C1000-172 IBM Cloud Professional Architect V6 Practice Questions
Prepare for C1000-172 with more than an answer.
- Exam fee
- $200 USD
- Level
- Professional
- Valid for
- 3 years
Domains covered on the exam 8
- Compute Options19%
- Designing Cloud Solutions16%
- Data Analytics and Data Management6%
- IBM Cloud Storage Options11%
- IBM Cloud Networking Options23%
- Security9%
- IBM Cloud Resiliency Features8%
- Observability Capabilities8%
- 1
The command
ibmcloud is vpn-gateway-update --routing-protocol _____is used to configure dynamic routing for a VPN gateway in a VPC. To enable BGP for exchanging routes with an on-premises network, what value should be used in the blank?Show answer details
Correct answer: B
For route-based VPNs, the
--routing-protocolflag is used with the value 'enable' to turn on dynamic routing capabilities (BGP). The specific BGP parameters are configured in subsequent steps. - 2
A company has an existing VMware vSphere environment on-premises and wants to extend its data center to IBM Cloud. Their primary goals are to maintain operational consistency using familiar VMware tools (like vCenter and NSX) and to facilitate seamless workload migration between on-premises and the cloud. The cloud solution must provide dedicated, bare-metal infrastructure for performance and isolation. Which IBM Cloud offering is specifically tailored for this scenario?
Show answer details
Correct answer: A
IBM Cloud for VMware Solutions is the purpose-built offering that provides a dedicated, automated environment running on bare metal servers for VMware workloads. It gives administrators full control over their vSphere, vCenter, and NSX environments, ensuring operational consistency with their on-premises setup and enabling easy migration with tools like HCX.
- 3
An architect is comparing IBM Key Protect and IBM Hyper Protect Crypto Services for a new cloud application. The application requires FIPS 140-2 Level 2 certified, multi-tenant key management for standard data encryption needs and supports a Bring Your Own Key (BYOK) model. Exclusive control of the HSM hardware is not a requirement. Which service is the more appropriate and cost-effective choice?
Show answer details
Correct answer: B
IBM Key Protect is a multi-tenant service based on FIPS 140-2 Level 2 certified HSMs. It is designed for standard cloud workloads, supports BYOK, and is more cost-effective than Hyper Protect Crypto Services. Since the requirement for exclusive HSM control (KYOK) and FIPS Level 4 is absent, Key Protect is the correct choice.
- 4
An architect needs to provision an IBM Cloud VPC, several subnets, and a set of Virtual Server Instances using an Infrastructure as Code approach. Which IBM Cloud service provides a managed environment for executing Terraform and Ansible automation?
Show answer details
Correct answer: B
IBM Cloud Schematics is the dedicated service for Automation and Infrastructure as Code on IBM Cloud. It provides managed runtimes for Terraform, Ansible, and other automation tools, allowing users to define and provision their cloud infrastructure from source code.
- 5
A logging administrator needs to configure log collection for all services within an IBM Cloud account. The requirements are to have a centralized location to search and analyze logs, archive logs to Cloud Object Storage for long-term compliance, and stream logs to an external SIEM system. Which service provides all these capabilities?
flowchart TD subgraph IBMCloud["IBM Cloud Account"] ServiceA[Service A] ServiceB[Service B] ServiceC[Service C] end ServiceA --> LogService{Log Collection Service} ServiceB --> LogService ServiceC --> LogService subgraph LogServiceFeatures Search[Search & Analyze] Archive[Archive to COS] Stream[Stream to SIEM] end LogService --> Search LogService --> Archive LogService --> StreamShow answer details
Correct answer: D
IBM Log Analysis is the centralized logging service for IBM Cloud. It aggregates logs from various services, provides a UI for searching and analyzing them, and includes features to configure archiving to Cloud Object Storage and streaming to external systems like a SIEM, fulfilling all the stated requirements.
- 6
A multinational corporation is designing a hub-and-spoke network topology on IBM Cloud. They have multiple VPCs in different MZRs (us-south, eu-de) that need to communicate with each other and with their on-premises data centers connected via Direct Link. The primary goals are centralized routing control, simplified network management, and avoiding complex VPC peering meshes. Which IBM Cloud networking service is specifically designed to act as a cloud network hub to connect VPCs and classic infrastructure across regions and with on-premises networks?
Show answer details
Correct answer: C
IBM Cloud Transit Gateway is the managed service designed for this exact purpose. It simplifies connectivity by acting as a central hub, connecting VPCs, classic infrastructure, and on-premises networks without requiring a full mesh of VPC peerings. A VRA is a valid but less-managed approach requiring more operational overhead. CIS is for edge services like DDoS and WAF, not internal routing. A full mesh of VPC peerings is complex to manage and does not scale well.
- 7
A DevOps team is deploying a stateful, data-intensive application on Red Hat OpenShift on IBM Cloud. The application consists of a PostgreSQL database that requires high I/O performance and a processing service that requires a shared file system for temporary data exchange between multiple pods. They need to select appropriate persistent storage solutions that are fully managed and integrated with the platform. Which TWO IBM Cloud storage services should the architect recommend to meet the database and shared file system requirements respectively? (Select TWO)
Show answer details
Correct answer: B, C
IBM Cloud Block Storage provides the necessary high-performance, low-latency persistent storage with ReadWriteOnce (RWO) access mode, which is ideal for a single-pod stateful set like a database.
IBM Cloud File Storage is an NFS-based service that provides ReadWriteMany (RWX) access mode, allowing multiple pods to mount and share the same volume simultaneously, which fits the shared file system requirement.
- 8
A leading European bank is architecting a new digital payments platform on IBM Cloud. Due to stringent regulatory requirements like GDPR and PSD2, they have an absolute mandate for "Keep Your Own Key" (KYOK) encryption. The bank's security policy dictates that they must have exclusive control over the entire key management lifecycle, including the hardware security module (HSM) where the master key resides. No cloud provider personnel, under any circumstances, should have access to the HSM or the keys. The solution must provide the highest level of cryptographic security available in the public cloud, validated by FIPS 140-2 Level 4 certification.
The architecture involves encrypting data in IBM Cloud Object Storage, Databases for PostgreSQL, and custom applications running in a VPC. The security team needs a centralized, highly secure service to act as the root of trust for all encryption keys used across these services. They are evaluating different key management solutions but are concerned about multi-tenancy risks and potential access by privileged cloud administrators.
Which IBM Cloud security service is uniquely designed to meet all the bank's stringent requirements for exclusive key control and the highest level of security certification?
Show answer details
Correct answer: C
IBM Hyper Protect Crypto Services is the only service that meets all the requirements. It provides a dedicated, single-tenant HSM (FIPS 140-2 Level 4 certified) that gives the client exclusive control (KYOK), meaning even IBM administrators cannot access the keys. It is designed to be the root of trust for other services. Key Protect is a multi-tenant service and only supports BYOK, not KYOK with exclusive HSM control. Certificate Manager is for TLS certificates, not data-at-rest encryption keys. A custom solution would be complex and lack the required certifications.
- 9
A retail company is modernizing its e-commerce platform. They want to decouple their order processing, inventory management, and shipping notification services. The goal is to build a resilient, scalable system where an "OrderCreated" event can trigger multiple downstream processes asynchronously without the core ordering service having to know about them. The expected event volume is high, with significant peaks during holiday seasons. Which fully managed IBM Cloud service is best suited to serve as the central message bus for this event-driven architecture, providing high-throughput, persistent, and scalable event streaming based on Apache Kafka?
Show answer details
Correct answer: C
IBM Event Streams is a managed Apache Kafka service, designed specifically for high-throughput, scalable, and persistent event streaming, which is exactly what is required for a central message bus in a high-volume event-driven architecture. IBM MQ is a message queue, better suited for traditional point-to-point or pub/sub messaging but not large-scale event streaming. Cloud Functions is a compute service that would consume events, not act as the bus itself. Cloudant is a NoSQL database.
- 10
An online media company streams live events to a global audience. They have application instances deployed in IBM Cloud MZRs in Dallas (us-south), Frankfurt (eu-de), and Tokyo (jp-tok). To ensure low latency and high availability, they need to direct users to the geographically closest data center. If the local data center becomes unhealthy, traffic should automatically failover to the next nearest healthy region. What IBM Cloud networking component should be used to achieve this geographic routing and automated global failover?
Show answer details
Correct answer: C
The IBM Cloud Internet Services (CIS) Global Load Balancer (GLB) is designed for this exact use case. It provides DNS-based global load balancing with features like geographic routing (directing users to the nearest origin pool), health checks, and automated failover between pools in different regions. An ALB operates within a single region. A Transit Gateway is for private network interconnection, not public internet traffic distribution. A VPN is for secure site-to-site connectivity.
