C1000-138 Sample Questions

C1000-138 Sample Questions & Answers

Building SOAP, REST and GraphQL APIs as a developer is weighted heaviest, alongside lifecycle management and governance, catalog and security administration for provider organizations, product and plan management, and running the developer portal.

Launch the full C1000-138 simulator →

Showing 10 of 20 free samples.

  1. Question 1Beginner

    API Product Manager Role · Distinguish between the various lifecycle stages of APIs and Products

    True or False: When an API Product is moved to the 'Deprecated' lifecycle state, any existing application subscriptions to its Plans are immediately disabled, and API calls will fail.

    Show answer & explanation

    Correct answer: B

    The statement is false. The 'Deprecated' state serves as a notice to consumers that the Product will be retired in the future. Existing subscriptions remain active, and API calls will continue to succeed. However, no new applications can subscribe to the Plans within the deprecated Product. This provides a grace period for consumers to migrate to a new version before the Product is eventually 'Retired', at which point calls would fail.

  2. Question 2Intermediate

    API Developer Role · Create and configure GraphQL

    A developer is implementing a GraphQL API proxy in API Connect for a backend GraphQL service. The requirement is to prevent certain expensive or sensitive fields in the GraphQL schema from being queryable by consumers. Which API Connect feature should be used to achieve this without modifying the backend service?

    Show answer & explanation

    Correct answer: B

    API Connect provides the @hide directive as a specific feature for GraphQL API proxies. By adding this directive to fields or types in the schema within the API definition, API Connect will automatically remove them from the schema exposed to consumers. This prevents those fields from being included in introspection queries and invalidates any incoming requests that attempt to query them, effectively hiding them without backend changes.

  3. Question 3AdvancedSelect 2

    Provider Organization Owner Role · Configure API Security related Resources (OAuth2, User registry, TLS profiles)

    A provider organization owner needs to configure mutual TLS (mTLS) for a specific Catalog. This requires the API Gateway to present its own certificate to backend services and to validate certificates presented by clients. Which TWO resources must be configured in the Cloud Manager or API Manager to enable this? (Select TWO).

    Show answer & explanation

    Correct answers: B, C

  4. Question 4Beginner

    API Developer Role · Use the IBM API Connect Developer Toolkit Command Line Interface (CLI)

    A developer is using the apic toolkit CLI to work on an API project locally. Which command should be used to validate the project's YAML definition files against the OpenAPI specification and check for API Connect-specific errors without connecting to a management server?

    Show answer & explanation

    Correct answer: C

    The apic validate command is specifically designed for local validation of project files. When run from the project directory, it checks the syntax and structure of the product.yaml and any referenced api.yaml files, reporting errors or warnings without requiring a connection to an API Connect server. This is a crucial step in a local development workflow before attempting to publish.

  5. Question 5Intermediate

    API Product Manager Role · Administer Applications and Subscriptions

    An API Product Manager for an e-commerce company is analyzing API usage data. They notice that a key partner is frequently hitting the rate limit for the 'Product Search' API, leading to failed requests and potential lost sales. The manager wants to offer this partner a higher limit without affecting other consumers on the same Plan. What is the most direct way to achieve this?

    Show answer & explanation

    Correct answer: B

    API Connect allows for plan overrides at the individual subscription level. This is the most efficient and targeted way to grant a specific application a different rate limit than the one defined in the general Plan. It avoids the overhead of creating new Products or Plans and doesn't require the consumer to make any changes on their end.

  6. Question 6Beginner

    API Developer Role · Leverage other assembly policies

    A developer is building an assembly flow that must perform a conditional action. If the incoming HTTP request header 'X-Transaction-Type' is 'Internal', a specific Map policy should be executed. Otherwise, a default Invoke policy should be called. Which flow control policy is best suited for implementing this logic?

    Show answer & explanation

    Correct answer: B

    The Switch policy is ideal for this scenario. It evaluates a value (in this case, request.headers.x-transaction-type) and executes a different sequence of policies for each matching case. It also includes an otherwise block for default actions. While an If policy could work, Switch is cleaner and more scalable if more transaction types are added later.

  7. Question 7Intermediate

    Developer Portal (Consumer and Administrator) · Administer portal customization

    A Developer Portal administrator needs to change the color scheme, logo, and fonts to match new corporate branding guidelines. Which of the following is the standard method for making these site-wide styling changes?

    Show answer & explanation

    Correct answer: C

    The Developer Portal uses a theming engine. The correct procedure is to download or export the existing theme, make modifications to its constituent files (like SASS variables, CSS, and templates) locally, package the modified theme into a .tgz file, and then upload it back to the portal. This ensures changes are properly applied and are not lost during portal upgrades.

  8. Question 8Intermediate

    API Developer Role · Use the debug and tracing capabilities

    During the debugging of an API assembly using the trace tool, a developer notices that a context variable set by a GatewayScript policy is not available in a subsequent policy. What is the most common reason for this behavior?

    Show answer & explanation

    Correct answer: B

    In GatewayScript, variables declared with var, let, or const are local to that script's execution scope. To make a value available to other policies in the assembly flow, it must be explicitly written to the API context using the apim.setvariable() or context.set() function. Forgetting to do this is a very common error, resulting in the variable being inaccessible to subsequent policies.

  9. Question 9Beginner

    API Developer Role · Create and configure a REST API (OpenAPI 2 & 3)

    What is the primary function of the x-ibm-configuration object in an OpenAPI 3.0 definition for an IBM API Connect proxy?

    Show answer & explanation

    Correct answer: C

    The x-ibm-configuration object is an OpenAPI extension used by IBM API Connect to store metadata and configuration that is not part of the standard OpenAPI specification. This includes the assembly definition (which contains the policy flow), API properties, target service definitions, CORS rules, and the gateway type (e.g., datapower-api-gateway).

  10. Question 10Beginner

    Overview of IBM API Connect · API and Product Governance

    Which statement accurately describes the relationship between an API, a Plan, and a Product in IBM API Connect?

    Show answer & explanation

    Correct answer: D

    The correct hierarchy is: APIs are the base technical implementation. One or more APIs are packaged into a Product, which is the unit of lifecycle management and visibility. Within the Product, you define one or more Plans (e.g., Basic, Premium). Each Plan specifies rate limits and which APIs/operations are accessible. A consumer application subscribes to a specific Plan within a Product to gain access.

Ready for the real thing?

The full C1000-138 simulator has every exam-style question, timed mode, and instant scoring.