IBM API Connect V10.0.3 Solution Implementation Free Sample Questions

Create a free account to browse all 20 sample questions. The full practice test includes 172 questions. Use the simulator for timed and flashcard mode.

Try Simulator

C1000-138 Sample Questions

  1. Question 1

    Q1

    A financial services company is using IBM API Connect to manage access to its core banking services. They have implemented a global policy to log all transaction requests for auditing. However, for a new 'Loan Application' API, they must prevent sensitive applicant data (e.g., social security number) from being written to the logs while still being passed to the backend system. The logging policy is a global post-request policy. What is the most effective way for the API developer to meet this requirement without altering the global policy?

    Show answer & explanation

    Correct answer: B

    The Redact policy is specifically designed for removing or masking sensitive data from a message payload. By placing it in the API's assembly flow, it will process the message before control is passed to any global policies. Since the logging is a post-request (meaning response flow) global policy, redacting the data in the API's response flow is the correct and most efficient solution. GatewayScript could achieve this but is more complex to implement and maintain. A Map policy is for transformation, not redaction. The Redact policy cannot be applied to the Activity Log policy directly.

  2. Question 2

    Q2

    A large enterprise has adopted IBM API Connect for multiple lines of business (LOBs), including Retail, Insurance, and Wealth Management. The enterprise architect's mandate is to provide each LOB with the ability to manage its own set of APIs, Products, developers, and a branded developer portal. However, a set of core 'Customer Profile' APIs, managed by a central IT team, must be made available for use by all LOBs in their respective Products. What is the most appropriate API Connect topology to fulfill these requirements?

    Show answer & explanation

    Correct answer: C

    This scenario is the primary use case for Syndication. Creating separate Catalogs provides the required isolation for each LOB, including a distinct developer portal and consumer base. Syndication allows a Product published in one Catalog (the central master) to be shared and made available in other Catalogs (the LOBs). This avoids duplicating the API definitions and allows for centralized management of the core APIs while enabling decentralized consumption. Spaces provide isolation but share a single developer portal, which does not meet the requirement.

  3. Question 3

    Q3

    An API developer is troubleshooting an OAuth2 authorization code flow. The client application successfully redirects the user to the authorization server, the user authenticates, but the subsequent token exchange request fails. The trace reveals the token endpoint returns an invalid_grant error. The developer confirms the authorization code is correct and has not expired. Which of the following is the most likely cause of this specific error in this context?

    Show answer & explanation

    Correct answer: C

    According to the OAuth 2.0 specification (RFC 6749), if the redirect_uri parameter was included in the initial authorization request, it MUST also be included in the token request, and the values must be identical. A mismatch is a common cause for an invalid_grant error, as it prevents authorization code injection attacks. While other issues can cause this error, the redirect_uri mismatch is a frequent and subtle problem in this specific flow.

  4. Question 4

    Q4

    A developer is creating a user-defined policy that needs to access a secure configuration value, such as an external service's API key. To avoid hardcoding this secret in the policy's implementation (e.g., GatewayScript), the developer wants to use a property that can be set in the API assembly. How should the property be defined in the policy's YAML file to ensure it is treated as a password, meaning its value is obfuscated in the API Connect user interfaces?

    Show answer & explanation

    Correct answer: B

    In the YAML definition file for a user-defined policy, when defining a property in the properties section, you can add format: password to a property of type: string. This instructs the API Connect UI to render the input field as a password field (obfuscating the value with asterisks or dots) and to handle the value as a secret.

  5. Question 5

    Q5

    A DevOps engineer needs to automate the deployment of API Products to different environments (Development, Staging, Production). Each environment has a different backend service URL for a specific API. Which combination of API Connect features should be used to manage these environment-specific URLs without modifying the OpenAPI definition for each deployment?

    Show answer & explanation

    Correct answer: C

    This is the standard best practice for managing environment-specific configurations. By defining a property in the API definition, you create a variable. This property can then be assigned a specific value at the Catalog level. When the API is published to the 'Development' Catalog, it uses the 'Development' value. When published to 'Production', it uses the 'Production' value. The Invoke policy in the assembly then references this property (e.g., $(backend_url)), allowing a single API definition to be promoted across environments without modification.

  6. Question 6

    Q6

    True or False: When an API Product is moved to the 'Deprecated' lifecycle state, any existing application subscriptions to its Plans are immediately disabled, and API calls will fail.

    Show answer & explanation

    Correct answer: B

    The statement is false. The 'Deprecated' state serves as a notice to consumers that the Product will be retired in the future. Existing subscriptions remain active, and API calls will continue to succeed. However, no new applications can subscribe to the Plans within the deprecated Product. This provides a grace period for consumers to migrate to a new version before the Product is eventually 'Retired', at which point calls would fail.

  7. Question 7

    Q7

    A developer is implementing a GraphQL API proxy in API Connect for a backend GraphQL service. The requirement is to prevent certain expensive or sensitive fields in the GraphQL schema from being queryable by consumers. Which API Connect feature should be used to achieve this without modifying the backend service?

    Show answer & explanation

    Correct answer: B

    API Connect provides the @hide directive as a specific feature for GraphQL API proxies. By adding this directive to fields or types in the schema within the API definition, API Connect will automatically remove them from the schema exposed to consumers. This prevents those fields from being included in introspection queries and invalidates any incoming requests that attempt to query them, effectively hiding them without backend changes.

  8. Question 8

    Q8Multiple answers

    A provider organization owner needs to configure mutual TLS (mTLS) for a specific Catalog. This requires the API Gateway to present its own certificate to backend services and to validate certificates presented by clients. Which TWO resources must be configured in the Cloud Manager or API Manager to enable this? (Select TWO).

    Show answer & explanation

    Correct answers: B, C

  9. Question 9

    Q9

    A developer is using the apic toolkit CLI to work on an API project locally. Which command should be used to validate the project's YAML definition files against the OpenAPI specification and check for API Connect-specific errors without connecting to a management server?

    Show answer & explanation

    Correct answer: C

    The apic validate command is specifically designed for local validation of project files. When run from the project directory, it checks the syntax and structure of the product.yaml and any referenced api.yaml files, reporting errors or warnings without requiring a connection to an API Connect server. This is a crucial step in a local development workflow before attempting to publish.

  10. Question 10

    Q10

    An API Product Manager for an e-commerce company is analyzing API usage data. They notice that a key partner is frequently hitting the rate limit for the 'Product Search' API, leading to failed requests and potential lost sales. The manager wants to offer this partner a higher limit without affecting other consumers on the same Plan. What is the most direct way to achieve this?

    Show answer & explanation

    Correct answer: B

    API Connect allows for plan overrides at the individual subscription level. This is the most efficient and targeted way to grant a specific application a different rate limit than the one defined in the general Plan. It avoids the overhead of creating new Products or Plans and doesn't require the consumer to make any changes on their end.

Register free to unlock 10 more sample questions

Create a free account to continue with the rest of the C1000-138 sample set.

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 172 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon