Skip to content

EX240 Red Hat Certified Specialist in API Management exam Practice Questions

Prepare for EX240 with more than an answer.

156 questions in the full set12 sample questionsUpdated Mar 12, 2026
Exam fee
$500 USD
Time limit
180 minutes
Questions on the exam
Not disclosed (practical tasks)
Passing score
210 out of 300 (70%) (scale 0-300)
Level
Specialist
Valid for
3 years
Domains covered on the exam 10
  1. Access Control10%
  2. Accounts15%
  3. Analytics10%
  4. API Authentication15%
  5. API Documentation5%
  6. Billing10%
  7. Developer Portal10%
  8. Service Discovery5%
  9. Product Definition10%
  10. Service Integration10%
  1. 1

    You are defining the metrics for a REST API in 3scale. You want to track usage of the GET /products endpoint separately from POST /products. Which approach correctly implements this?

    Show answer details

    Correct answer: B

    In 3scale, 'Methods' are used to represent specific operations on the API (like GET vs POST) and are typically nested under the 'Hits' metric. You then use Mapping Rules to link the actual HTTP request (Verb + Path) to these specific Methods. This allows 3scale to increment the specific method count as well as the overall 'Hits' count.

  2. 2

    Scenario: Your company has two distinct groups of API consumers: 'Internal-Devs' and 'External-Partners'. You want to display a specific section of documentation, 'Private Internal APIs', only to the 'Internal-Devs' group on the Developer Portal.

    How should you configure this in the 3scale Admin Portal?

    Show answer details

    Correct answer: B

    The 3scale CMS allows you to organize content into Sections. Each Section has an access control setting where you can specify which Groups are allowed to view it. By placing the documentation page inside a Section restricted to 'Internal-Devs', the portal automatically handles the visibility restriction without requiring custom Liquid logic for every page.

  3. 3

    When configuring ActiveDocs for an API that uses 'App_ID and App_Key' authentication, which security scheme type must be defined in the OpenAPI Specification (Swagger) to ensure the interactive documentation works correctly?

    Show answer details

    Correct answer: A

    In OpenAPI 2.0 (Swagger), App_ID/App_Key authentication is typically modeled as two separate API key definitions (e.g., in: query or in: header). You then apply both requirements to the operations. 3scale ActiveDocs reads these definitions to provide the input fields for testing the API.

  4. 4

    You have deployed 3scale on OpenShift and are using the 'APIcast self-managed' gateway. You updated a Mapping Rule in the Admin Portal, but the changes are not reflected in the gateway traffic. What step is likely missing?

    Show answer details

    Correct answer: B

    Changes in the Admin Portal (like mapping rules) are saved to the database but not automatically pushed to the gateways. You must explicitly 'Promote' the configuration to Staging (and then Production) for the gateway to fetch and apply the new settings.

  5. 5

    A Senior API Architect is designing a monetization strategy for a weather data API using Red Hat 3scale. The requirement is to allow free access up to 1,000 calls per day, but charge $0.01 per call for any usage exceeding this limit within the same day, without blocking traffic. Which configuration combination in the Application Plan achieves this specific tiered pricing model?

    Show answer details

    Correct answer: B

    In 3scale, pricing rules can be tiered using ranges. To achieve a 'freemium' overage model where the first 1,000 are free and subsequent calls are charged, you define a Pricing Rule where the cost applies starting 'From' 1,001. You should not set a hard Usage Limit (blocking limit) if the goal is to allow traffic to continue (pay-as-you-go) after the threshold.

  6. 6

    An administrator needs to temporarily disable API access for a specific developer account due to a violation of the terms of service. The administrator wants to ensure the developer cannot generate new keys or access the Developer Portal, but the account data must be preserved for an audit. Which action should be taken in the Admin Portal?

    Show answer details

    Correct answer: B

    Suspending an account in 3scale disables access to the Developer Portal and API for all users and applications associated with that account, while preserving the data for future review or reactivation. Deleting the account would lose the audit data.

Create an account to continue.