading account and entitlement data from connected applications and updating IdentityIQ's identity cube data
C.The accumulation of policy violations before they are sent in a batch notification
D.The merging of duplicate identity records into a single identity cube
Explanation: Aggregation is the core data collection process in IdentityIQ where the platform reads account, entitlement, and group data from connected applications (Active Directory, LDAP, SAP, Salesforce, etc.) and stores it in IdentityIQ's database to populate identity cubes. Aggregation runs on configurable schedules and is the foundation for accurate access visibility and governance.
7What is 'Correlation' in the context of SailPoint IdentityIQ?
A.Matching application accounts to IdentityIQ identity records based on defined rules to build the identity cube
B.Creating relationships between roles and entitlements in the role catalog
C.Aligning compliance policies to specific regulatory frameworks
D.Comparing access request approvals against historical provisioning patterns
Explanation: Correlation in IdentityIQ is the process of associating aggregated accounts from managed applications with the correct identity records (identity cubes). Correlation rules use attributes (e.g., employee ID, email, username format) to match an account in Salesforce or Active Directory to the correct person's identity cube. Uncorrelated accounts appear as orphaned or unmanaged accounts.
8What is a 'Certification Campaign' in IdentityIQ?
A.A marketing initiative to increase IdentityIQ user adoption within the organization
B.A periodic review process where managers or application owners certify whether users' access is still appropriate and revoke excess entitlements
C.An automated provisioning workflow triggered when a new application is onboarded
D.A test campaign that verifies IdentityIQ policy rules are correctly configured
Explanation: Certification Campaigns (also called access reviews or recertifications) in IdentityIQ are scheduled or ad-hoc reviews where designated reviewers (managers, application owners, or others) examine assigned access and certify whether each entitlement is still appropriate. Items that are not certified can be automatically revoked, supporting access governance and compliance with least privilege principles.
9In IdentityIQ, what is 'Separation of Duties' (SoD) and how is it enforced?
A.SoD ensures IT and business teams use separate IdentityIQ deployment environments
B.SoD policies define conflicting combinations of roles or entitlements that a single user should not hold, and IdentityIQ detects violations during provisioning and certification
C.SoD requires that access requests are approved by two separate managers before provisioning
D.SoD automatically expires access after a defined time period to prevent accumulation
Explanation: Separation of Duties (SoD) is a compliance control requiring that conflicting functions be held by different people — for example, the ability to create a vendor and approve payment should not be held by the same person. IdentityIQ's Policy module allows defining SoD policies as pairs or sets of conflicting entitlements/roles, then automatically detects violations during provisioning requests and certification reviews.
10What is 'Provisioning' in IdentityIQ and which two primary methods does it support?
A.Provisioning is the process of deploying IdentityIQ to a new server; it supports cloud and on-premise deployment
B.Provisioning is creating or modifying access on target applications; it supports direct connector-based provisioning and manual work items for applications without connectors
C.Provisioning is the process of backing up IdentityIQ configuration; it supports local and remote backup
D.Provisioning is user training on IdentityIQ; it supports self-service and instructor-led methods
Explanation: Provisioning in IdentityIQ is the process of creating, modifying, enabling, or disabling accounts and entitlements on target applications based on identity governance decisions. It supports two methods: (1) direct connector-based provisioning where IdentityIQ's connector sends commands directly to the application API/directory, and (2) manual provisioning work items where IdentityIQ notifies an application admin to perform the change manually.

About the IIQ Engineer Exam

The SailPoint Certified IdentityIQ Engineer certification validates expertise in implementing and administering SailPoint IdentityIQ — the on-premise enterprise identity governance platform. It covers the Identity Cube data model, application onboarding and connectors, aggregation and correlation, provisioning workflows, lifecycle events, role and entitlement governance, certification campaigns, SoD policy enforcement, and BeanShell rule and workflow development.

Exam sponsor: SailPoint. The requirements and fees below concern the certification or admission exam, separate from our free practice resources.

Assessment

Variable-length assessment

Time Limit

Up to 90 minutes

Passing Score

Pass/Fail (threshold not published)

Exam / Certification Fees

$400 (includes two attempts)

Exam sponsor website

Our practice resources: topics covered

We aim to reflect publicly available exam outlines and topic information in our study resources. Coverage, format, and difficulty may differ from the actual exam, and we cannot guarantee that every detail is accurate or current. Confirm exam requirements, fees, and policies with the official exam sponsor.

Not published

Installation, Build, and Deployment

Infrastructure components, installation steps, extended attributes, ongoing build and deployment, patches and upgrades, end-user access, and email server settings (objectives 1.1-1.7)

Not published

Lifecycle Manager

Lifecycle Manager configuration, identity provisioning policies, LCM workflows, lifecycle events, QuickLinks and QuickLink populations, batch requests, and Rapid Setup (objectives 2.1-2.7)

Not published

Identity Governance

Certification campaigns, certification rules, policies, responses to policy violations, reporting, Advanced Analytics, and auditing (objectives 3.1-3.7)

Not published

Development

Rule libraries, rule inputs and outputs, workflow variables, transitions, step conditions, work item steps, step usages, sub-workflows, the SailPoint API, email templates, branding, and localization (objectives 4.1-4.10)

Not published

Application Onboarding

Application definitions, common connector settings, Rapid Setup aggregation settings, task scheduling for data loading, and application and connector rule types (objectives 5.1-5.6)

Not published

Debugging and Troubleshooting

log4j, Syslog, the IdentityIQ console, debug pages, email redirection, and the Administrator Console (objectives 6.1-6.6)

Not published

Data and Access Modeling

Default role types, role configuration, identity attribute mappings, objects with extended attributes, common data objects and their relationships, and group types (objectives 7.1-7.7)

Preparing for the IIQ Engineer Exam

What You Need to Know

  • Passing score: Pass/Fail (threshold not published)
  • Assessment: Variable-length assessment
  • Time limit: Up to 90 minutes
  • Exam / certification fees: $400 (includes two attempts) Official sources

Using Our Practice Resources

  • Work through all 128 available questions
  • Review every answer and explanation
  • Track weak areas and revisit them
  • Use our AI tutor for tough concepts

IIQ Engineer: Suggested Study Strategy

1Build a sandbox and install IdentityIQ yourself, including init.xml, init-lcm.xml, and a site-specific keystore
2Learn the order of data loading: authoritative aggregation, other aggregations, group aggregation, then Identity Refresh
3Practice judging single answer options as true or false, because the exam uses the DOMC format
4Know where each setting lives: Global Settings pages, the Lifecycle Manager page, Setup menus, and the Debug pages
5Write and test rules and workflows from the console with the rule, workflow, validate, and parse commands
6Use log4j, Syslog incident codes, the Debug pages, and the Administrator Console to troubleshoot
7Review the documentation page for every term in SailPoint's Exam Prep Guide blueprint

Frequently Asked Questions

What is the SailPoint Certified IdentityIQ Engineer certification?

It is SailPoint's role-based certification for people who install, deploy, configure, and develop IdentityIQ, SailPoint's customer-managed identity governance platform. The exam covers installation and deployment, Lifecycle Manager, identity governance, development, application onboarding, debugging, and data and access modeling.

How many questions are on the IdentityIQ Engineer exam?

SailPoint's Exam Prep Guide says the exam has up to 66 Discrete Option Multiple Choice (DOMC) questions with a seat time of up to 90 minutes. The exam ends early once you have answered enough questions correctly or incorrectly, and results are reported only as Pass or Fail.

What BeanShell skills are tested?

The Development domain covers rule libraries, rule input and output arguments, workflow variables, transitions, and step conditions, sub-workflows, and the common SailPoint API objects and methods. Expect to read and reason about BeanShell rules that use the SailPointContext, Filter, and QueryOptions.

What are the most important topics to study?

SailPoint publishes no domain weights, so study all 50 objectives across the seven domains. Hands-on practice with installation, application onboarding, aggregation and refresh, LCM workflows, certifications, rules, and the debugging tools matters most, because SailPoint describes this as a role-based exam.

What is the difference between aggregation and correlation in IdentityIQ?

Aggregation is the process of reading account and entitlement data from a connected application and storing it in IdentityIQ's database. Correlation is the subsequent process of matching those aggregated accounts to the correct identity records (Identity Cubes) using matching rules (e.g., account email matches identity email). Aggregation brings data in; Correlation assigns that data to the right identity owner.