The statement is incorrect. A Virtual Appliance is primarily a secure connectivity and connector-execution component that enables Identity Security Cloud to communicate with sources located inside an organization's private network or otherwise inaccessible directly from the SailPoint cloud environment.
During aggregation, the VA can communicate with the source and transmit relevant account, identity, group, and entitlement information to Identity Security Cloud. However, the Virtual Appliance is not intended to function as the persistent entitlement repository or search-indexing database.
Entitlement information used for access modeling, certifications, governance, search, roles, access profiles, and policy analysis is managed within the Identity Security Cloud platform. The VA facilitates source communication and executes connector-related operations such as aggregation and provisioning when required.
This architectural distinction is important because Virtual Appliances should not be treated as local databases containing governance data. Their primary responsibilities are secure connectivity, execution of integration workloads, and communication between SailPoint's cloud services and enterprise-managed systems.
Study Guide Reference: Virtual Appliances — VA Architecture, Source Connectivity, Aggregation and Provisioning Operations.
===============