A customer wants to protect communication between two WebSphere DataPower Appliances against a replay attack. The second DataPower appliance needs to validate that the message received from the first appliance has spent no more than 30 seconds in transit. How should the solution implementer satisfy this requirement?
A. Set the var://service/transaction-timeout variable on the first DataPower appliance to30 seconds.
B. Use symmetric key encryption using an encrypt-string extension function on a timestamp string on the first DataPower appliance. Then use the same key with a decrypt-string extension function on the second appliance and validate the timestamp.
C. Use symmetric key encryption using an encrypt-string extension function on a timestamp string on the first DataPower appliance. Then use the public certificate from the first device with a decrypt-string extension function on the second appliance and validate the timestamp.
D. Configure mutually authenticated SSL between the two DataPower appliances with an SSL timeout field configured to 30 seconds.
正解:B
質問 2:
A company wants to enforce the run-time SOA governance using service level agreement (SLA) and servicelevel definitions (SLD) policy attachments for a line of business. The solution implementer has configured a web service proxy service that uses a WebSphere Service Registry and Repository (WSRR) subscription to meet this requirement. The WSRR server hoststhe governance enablement profile that contains SLA and SLD entities. The SLA objects in WSRR are in SLA Active State. During a test run, it was identified that SLA policies from WSRR are not enforced. How can the solution implementer resolve this situation to enforce SLA policies? (choose 2) Verify that the:
A. WSRR server object is set to version 7.5 or later.
B. FetchPolicy Attachments option for the WSRR Subscription is set as "on".
C. SLA Enforcement Mode is set as "reject".
D. WS-Policy Enforcement Mode is set as "enforce".
E. SLA policies are accurate using probe.
正解:A,B
質問 3:
A solution implementer is configuring a AAA Policy to secure a DataPower service. Why would the solution implementer configure Mapping Authentication Credentials and Mapping Requested Resources in the DataPower AAA Policy? (choose 2)
A. To map the requested resource to the correct backend URL for dynamic message routing.
B. To map the requested resource from a legacy operation name to a new operation name to allow correctauthorization.
C. To map the authenticated credentials from a DN-formatted LDAP response to a username for Tivoli Access Manager(TAM) authorization.
D. To map the authenticated credentials to an alternative security token to insert into the message payload for authorization.
E. To map the authenticated credentials to mediate the security headers of two different protocols (for example from HTTP headers to MQMD).
正解:B,C
質問 4:
A solution implementer has created a Deployment Policy to scan through configuration objects when they are imported and to remove any references to appliance specific settings such as the Ethernet addresses. Which of the following Deployment Policy settings would provide this functionality? (choose two)
A. A Filtered Configuration with a list of the objects that are to be excluded.
B. An Accepted Configuration with a list of the correct values for the properties forany named objects that will be updated during import.
C. A Modified Configuration with rules specifying Delete Configuration for the object references to be removed on import.
D. A Filtered Configuration with a list of the objects that are to be included.
E. A Rejected Configuration with a list ofthe objects that must be rejected during import.
正解:A,C
質問 5:
A company has an extensive list of Miscellaneous XML Threats that they require protection from. The list includes: ?XML Entity Expansion and RecursionAttacks ?XML Wellformedness-based Parser Attacks ?Memory Space Breach and Buffer Overflow Attacks ?Public Key DoS Attacks ?Resource Hijack Attacks What must the solution implementer do to protect SOA Applications exposed via a WSDL and a Web Service Proxyservice?
A. Enable the web service proxy's ultiple Message XML Denial of Service (MMXDoS) Protection".Enable the web service proxy's ?ultiple Message XML Denial of Service (MMXDoS) Protection".
B. Web service proxy default options protect against these threats. No configuration is required.
C. Enable the web service proxy's QL Injection Protection?Enable the web service proxy's ?QL Injection Protection?
D. Enable the web service proxy's ingle Message XML Denial of Service (XDoS) Protection".Enable the web service proxy's ?ingle Message XML Denial of Service (XDoS) Protection".
正解:B
質問 6:
An multi-protocol gateway (MPGW) service is created to process a request message containing values for the MQMD.ReplyQ andMQMD.ReplyToQMgr that are not configured in the MPGW service. The back end service sends a SOAP message as response to the MPGW service that needs to be routed to the originating client using MQ Object Descriptor (MQOD) method. How can the solution implementer accomplish this requirement using the configured MPGW service?
A. Using Header Tab, inject service virtual headers named "ReplyToQ" and "ReplyToQM"
with the value of an empty string for the front end with a direction as "front"
B. Using XSLT, inject service virtual headers named "ReplyToQ" and "ReplyToQM" with
the value of an empty string inthe response rule as shown below:
<dp:set-response-header name="'ReplyToQ'" value="' '"/>
<dp:set-response-header name="'ReplyToQM'" value="' '"/>
C. Using Header Tab, inject service virtual headers named "ReplyToQ" and "ReplyToQM"
with the value of an empty string for the back end with a direction as "back"
D. Using XSLT, inject service virtual headers named "ReplyToQ" and "ReplyToQM" with
the value of an empty string in the request rule as shown below:
<dp:set-request-header name="'ReplyToQ'" value="' '"/>
<dp:set-request-header name="'ReplyToQM'" value="' '"/>
正解:B
質問 7:
A solution implementer has created a multi-protocol gateway to pass messages to a backend server. The complete contents of all request messages should be logged; performance is a high priority but the transaction should not fail if the log server is down. Which logging mechanisms should the solution implementer use to satisfy both requirements?
A. Add an MQ Log Target for the request message with an Object Filter referencing the service handling the request.
B. Add an Extract action to the start of the request rule for the message setting the XPath field to "/" toextract the complete request message.
C. Add a Log action to start of the request rule for the message and setthe Asynchronous option to On.
D. Add an SQL action to the start of the request rule for the message that uses an INSERT statement.
正解:C
質問 8:
The solution implementer needs to configure the DataPower appliance to restrict user account access to specific domains. The solution implementer implements this requirement by configuring the Domain Restriction section of the user account. During application execution, the configured user account is able to access a domain that is configured as restricted (no access allowed by this user). What should the solution implementer identify as a valid source of the problem?
A. An existing access policy or RBM policy can supersede the Domain Restriction list.
B. The user is a member of the 'root' user group.
C. The RBM system was not used to restrict access, which is the only way to meet the Domain Restriction requirement.
D. User access cannot be restricted to a specific domain in the user account configuration.
正解:A
843 お客様のコメント





来宫** -
C2180-274試験は無事に合格することができました。Pass4Testサンキュー