2V0-72-22 Sample Questions & Answers
Spring Boot's own features, properties and actuator carry the most weight, next to the core framework, Java config and profiles, Spring's JDBC layer and transactions, putting together web and REST endpoints, testing via MockMVC, and basic security setup.
Launch the full 2V0-72-22 simulator →Showing 10 of 20 free samples.
- Question 1Beginner
Spring Boot · Spring Boot Properties and Autoconfiguration
A Spring Boot application needs to connect to a database whose credentials are provided via environment variables
DB_URL,DB_USER, andDB_PASS. Theapplication.propertiesfile contains the following entries:spring.datasource.url=${DB_URL:jdbc:h2:mem:defaultdb}spring.datasource.username=${DB_USER:sa}spring.datasource.password=${DB_PASS:}If the
DB_USERenvironment variable is NOT set, butDB_URLandDB_PASSare, what value will be used for the datasource username?Show answer & explanation
Correct answer: B
The syntax
${PROPERTY:defaultValue}is used for property placeholders. If thePROPERTY(in this case, theDB_USERenvironment variable) is not found, thedefaultValue(sa) will be used instead. - Question 2Intermediate
Spring MVC · REST Applications
An architect is designing a REST API using Spring MVC. The API needs to return different JSON representations of a
Userobject depending on the endpoint. For example,/api/users/{id}should return all user fields, but/api/users/summaryshould return only theidandusername. What is the most appropriate Spring feature to implement this requirement without creating separate DTOs (Data Transfer Objects) for each view?Show answer & explanation
Correct answer: C
Jackson's
@JsonViewannotation, which is well-integrated with Spring MVC, is designed for this exact purpose. It allows you to define multiple 'views' (e.g., public, internal) on a single model object and then specify which view to use for serialization at the controller method level, enabling different JSON outputs from the same object. - Question 3Intermediate
Spring Core · Spring Bean Lifecycle
A developer needs to create a Spring bean that calculates a value based on other beans, but this calculation only needs to happen once at startup. The result should then be cached and injected into other components. Which combination of annotations and lifecycle callbacks is most suitable for this scenario?
Show answer & explanation
Correct answer: D
This is the ideal approach. A singleton bean is created only once. Injecting dependencies via the constructor ensures they are available when the bean is initialized. The
@PostConstructannotation guarantees the calculation method runs after dependency injection is complete but before the bean is made available to other components. The result can be stored in a field for subsequent use. - Question 4Intermediate
Data Management · Introduction to Spring JDBC
A Spring Boot application uses a
JdbcTemplateto perform database queries. During a code review, a senior developer points out a potential SQL injection vulnerability in the following code snippet:String status = "ACTIVE";String sql = "SELECT * FROM users WHERE status = '" + status + "'";jdbcTemplate.query(sql, userRowMapper);What is the best way to refactor this code to prevent the SQL injection vulnerability?
Show answer & explanation
Correct answer: C
The correct and standard way to prevent SQL injection is to use parameterized queries (prepared statements). The
JdbcTemplatesupports this by using?as a placeholder in the SQL string and passing the actual values as separate arguments to the query method. This ensures user input is treated as data, not executable code. The refactored code would be:String sql = "SELECT * FROM users WHERE status = ?"; jdbcTemplate.query(sql, new Object[]{status}, userRowMapper); - Question 5Advanced
Spring Boot · Spring Boot Actuator
Company Background
A large e-commerce company, "ShopFast", is modernizing its monolithic backend. They are adopting a microservices architecture and have chosen Spring Boot for new services. One of the first services being built is theOrderProcessingService. This service needs to be highly available and observable.Current Situation
The development team has built the core logic for theOrderProcessingService. It exposes several REST endpoints for creating and querying orders. The service interacts with a PostgreSQL database and a RabbitMQ message queue. The company has a centralized Prometheus server for metrics collection and Grafana for dashboarding. The security team mandates that all management endpoints must be secured and only accessible by administrators.Requirements
- The service must expose its operational status, including database connectivity and message queue health.
- Key business metrics, such as
orders_createdandorder_processing_time, must be exposed in a format compatible with Prometheus. - All management and monitoring endpoints must be exposed on a separate port from the main application port (8080) for security reasons.
- Access to these management endpoints must be restricted to users with the
ADMINrole.
Question
Which set of configurations inapplication.propertiesand dependencies inpom.xmlwill satisfy all the stated requirements?Show answer & explanation
Correct answer: D
This solution correctly addresses all requirements.
spring-boot-starter-actuatorprovides the health and metrics endpoints.micrometer-registry-prometheusensures metrics are in the Prometheus format.management.server.port=9090isolates the management endpoints.management.endpoints.web.exposure.include=*exposes all endpoints, including the required health and prometheus ones. Finally, addingspring-boot-starter-securityand configuringHttpSecurityallows for role-based access control to the actuator path, fulfilling the security requirement. - Question 6Advanced
Spring Core · Properties and Profiles
A developer is using Spring Expression Language (SpEL) to conditionally create a bean. The goal is to create the
EmailServicebean only if the application profile is 'production' AND a system property named 'email.enabled' is set to 'true'. Which@ConditionalOnExpressionannotation is correct?Show answer & explanation
Correct answer: A
This SpEL expression is correct.
environment.acceptsProfiles('production')is the proper way to check the active profile within a SpEL context.systemProperties['email.enabled'] == 'true'correctly accesses the system property and performs a string comparison. Theandoperator combines the two conditions as required. - Question 7Advanced
Security · Define Method-level Security
A developer wants to implement method-level security on a service method. The requirement is that only users who have the role 'ADMIN' OR are the owner of the account can invoke the
getAccountDetailsmethod. The method signature isgetAccountDetails(String username). How should the@PreAuthorizeannotation be written to enforce this rule?Show answer & explanation
Correct answer: D
This SpEL expression correctly implements the logic.
hasRole('ADMIN')checks for the required role. Theoroperator provides the alternative condition.authentication.nameaccesses the username of the currently authenticated principal, and#usernamerefers to theusernameargument passed to the method, allowing for the ownership check. - Question 8BeginnerSelect 2
Spring MVC · Web Applications with Spring Boot
Which of the following statements accurately describe the differences between
@RestControllerand@Controllerin Spring MVC? (Select TWO)Show answer & explanation
Correct answers: A, D
This is the primary definition of
@RestController. It is a stereotype annotation that implies both@Controller(making it a candidate for component scanning and web request handling) and@ResponseBody(indicating that the return value of every handler method should be written directly to the response body).By default, the return value of a method in a
@Controllerclass is interpreted as a view name to be resolved by aViewResolver. In contrast, because@RestControllerimplies@ResponseBodyon all methods, their return values are serialized (e.g., to JSON) and sent in the response body. - Question 9Intermediate
Spring Boot · Spring Boot Actuator
A developer needs to create a custom health indicator for a Spring Boot application that checks the status of an external REST service. Which interface must the developer implement to create this custom health check?
Show answer & explanation
Correct answer: B
To create a custom health check that integrates with the Spring Boot Actuator's
/healthendpoint, a developer must implement theHealthIndicatorinterface and override itshealth()method. The implementation should return aHealthobject indicating the status (e.g., UP, DOWN). - Question 10Intermediate
Spring Core · Spring Bean Lifecycle
True or False: A
BeanPostProcessorallows you to modify the bean definition, such as changing its scope or property values, before the bean is instantiated.Show answer & explanation
Correct answer: A
This statement is false. A
BeanPostProcessoroperates on bean instances after they have been created. It cannot modify the bean definition itself. The component responsible for modifying bean definitions before instantiation is theBeanFactoryPostProcessor.
Ready for the real thing?
The full 2V0-72-22 simulator has every exam-style question, timed mode, and instant scoring.