IBM C2180-274 Exam
IBM WebSphere DataPower SOA Appliances Firmware V5.0 Solution Implementation Exam (Page 5 )

Updated On: 1-Feb-2026

A solution implementer is tasked with securing a backend web service by creating an externally advertised web service interface that will: ?easilyadapt to any backend changes. ?conform to the backend service Web Service Description Language (WSDL) document. ?monitor and control message traffic based on consumer and requested resources to the WSDL operation level. What DataPower service should the solution implementer configure to satisfy these requirements?

  1. Web service proxy using the WSDL with a dynamic backend.
  2. Web application firewall with operations imported directly from the WSDL.
  3. Multi-protocol gateway using a WSDL with a sign/verifyactions.
  4. Loopback XML firewall with a user agent subscribed to a WSDL.

Answer(s): A



A solution implementer needs to integrate the following security profile.


What must the solution implementer do to a message to satisfy this policy?

  1. Encrypt and sign the body of the message.
  2. Encrypt the body and header. Sign BOTH body and header.
  3. Encrypt the body, sign the message and usean X.509 Token.
  4. Encrypt the body, sign the Parts, and use an UsernameToken.

Answer(s): C



A service needs to be configured on the DataPower appliance to allow a client to share access to aprivate resource. This sharing must be done without the sharing of user credentials. A solution implementer has decided to implement an OAuth solution for the customer. Which of the following are available to the solution implementer to implement OAuth?(choose 3)

  1. AAA action
  2. SSL proxy profile
  3. Web Token Service
  4. 1-legged authentication
  5. OAuth client and OAuth client group
  6. OAuth open source DataPower plug-in

Answer(s): A,C,E



A solution implementer has been provided the following securityrequirements to implement a solution for a company to transact business with its business partners. ?Message Confidentiality - none can see the message in transit in clear text between the company and partner end points ?Message Integrity - no man-in-the-middle tampered with the message between the company and partner end points ?Non-repudiation - be able to verify the senders are who they say they are What actions should the solution implementer take to satisfy all the requirements?

  1. Use SSL and createa digital signature solution with sign and verify actions.
  2. Use SSL and create an asymmetric encryption on the message with encrypt and decrypt actions.
  3. Use SSL since it satisfies all the requirements without the use of either encrypt/decrypt actionsor sign/verify actions.
  4. Use symmetric encryption and share the encryption key with the partner for both request and response.

Answer(s): A



A customer wants to protect communication between two WebSphere DataPower Appliances against a replay attack. The second DataPower appliance needs to validate that the message received from the first appliance has spent no more than 30 seconds in transit. How should the solution implementer satisfy this requirement?

  1. Set the var://service/transaction-timeout variable on the first DataPower appliance to30 seconds.
  2. Configure mutually authenticated SSL between the two DataPower appliances with an SSL timeout field configured to 30 seconds.
  3. Use symmetric key encryption using an encrypt-string extension function on a timestamp string on the first DataPower appliance. Then use the same key with a decrypt- string extension function on the second appliance and validate the timestamp.
  4. Use symmetric key encryption using an encrypt-string extension function on a timestamp string on the first DataPower appliance. Then use the public certificate from the first device with a decrypt-string extension function on the second appliance and validate the timestamp.

Answer(s): C



Viewing page 5 of 16
Viewing questions 21 - 25 out of 75 questions



Post your Comments and Discuss IBM C2180-274 exam prep with other Community members:

Join the C2180-274 Discussion