Download IBM Security Access Manager V9.0 Deployment.C2150-609.PassLeader.2019-02-25.138q.vcex

Vendor: IBM
Exam Code: C2150-609
Exam Name: IBM Security Access Manager V9.0 Deployment
Date: Feb 25, 2019
File Size: 661 KB

How to open VCEX files?

Files with VCEX extension can be opened by ProfExam Simulator.

Demo Questions

Question 1
A customer has a developed an OAuth 2.0 Client application to access resources on behalf of a user. The customer states that the OAuth client has the following two constraints:
  1. The OAuth client is not capable of maintaining its credentials confidential for authentication with the authorization server. 
  2. The resources owner does not have a trust relationship with the client. 
What is the suitable OAuth 2.0 grant type for the API Protection Policy if the user resource accessed by the OAuth 2.0 client is to be protected by IBM Security Access Manager V9.0?
  1. Implicit Grant
  2. Client Credential Grant
  3. Authorization Code Grant
  4. Resource Owner Password Credentials Grant
Correct answer: B
Question 2
In a customer environment, a REST API client is being developed to carry out Reverse Proxy configuration and maintenance. As part of one of the activities the customer needs to update the junction information with an additional Backend Server. The customer has written a REST API client but is not able to modify the junction. 
Which HTTP headers should the customer pass?
  1. Host, Authorization
  2. Host, Accept: Application/json
  3. Authorization, Accept: Application/json
  4. content-type: application/json, Authorization
Correct answer: C
Question 3
During installation WebSEAL provides a default certificate key database that is used to authenticate both clients and junctioned servers. 
Which stanza entry of the WebSEAL configuration file points to the default certificate key database (i.e. kdb file)?
  1. ssl-keyfile
  2. jct-cert-keyfile
  3. webseal-cert-keyfile
  4. webseal-cert-keyfile-label
Correct answer: C
Question 4
A company has a large number of users who use mobile applications. The company wants to implement context-aware access controls for these resources. 
Which module of IBM Security Access Manager V9.0 should the company enable to support this requirement?
  1. Federation module
  2. Protocol Analysis module
  3. Mobile Access Control module
  4. Advanced Access Control module
Correct answer: D
Explanation:
Reference: https://www-01.ibm.com/common/ssi/cgi-bin/ssialias?infotype=an&subtype=ca&appname=gpateam&supplier=897&letternum=ENUS215-191
Reference: https://www-01.ibm.com/common/ssi/cgi-bin/ssialias?infotype=an&subtype=ca&appname=gpateam&supplier=897&letternum=ENUS215-191
Question 5
A request for a virtual host junction shows an unexpected source IP address. 
Which troubleshooting tool can be used to investigate this issue?
  1. Host File
  2. Snapshots
  3. Support Files
  4. Packet Tracing
Correct answer: A
Question 6
An IBM Security Access Manager V9.0 deployment professional is charged with monitoring request response times from WebSEAL to the backend. The deployment professional wants the flexibility to see response times per request, per junction, per HTTP return code, or other criteria that may come up in the future. 
What action will generate the required data for this analysis?
  1. Customize the request.log to include response times
  2. Run pdadmin “stats get pdweb.jct” on all junctions on a regular basis
  3. Run pdadmin stats get pdweb.https” and “stats get pdweb.http” on a regular basis
  4. Write a REST API script to pull “application interface statistics” on a regular basis
Correct answer: A
Question 7
A deployment professional attempts to log into an appliance which is part of a cluster to run pdadmin commands and receives the following message:
pdadmin> login-a sec_master –p password 
2016-03-03-02:04:38:.683-06:001 ---0x1354A420 pdadmin ERROR ivc socket mtsclient.cpp 2376
0x7fc2b7b0c720 
HPDCO1056E Could not connect to the server 192.168.254.11, on port 7135. 
Error: Could not connect to the server. (status 0x1354a426)
What should the deployment professional check concerning the login target?
  1. Login was attempted on a special node
  2. Login was attempted on a restricted node
  3. Login was attempted on a secondary master that has not been promoted to the primary
  4. Login was attempted on a non-primary master of a cluster and the primary policy server is down.
Correct answer: C
Question 8
A customer is migrating from TAM v6.1 running on AIX to IBM Security Access Manager (ISAM) V9.0 hardware appliance. 
Which information form the TAM v6.1 environment will be useful in sizing the new ISAM V9.0 hardware configuration?
  1. WebSEAL request logs
  2. WebSEAL CDAS specifics
  3. Number of LDAP replicas
  4. Number of objects in the protected object space
Correct answer: B
Question 9
There is an SSL connectivity issue between the IBM Security Access Manager V9.0 Reverse Proxy and the backend business application. 
Which Two troubleshooting commands under Tools in the application SSH interface can be used to validate the Reverse Proxy can successfully connect to the backend host: secure-port? (Choose two.)
  1. Ping
  2. Session
  3. Connect
  4. Traceout
  5. Connections
Correct answer: AB
Question 10
An IBM Security Access Manager V9.0 Reverse Proxy has a stateful junction to a Portal application called “/wps” There is no web server in front of Portal. This junction has three Portal servers defined behind it. The Portal team needs to do maintenance on each of the three servers. The team wants to accomplish with least impact to end users. 
Which pdadmin “server task” based steps will accomplish this?
  1. Stop a server, have Portal team apply maintenance, bring server online-repeat for the other two servers.
  2. Delete a server, have Portal team apply maintenance then add server back-repeat for the other two servers.
  3. Take a server offline, have Portal team apply maintenance, bring server online- repeat for the other two servers.
  4. Throttle a server, ensure activity has ceased for that server, have Portal team apply maintenance, bring server online-repeat for the other two servers.
Correct answer: C
HOW TO OPEN VCE FILES

Use VCE Exam Simulator to open VCE files
Avanaset

HOW TO OPEN VCEX AND EXAM FILES

Use ProfExam Simulator to open VCEX and EXAM files
ProfExam Screen

ProfExam
ProfExam at a 20% markdown

You have the opportunity to purchase ProfExam at a 20% reduced price

Get Now!