Skip to content

C1000-138 IBM API Connect V10.0.3 Solution Implementation Practice Questions

Prepare for C1000-138 with more than an answer.

172 questions in the full set20 sample questionsUpdated Jan 28, 2026
Level
Solution Implementer
Valid for
Refer to IBM certification policies
Domains covered on the exam 5
  1. Overview of IBM API Connect19%
  2. Provider Organization Owner Role18%
  3. API Developer Role32%
  4. API Product Manager Role18%
  5. Developer Portal (Consumer and Administrator)13%
  1. 1

    A JWT validation policy is configured in an API assembly. The policy is failing with a 'clock skew' error for tokens issued by a partner's identity server. What does this error indicate and how should it be resolved in API Connect?

    Show answer details

    Correct answer: C

    A 'clock skew' error means there is a time difference between the system that issued the token (the IdP) and the system validating it (API Connect Gateway). This can cause validation of the nbf (not before) and exp (expiration time) claims to fail even if the token is technically valid. The JWT validation policy has an 'Allowed clock skew' setting to define a tolerance in seconds to account for these minor time discrepancies. The best practice is to set a small, reasonable value, not to accept expired tokens.

  2. 2

    A healthcare organization is exposing a patient data API that must comply with strict auditing requirements. They need to log the entire request and response payload for every transaction. Which built-in policy is designed for this purpose?

    Show answer details

    Correct answer: C

    The activity-log policy is the designated policy for capturing transaction data and sending it to the analytics service. It can be configured to capture headers, the entire message body (payload), or just specific parts of the transaction for later analysis and auditing in the API Connect analytics dashboards.

  3. 3

    A Provider Organization Owner is configuring a new Catalog. They want to ensure that all consumer organization registrations and all new application subscriptions require manual approval by an administrator. Where are these approval settings configured?

    Show answer details

    Correct answer: C

    The default approval requirements for a Developer Portal are managed at the Catalog level. Within the Catalog's settings, the 'Self-service onboarding' section contains checkboxes to enable or disable automatic approval for new user registrations and new application subscriptions. Unchecking these boxes enforces a manual approval workflow.

  4. 4

    When creating a REST API by importing an existing WSDL file, what is the primary role of the assembly that API Connect generates automatically?

    Show answer details

    Correct answer: B

    When generating a REST API from a WSDL, API Connect's main task is to act as a transformation bridge. The automatically generated assembly contains Map policies (or other transformation logic) that convert the incoming RESTful request (typically JSON) into the SOAP XML envelope expected by the backend. It then invokes the SOAP service and performs the reverse transformation on the response, converting the SOAP XML back into JSON for the client.

  5. 5

    An API goes through several stages in its lifecycle within API Connect. Based on the provided diagram, which action triggers the transition of an API from the 'Staged' state to the 'Published' state?

    stateDiagram-v2 [*] --> Identified Identified --> Staged: Stage Staged --> Published: ??? Published --> Deprecated: Deprecate Published --> Superseded: Supersede Deprecated --> Retired: Retire Retired --> [*]

    Show answer details

    Correct answer: B

    The 'Publish' action is the explicit step taken by an API Product Manager or other authorized role to make an API Product available for discovery and subscription in the Developer Portal. This action moves the Product from the 'Staged' state, where it might be undergoing final testing in a Catalog, to the 'Published' state, making it live for consumers.

  6. 6

    A financial services company is using IBM API Connect to manage access to its core banking services. They have implemented a global policy to log all transaction requests for auditing. However, for a new 'Loan Application' API, they must prevent sensitive applicant data (e.g., social security number) from being written to the logs while still being passed to the backend system. The logging policy is a global post-request policy. What is the most effective way for the API developer to meet this requirement without altering the global policy?

    Show answer details

    Correct answer: B

    The Redact policy is specifically designed for removing or masking sensitive data from a message payload. By placing it in the API's assembly flow, it will process the message before control is passed to any global policies. Since the logging is a post-request (meaning response flow) global policy, redacting the data in the API's response flow is the correct and most efficient solution. GatewayScript could achieve this but is more complex to implement and maintain. A Map policy is for transformation, not redaction. The Redact policy cannot be applied to the Activity Log policy directly.

  7. 7

    A large enterprise has adopted IBM API Connect for multiple lines of business (LOBs), including Retail, Insurance, and Wealth Management. The enterprise architect's mandate is to provide each LOB with the ability to manage its own set of APIs, Products, developers, and a branded developer portal. However, a set of core 'Customer Profile' APIs, managed by a central IT team, must be made available for use by all LOBs in their respective Products. What is the most appropriate API Connect topology to fulfill these requirements?

    Show answer details

    Correct answer: C

    This scenario is the primary use case for Syndication. Creating separate Catalogs provides the required isolation for each LOB, including a distinct developer portal and consumer base. Syndication allows a Product published in one Catalog (the central master) to be shared and made available in other Catalogs (the LOBs). This avoids duplicating the API definitions and allows for centralized management of the core APIs while enabling decentralized consumption. Spaces provide isolation but share a single developer portal, which does not meet the requirement.

  8. 8

    An API developer is troubleshooting an OAuth2 authorization code flow. The client application successfully redirects the user to the authorization server, the user authenticates, but the subsequent token exchange request fails. The trace reveals the token endpoint returns an invalid_grant error. The developer confirms the authorization code is correct and has not expired. Which of the following is the most likely cause of this specific error in this context?

    Show answer details

    Correct answer: C

    According to the OAuth 2.0 specification (RFC 6749), if the redirect_uri parameter was included in the initial authorization request, it MUST also be included in the token request, and the values must be identical. A mismatch is a common cause for an invalid_grant error, as it prevents authorization code injection attacks. While other issues can cause this error, the redirect_uri mismatch is a frequent and subtle problem in this specific flow.

  9. 9

    A developer is creating a user-defined policy that needs to access a secure configuration value, such as an external service's API key. To avoid hardcoding this secret in the policy's implementation (e.g., GatewayScript), the developer wants to use a property that can be set in the API assembly. How should the property be defined in the policy's YAML file to ensure it is treated as a password, meaning its value is obfuscated in the API Connect user interfaces?

    Show answer details

    Correct answer: B

    In the YAML definition file for a user-defined policy, when defining a property in the properties section, you can add format: password to a property of type: string. This instructs the API Connect UI to render the input field as a password field (obfuscating the value with asterisks or dots) and to handle the value as a secret.

  10. 10

    A DevOps engineer needs to automate the deployment of API Products to different environments (Development, Staging, Production). Each environment has a different backend service URL for a specific API. Which combination of API Connect features should be used to manage these environment-specific URLs without modifying the OpenAPI definition for each deployment?

    Show answer details

    Correct answer: C

    This is the standard best practice for managing environment-specific configurations. By defining a property in the API definition, you create a variable. This property can then be assigned a specific value at the Catalog level. When the API is published to the 'Development' Catalog, it uses the 'Development' value. When published to 'Production', it uses the 'Production' value. The Invoke policy in the assembly then references this property (e.g., $(backend_url)), allowing a single API definition to be promoted across environments without modification.

Create an account to continue.