Question 1
Q1A financial services company is using IBM API Connect to manage access to its core banking services. They have implemented a global policy to log all transaction requests for auditing. However, for a new 'Loan Application' API, they must prevent sensitive applicant data (e.g., social security number) from being written to the logs while still being passed to the backend system. The logging policy is a global post-request policy. What is the most effective way for the API developer to meet this requirement without altering the global policy?
Show answer & explanation
Correct answer: B
The Redact policy is specifically designed for removing or masking sensitive data from a message payload. By placing it in the API's assembly flow, it will process the message before control is passed to any global policies. Since the logging is a post-request (meaning response flow) global policy, redacting the data in the API's response flow is the correct and most efficient solution. GatewayScript could achieve this but is more complex to implement and maintain. A Map policy is for transformation, not redaction. The Redact policy cannot be applied to the Activity Log policy directly.