C1000-196 IBM DataPower Gateway v10.x Administrator - Professional Practice Questions
Prepare for C1000-196 with more than an answer.
- 1
An administrator is configuring high availability using Standby Control across two DataPower Gateway appliances. According to IBM official guidelines, what recommendation is specified regarding the 'standby-preempt' setting?
Show answer details
Correct answer: D
IBM DataPower documentation explicitly advises: 'Do not enable preemption'. Enabling preemption can cause virtual IP flapping if an appliance undergoes transient reboots or flapping network connections, disrupting in-flight transactions unnecessarily.
- 2
A systems architect is deploying IBM DataPower Gateway for Linux on two Red Hat Enterprise Linux (RHEL) bare-metal servers. The networking team intends to utilize Standby Control to manage a shared virtual IP (VIP) and enable Self-Balancing using the Application Optimization feature.
During testing, the team observes that the standby control daemon fails to initialize properly, and network traffic directed to the VIP experiences packet drops. Further inspection reveals that the host operating system is running local firewalld services, and 'datapower.conf' retains default values.
Which architectural constraint and configuration adjustment must the administrator address to successfully implement Standby Control on DataPower Gateway for Linux?
flowchart TD Host[RHEL Host OS] --> Conf{datapower.conf: EnableStandbyControl=true} Conf -->|Disabled| Fail[Standby Control Inactive] Conf -->|Enabled| Kernel[DataPower Takes Control of iptables & ip_vs] Kernel --> FW{Host Firewall Running?} FW -->|Yes| Conflict[Conflict: Host Firewall Blocks Standby] FW -->|No| Success[Standby Control Functional] Success --> Bal{Self-Balancing Requested?} Bal -->|Yes| Unsupported[Unsupported on Linux Form Factor]Show answer details
Correct answer: B
On DataPower Gateway for Linux, Standby Control is disabled by default and requires setting 'EnableStandbyControl=true' in datapower.conf. When enabled, the host firewall cannot be run because DataPower takes full control of the iptables and ip_vs subsystems. Furthermore, Self-Balancing (which requires Application Optimization) is explicitly unsupported on the Linux platform.
- 3
A security administrator is planning a disaster recovery procedure using the CLI command 'secure-backup "" [include-raid]'. Which cryptographic limitation and platform constraint apply to this command?
Show answer details
Correct answer: A
IBM DataPower Gateway documentation mandates that the certificate used to encrypt private data in a 'secure-backup' package cannot contain an ECDSA key (RSA must be used). Furthermore, the 'secure-backup' command is not supported on the Docker platform.
- 4
When an administrator executes a complete 'secure-backup' on a physical IBM DataPower Gateway appliance, which critical items are excluded from the encrypted backup package?
Show answer details
Correct answer: D
In DataPower Gateway, 'secure-backup' captures configuration, internal files, certificates, and optional RAID data. However, HSM private keys (which never leave the physical module unencrypted) and IPMI user passwords stored in the Baseboard Management Controller (BMC) are never included in the backup package.
- 5
An enterprise DataPower administrator is architecting a logging infrastructure across 40 application domains on an IBM DataPower Gateway appliance. When planning the allocation of log target objects, what system capacity ceiling and domain initialization behavior must the administrator account for?
Show answer details
Correct answer: C
IBM DataPower Gateway supports a global system limit of 1004 log targets. Whenever a new application domain is instantiated, DataPower automatically creates 2 log targets for that domain by default (default-log and webgui-log). Understanding this baseline is critical for capacity planning when deploying dozens of administrative domains.
- 6
When configuring event subscriptions on a DataPower log target using the CLI command 'logging event ', which behavior correctly describes how the gateway processes the configured priority threshold?
Show answer details
Correct answer: A
In DataPower Gateway, setting an event subscription priority threshold captures all events at or above that severity level. The priority hierarchy in descending order is emerg, alert, critic, error, warn, notice, info, and debug. For example, subscribing at 'error' captures 'error', 'critic', 'alert', and 'emerg' events.
