C1000-150 IBM Cloud Pak for Business Automation V21.0.3 Administration Practice Questions
Prepare for C1000-150 with more than an answer.
- Exam fee
- $200 USD
- Level
- Administrator
- Valid for
- Not specified
Domains covered on the exam 5
- Planning and Install26%
- Troubleshooting27%
- Security17%
- Resiliency10%
- Management20%
- 1
Case Study
A healthcare provider is deploying IBM Cloud Pak for Business Automation v21.0.3 to automate patient intake and records management. They have a strict security policy that requires all external access to be encrypted with company-issued certificates and all user authentication to be handled by their on-premises Active Directory.
Their OpenShift cluster is running in a public cloud, and the on-premises Active Directory is connected via a secure VPN. The security team has provided a wildcard TLS certificate (
*.apps.healthcare.com) and its private key. The team wants to ensure that all CP4BA web interfaces (e.g., Navigator, BAW Portal) are accessible via HTTPS using this certificate.Requirements:
- Replace the default self-signed certificates for all external routes with the company-issued wildcard certificate.
- Integrate the platform with the on-premises Active Directory for user authentication.
- Ensure the connection to Active Directory is secure using LDAPS.
Which approach correctly addresses all these requirements?
Show answer details
Correct answer: D
This is the correct, operator-managed approach. The CP4BA operator is designed to handle these configurations via the Custom Resource. Specifying the TLS secret in
sc_ingress_tls_secret_nametells the operator to apply this certificate to all created routes. Thespec.ldap_configurationblock is the designated place to configure the connection to an external directory like Active Directory, including support for LDAPS and providing necessary credentials and trust certificates via Kubernetes secrets. - 2
What is the role of the
ibm-cp4a-operatorin a multi-pattern deployment that includes both Business Automation Workflow (BAW) and FileNet Content Manager (FNCM)?Show answer details
Correct answer: B
The
ibm-cp4a-operatoris the primary or 'meta' operator for the Cloud Pak. It reads the singleICP4AClusterCustom Resource. Based on the capabilities enabled in the CR (e.g.,baw_configurationandfncm_configuration), it then triggers and manages the underlying component operators and resources, ensuring they are deployed correctly and integrated with each other and with the foundational services. - 3
To view the logs of the previously terminated instance of a pod named
baw-server-0that has been restarted due to a failure, an administrator should use which command?Show answer details
Correct answer: C
The
--previous(or-p) flag for theoc logscommand is used to retrieve the logs from the last, terminated instance of a container within a pod. This is essential for troubleshootingCrashLoopBackOfferrors, as it allows the administrator to see the error messages that caused the container to crash before it was restarted. - 4
What is the primary role of Apache Flink within the Business Automation Insights (BAI) component?
Show answer details
Correct answer: D
Apache Flink is the stream processing engine at the core of BAI. It consumes raw event streams from Kafka, executes processing jobs to aggregate, correlate, and summarize this data in real-time, and then writes the resulting summaries to Elasticsearch. This processed data is what powers the dashboards and analytics in BAI.
- 5
The following diagram shows two common installation flows for IBM Cloud Pak for Business Automation. Which step is unique and essential to Flow B?
flowchart TD subgraph Flow A [Online Installation] A1[Configure CatalogSource for IBM Registry] --> A2[Create Subscription] A2 --> A3[Operator Installs] A3 --> A4[Apply Custom Resource] end subgraph Flow B [Air-Gapped Installation] B1[Mirror Images & CASE to Private Registry] --> B2{Step X} B2 --> B3[Create Subscription] B3 --> B4[Operator Installs] B4 --> B5[Apply Custom Resource] endShow answer details
Correct answer: C
In an air-gapped installation (Flow B), after mirroring the necessary content, the OpenShift cluster must be told where to find the operator catalogs. This is done by creating a CatalogSource object that points to the index image that was mirrored to the private registry. This step is unnecessary in an online installation (Flow A), where the CatalogSource points directly to the public IBM Entitled Registry.
- 6
A financial services firm is deploying IBM Cloud Pak for Business Automation v21.0.3 in a fully air-gapped environment. The administrator has already mirrored the required container images to a private registry. However, the operator installation fails, and the logs indicate that it cannot find the CASE package. What is the most likely cause of this failure?
Show answer details
Correct answer: C
In an air-gapped installation, the Operator Lifecycle Manager (OLM) needs to know where to find the operator bundles (defined in CASE packages). This is achieved by creating a CatalogSource that points to an index image mirrored in the private registry. If the CatalogSource still points to the public IBM registry, the operator installation will fail because the cluster cannot reach the external internet to pull the package metadata.
- 7
During a security review, an administrator is tasked with ensuring that the Business Automation Workflow (BAW) component can only communicate with its dedicated PostgreSQL database pods and not with any other pods in the namespace. Which of the following actions is the most effective way to enforce this policy?
Show answer details
Correct answer: B
The standard Kubernetes/OpenShift security model for network traffic is to use NetworkPolicies. A default-deny policy on ingress traffic to all pods provides a baseline. Then, a specific egress policy can be applied to the BAW pods (selected by labels) that explicitly allows outbound traffic only to the database pods (also selected by labels) on the required database port. This provides fine-grained, least-privilege network access.
- 8
A user reports extremely slow document retrieval from FileNet Content Manager (FNCM). An administrator observes high CPU utilization on the CPE (Content Platform Engine) pods. Initial log analysis of
systemout.logdoes not show any authentication errors. Which log file should the administrator investigate next to identify potential performance bottlenecks related to queries or long-running operations?Show answer details
Correct answer: B
While
systemout.logis for general application server messages andp8_server_error.logis for errors, thep8_server_trace.logis specifically designed for detailed tracing. By enabling appropriate trace subsystems (like Database or Search), an administrator can get granular details about SQL queries, their execution times, and other internal operations, which is crucial for diagnosing performance issues. - 9
When configuring a multi-zone, highly available deployment for Operational Decision Manager (ODM), what is the primary purpose of setting pod anti-affinity rules in the deployment configuration?
Show answer details
Correct answer: B
Pod anti-affinity is a critical mechanism for high availability. It instructs the Kubernetes scheduler to avoid placing replicas of the same service (e.g., ODM Decision Center pods) on the same failure domain, such as a single worker node or an entire availability zone. This ensures that if a node or zone fails, other replicas of the service remain operational elsewhere, preventing a complete service outage.
- 10
An administrator needs to create a custom Grafana dashboard to monitor the JVM heap usage of all Content Platform Engine (CPE) pods over time to proactively identify memory leaks. Which Prometheus query would be the most appropriate source for this data?
Show answer details
Correct answer: C
This Prometheus query specifically targets the metrics exposed by the JVM itself. It filters for memory usage (
jvm_memory_used_bytes), narrows it down to theheapmemory area, and selects only the pods whose names start withcpe-, which corresponds to the Content Platform Engine pods. This provides the most accurate measure of application-level heap usage, distinct from the overall container memory.
