C1000-197 IBM Guardium Data Protection v12.x Administrator - Professional Practice Questions
Prepare for C1000-197 with more than an answer.
- 1
A network security specialist is reviewing firewall rules between a newly deployed managed collector and the Central Manager. In a standard Guardium Data Protection v12.x deployment, which TCP port must be open for communication initiated from the managed collector to the Central Manager?
Show answer details
Correct answer: C
In Guardium v12.x architecture, managed units (collectors and aggregators) communicate back to the Central Manager over TCP port 9983. Communication from the Central Manager out to managed units in default mode utilizes TCP port 8983. Port 8443 is typically used for GUI/HTTPS access, enterprise load balancing, and S-TAP to CM registration, while port 161 is standard SNMP.
- 2
True or False: When entering a Logstash filter configuration into the Universal Connector Filter Configuration field in the Guardium user interface, you must include the enclosing 'filter { ... }' wrapper tags.
Show answer details
Correct answer: B
According to the Guardium Universal Connector configuration documentation, when pasting your Logstash filter configuration (.conf file contents) into the GUI 'Filter Configuration' field, you must omit the outer 'filter {' keyword and its closing '}' bracket. The Guardium engine automatically wraps the input in the necessary Logstash block structure during deployment; including the outer filter wrapper results in a syntax error.
- 3
A security analyst needs to customize an out-of-the-box Configuration Auditing System (CAS) template set for Oracle on Linux to monitor changes to custom initialization parameters. Upon opening the default template set, the analyst finds that the edit options are unavailable. What is the standard Guardium operational procedure required to modify default CAS template sets?
Show answer details
Correct answer: A
Default CAS template sets provided by IBM Guardium are read-only and cannot be modified directly. To customize monitoring parameters, an administrator must clone the desired default template set, modify the cloned template set (adding, removing, or adjusting monitored items such as files, scripts, or environment variables), and then apply the cloned set to the monitored hosts. Default template sets cannot be unlocked via CLI commands or direct database updates.
- 4
A database security architect is deploying a fresh virtual appliance intended to serve as a secondary Central Manager and Aggregator in a multi-collector enterprise environment. Before configuring feature modules such as Data Activity Monitoring (DAM) and Vulnerability Assessment (VA), the architect must apply the appropriate license files. What is the mandatory licensing sequence and requirement for this appliance?
Show answer details
Correct answer: C
In IBM Guardium Data Protection v12.x, every newly deployed appliance requires a base license key (also termed a reset key) that establishes the machine role—either Collector (for standalone units/collectors) or Aggregator (for aggregators/central managers). Base licenses validate appliance role compatibility but do not activate functional security modules. Feature modules (such as DAM Standard/Advanced or VA Standard) require one or more append licenses, which can only be applied after the base license is successfully installed and the license agreement is accepted. Append licenses cannot provision base appliance roles, and Collector base keys cannot be converted to Aggregator roles without applying an Aggregator base key.
- 5
A security engineer plans to enable the Real-Time Trust Evaluator on a Central Manager to identify untrusted database client activities, such as cleartext credential transmissions and brute-force connection floods. Which automatic system action occurs immediately when the Real-Time Trust Evaluator is switched from Disabled to Enabled in the Guardium console?
Show answer details
Correct answer: C
When Real-Time Trust Evaluator is enabled in Guardium v12.x, the appliance automatically activates the probability engine, begins learning/training routines for anomaly detection, and installs a pre-configured security incident policy (by default, 'Real-time trust evaluator: incidents related to all users', which can optionally be changed to monitor admin users only). Disabling the feature automatically uninstalls this policy. It does not reboot inspection engines, create CAS template sets, or inject S-GATE blocking rules.
- 6
A procurement team is budgeting for an expansion of IBM Guardium Vulnerability Assessment (VA Standard) across an enterprise hybrid cloud architecture. Which licensing metric is used by IBM to determine the required entitlement capacity for Guardium Vulnerability Assessment?
Show answer details
Correct answer: B
Guardium Vulnerability Assessment entitlements are calculated using the Managed Virtual Server (MVS) licensing metric, determined by the total number of physical or virtual database servers evaluated by VA scan jobs. It is not licensed by Authorized Users (which applies to user access seats in certain legacy tools), total database storage capacity (TB), or S-TAP agent connection counts (since VA performs agentless JDBC connections).
