It is impossible to pass IBM C2150-609 exam without any help in the short term. Come to Pass4sure soon and find the most advanced, correct and guaranteed IBM C2150-609 practice questions. You will get a surprising result by our Replace IBM Security Access Manager V9.0 Deployment practice guides.
IBM C2150-609 Free Dumps Questions Online, Read and Test Now.
NEW QUESTION 1
How should the disk space occupied by the several large support files be reduced?
- A. Configure automatic roll over of support files using the LMI
- B. Download the support files and delete them from the appliance
- C. Download the support files which will also delete them from the appliance
- D. Configure support file retention policy using the LMI to restrict, such that files older than a certain date are purged
Answer: A
NEW QUESTION 2
An IBM Security Access Manager (ISAM) V9.0 environment is defined with multiple WebSEAL servers defined for high availability. They protect the same set of backend junctions.
Which parameter needs to be configured in each WebSEAL's configuration file to force all replicated WebSEAL servers to perform authorization checks against the same protected object space?
- A. host-name
- B. server-name
- C. domain-name
- D. virtual-host-name
Answer: C
NEW QUESTION 3
A deployment professional in charge of a large deployment with replicated reverse proxy instances needs to keep junctions, template files, and configuration settings in sync between the instances.
How can this be done?
- A. Setup appliance clustering and issue server sync all
- B. Setup appliance clustering and issue server cluster sync
- C. Setup a master reverse proxy instance and issue server task source-instance sync target-instance
- D. Setup a master reverse proxy instance and issue server task target-instance sync source-instance
Answer: AB
NEW QUESTION 4
A deployment professional creates a support file on an IBM Security Access Manager V9.0 appliance. What is its purpose?
- A. For backup and recovery
- B. To re-image the appliance
- C. To help troubleshoot problems with the appliance
- D. To capture a snapshot of the appliance configuration
Answer: B
NEW QUESTION 5
An OAuth client intermittently receives an error related to maximum number of tokens exceeded. What property should be adjusted to prevent this error?
- A. Set the strictjimit to variable
- B. Set least_recently_used to true
- C. Increase limit_oauth_tokens_per user_per_client
- D. Increase max_oauth_tokens_per_user_per_client
Answer: D
NEW QUESTION 6
A customer is deploying an IBM Security Access Manager V9.0 solution to protect back end resources and is planning to use an LDAP Server that is set up to use SSL server authentication.
What is required to enable SSL to secure communications with LDAP?
- A. LDAP server's private key
- B. LDAP server's public key stash file
- C. LDAP server's CA signer certificate
- D. LDAP server's private and public key
Answer: C
NEW QUESTION 7
As part of installing a fixpack a deployment professional wants to back up the appliance configuration. How is this done?
- A. Click on the Create Backup link of the active partition
- B. Select the active partition, select the Backup option from the Edit menu
- C. Create a new snapshot, download the snapshot to the deployment professional's workstation, install the fixpack
- D. Install the fixpac
- E. The installation will copy the configuration and install the fixpack to the inactive partition, set it active and restart
Answer: A
NEW QUESTION 8
In an IBM Security Access Manager (ISAM) V9.0 Federated SSO flow, the ISAM V9.0 appliance is used as the Service Provider. The SSO is I DP initiated. The I DP initiated unsolicited SSO doesn't have the target URL specified where Service Provider should be sending the user after consuming the SAML2.0 Assertion. The implementer of the SSO provider has been given the task of providing Target URL through a mapping rule in the Service Provider configuration.
How should this requirement be achieved in the mapping URL?
- A. login-redirect in <webseald>.conf
- B. local-response-redirect in <webseald>.conf
- C. itfim_override_targeturl in <serviceprovidermapping>.js
- D. ITFIM attribute target_url in <serviceprovidermapping>.xslt
Answer: D
Explanation:
A deployment professional has created an Access Control Policy to protect sensitive business information, but is not obtaining the desired result.
NEW QUESTION 9
The customer directory environment includes two Active Directory (AD) Domain Controllers (DC) managing separate suffixes (one for corporate users, one for field offices), and one occurrence of Oracle Directory Server (ODS). The business requirement states the AD for corporate users is optional and the environment should remain available even if this DC is down. There are no duplicate users across these directories.
After configuring all directories in the Secure Web Settings -> Runtime Component -> Manage -> Federated Directories, how can this requirement be achieved?
- A. Edit the resulting Idap.conf and add the "ignore-if-down = yes" to the AD for the corporate.
- B. Ensure the "Required" checkbox is checked for both the field office AD and the ODS server.
- C. Edit the resulting Idap.conf and add the "max-server-connections = 0" to the AD for the corporate.
- D. Edit the resulting Idap.conf and add the "ignore-if-down = yes" to the AD for the field offices and ODS server.
Answer: A
NEW QUESTION 10
A company has deployed an IBM Security Access Manager V9.0 solution for protecting web resources and has enabled auditing for monitoring purposes. A security deployment professional has observed that audit records are using large quantities of disk space due to the large number of audit events related to HTTP access.
Which two strategies will help to reduce the volume of audit events in above scenario? (Choose two.)
- A. Generate audit records for specific groups only
- B. Generate events for unsuccessful HTTP accesses only
- C. Generating selective audit records using authorization rules
- D. Reconfigure WebSEAL to use CARS auditing, instead of native auditing
- E. Selectively disable the generation of events by using attached protected object policies (POPs)
Answer: CD
NEW QUESTION 11
Users are experiencing authentication failures. They are opening a large number of Help Desk tickets. Which message severity level should a deployment professional be looking for in the message log?
- A. Error message
- B. Fatal message
- C. Notice message
- D. Warning message
Answer: B
NEW QUESTION 12
IBM Security Access Manager V9.0 will be configured as Service Provider (SP) in a SAML Federation. The same user that logs in at the Identity Provider (IdP) will be logged in fen the SP side after the Single Sign-On, for example UserA on IdP will be UserA on the SP side.
Which name identifier format meets this requirement?
- A. transient
- B. persistent
- C. principalName
- D. emailAddress
Answer: B
NEW QUESTION 13
The customer currently maintains all its users in Active Directory. As part of its new IBM Security Access Manager (ISAM) V9.0 deployment, the customer understands it will have to implement the ISAM "Global Sign-on (GSO)" to achieve SSO with certain backend applications which do their own authentication and cannot be modified.
Which federated repositories configuration will address the customer requirements?
- A. Use an external ISDS LDAP as the ISAM Primary LDAP, federate with the AD and import all AD users into the ISAM TDS
- B. Configure the AD as the ISAM Primary LDAP, which will create the necessary secauthority=default suffi
- C. Import all users into the ISAM AD
- D. Use the ISAM embedded LDAP as the Primary LDAP, federate with the AD and configure "basic user", and specify "basic-user-principal-attribute = samAccountName"
- E. Use an external ISDS LDAP as the Primary LDAP, federate with the AD, configure "basic user”, specify "basic-user-principal-attribute = samAccountName" and "basic-user-search-suffix = secauthority=default"
Answer: B
NEW QUESTION 14
The SSL connection from browser to the IBM Security Access Manager V9.0 Reverse Proxy is broken and the deployment professional suspects an expired certificate.
In which location will the "Certificate expired" warning message that contains additional information to isolate the issue be seen?
- A. LMI Home Dashboard
- B. Systems message log
- C. pdweb.debug trace file
- D. Reverse proxy request log
Answer: A
NEW QUESTION 15
In a customer environment, a REST API client is being developed to carry out Reverse Proxy configuration and maintenance. As part of one of the activities the customer needs to update the junction information with an additional Backend Server. The customer has written a REST API client but is not able modify the junction.
Which HTTP headers should the customer pass?
- A. Host, Authorization
- B. Host, Accept: Application/json
- C. Authorization, Accept:Application/json
- D. content-type:application/json, Authorization
Answer: C
NEW QUESTION 16
The IBM Security Access Manager V9.0 deployment professional has enabled the Reverse Proxy pdweb.sescache statistic to troubleshoot a problem.
What is the problem?
- A. HTTP sessions are being timed out prematurely.
- B. HTTP requests are taking longer than expected.
- C. User sessions are terminated sooner than expected.
- D. Document caching is not as effective as anticipated.
Answer: B
NEW QUESTION 17
An IBM Security Access Manager V9.0 deployment professional is charged with monitoring request response times from WebSEAL to the backend. The deployment professional wants the flexibility to see response times per request, per junction, per HTTP return code, or other criteria that may come up in the future.
What action will generate the required data for this analysis?
- A. Customize the request.log to include response times
- B. Run pdadmin "stats get pdweb.jct" on all junctions on a regular basis
- C. Run pdadmin "stats get pdweb.https" and "stats get pdweb.http" on a regular basis
- D. Write a REST API script to pull "application interface statistics" on a regular basis
Answer: D
NEW QUESTION 18
A system is configured with two IBM Security Access Manager (ISAM) V9.0 reverse proxy servers behind a load balancer, and it is planned to use forms-based user authentication. It is a requirement that if a reverse proxy were to fail, users that were already logged in would not be required to log in again.
Which two configurations can the deployment professional use to achieve this? (Choose two.)
- A. Configure the system to use LTPA cookies
- B. Configure the system to use session cookies
- C. Configure the system to use failover cookies
- D. Configure the system to use the global signon (GSO) cache
- E. Configure the system to use the Distributed Session Cache (DSC)
Answer: AB
NEW QUESTION 19
What out-of-the-box feature of IBM Security Access Manager (ISAM) V9.0 enables invalidating a defined collection of back-end server generated HTTP cookies when the user logs off WebSEAL?
- A. cookie jar
- B. /pkmslogout
- C. logout-remove-cookie attribute in webseal.conf
- D. -k option on junction create command (server task create)
Answer: C
NEW QUESTION 20
A company has deployed an IBM Security Access Manager V9.0 solution to protect web resources and now wants to secure access to enterprise resources from mobile devices. The security deployment professional needs to run a utility to configure the existing WebSEAL with the instance of the appliance that provides the authorization server for Advanced Access Control.
Which utility tool will perform this configuration?
- A. isamcfg
- B. pdadmin
- C. Web Administration Tool (WAT)
- D. Middleware Configuration Utility
Answer: A
NEW QUESTION 21
......
100% Valid and Newest Version C2150-609 Questions & Answers shared by Dumpscollection.com, Get Full Dumps HERE: https://www.dumpscollection.net/dumps/C2150-609/ (New 137 Q&As)