C1000-138 Sample Questions & Answers
Building SOAP, REST and GraphQL APIs as a developer is weighted heaviest, alongside lifecycle management and governance, catalog and security administration for provider organizations, product and plan management, and running the developer portal.
Launch the full C1000-138 simulator →Showing 10 of 20 free samples.
- Question 1Beginner
API Product Manager Role · Distinguish between the various lifecycle stages of APIs and Products
True or False: When an API Product is moved to the 'Deprecated' lifecycle state, any existing application subscriptions to its Plans are immediately disabled, and API calls will fail.
Show answer & explanation
Correct answer: B
The statement is false. The 'Deprecated' state serves as a notice to consumers that the Product will be retired in the future. Existing subscriptions remain active, and API calls will continue to succeed. However, no new applications can subscribe to the Plans within the deprecated Product. This provides a grace period for consumers to migrate to a new version before the Product is eventually 'Retired', at which point calls would fail.
- Question 2Intermediate
API Developer Role · Create and configure GraphQL
A developer is implementing a GraphQL API proxy in API Connect for a backend GraphQL service. The requirement is to prevent certain expensive or sensitive fields in the GraphQL schema from being queryable by consumers. Which API Connect feature should be used to achieve this without modifying the backend service?
Show answer & explanation
Correct answer: B
API Connect provides the
@hidedirective as a specific feature for GraphQL API proxies. By adding this directive to fields or types in the schema within the API definition, API Connect will automatically remove them from the schema exposed to consumers. This prevents those fields from being included in introspection queries and invalidates any incoming requests that attempt to query them, effectively hiding them without backend changes. - Question 3AdvancedSelect 2
Provider Organization Owner Role · Configure API Security related Resources (OAuth2, User registry, TLS profiles)
A provider organization owner needs to configure mutual TLS (mTLS) for a specific Catalog. This requires the API Gateway to present its own certificate to backend services and to validate certificates presented by clients. Which TWO resources must be configured in the Cloud Manager or API Manager to enable this? (Select TWO).
Show answer & explanation
Correct answers: B, C
- Question 4Beginner
API Developer Role · Use the IBM API Connect Developer Toolkit Command Line Interface (CLI)
A developer is using the
apictoolkit CLI to work on an API project locally. Which command should be used to validate the project's YAML definition files against the OpenAPI specification and check for API Connect-specific errors without connecting to a management server?Show answer & explanation
Correct answer: C
The
apic validatecommand is specifically designed for local validation of project files. When run from the project directory, it checks the syntax and structure of theproduct.yamland any referencedapi.yamlfiles, reporting errors or warnings without requiring a connection to an API Connect server. This is a crucial step in a local development workflow before attempting to publish. - Question 5Intermediate
API Product Manager Role · Administer Applications and Subscriptions
An API Product Manager for an e-commerce company is analyzing API usage data. They notice that a key partner is frequently hitting the rate limit for the 'Product Search' API, leading to failed requests and potential lost sales. The manager wants to offer this partner a higher limit without affecting other consumers on the same Plan. What is the most direct way to achieve this?
Show answer & explanation
Correct answer: B
API Connect allows for plan overrides at the individual subscription level. This is the most efficient and targeted way to grant a specific application a different rate limit than the one defined in the general Plan. It avoids the overhead of creating new Products or Plans and doesn't require the consumer to make any changes on their end.
- Question 6Beginner
API Developer Role · Leverage other assembly policies
A developer is building an assembly flow that must perform a conditional action. If the incoming HTTP request header 'X-Transaction-Type' is 'Internal', a specific Map policy should be executed. Otherwise, a default Invoke policy should be called. Which flow control policy is best suited for implementing this logic?
Show answer & explanation
Correct answer: B
The Switch policy is ideal for this scenario. It evaluates a value (in this case,
request.headers.x-transaction-type) and executes a different sequence of policies for each matchingcase. It also includes anotherwiseblock for default actions. While anIfpolicy could work,Switchis cleaner and more scalable if more transaction types are added later. - Question 7Intermediate
Developer Portal (Consumer and Administrator) · Administer portal customization
A Developer Portal administrator needs to change the color scheme, logo, and fonts to match new corporate branding guidelines. Which of the following is the standard method for making these site-wide styling changes?
Show answer & explanation
Correct answer: C
The Developer Portal uses a theming engine. The correct procedure is to download or export the existing theme, make modifications to its constituent files (like SASS variables, CSS, and templates) locally, package the modified theme into a
.tgzfile, and then upload it back to the portal. This ensures changes are properly applied and are not lost during portal upgrades. - Question 8Intermediate
API Developer Role · Use the debug and tracing capabilities
During the debugging of an API assembly using the trace tool, a developer notices that a context variable set by a GatewayScript policy is not available in a subsequent policy. What is the most common reason for this behavior?
Show answer & explanation
Correct answer: B
In GatewayScript, variables declared with
var,let, orconstare local to that script's execution scope. To make a value available to other policies in the assembly flow, it must be explicitly written to the API context using theapim.setvariable()orcontext.set()function. Forgetting to do this is a very common error, resulting in the variable being inaccessible to subsequent policies. - Question 9Beginner
API Developer Role · Create and configure a REST API (OpenAPI 2 & 3)
What is the primary function of the
x-ibm-configurationobject in an OpenAPI 3.0 definition for an IBM API Connect proxy?Show answer & explanation
Correct answer: C
The
x-ibm-configurationobject is an OpenAPI extension used by IBM API Connect to store metadata and configuration that is not part of the standard OpenAPI specification. This includes the assembly definition (which contains the policy flow), API properties, target service definitions, CORS rules, and the gateway type (e.g.,datapower-api-gateway). - Question 10Beginner
Overview of IBM API Connect · API and Product Governance
Which statement accurately describes the relationship between an API, a Plan, and a Product in IBM API Connect?
Show answer & explanation
Correct answer: D
The correct hierarchy is: APIs are the base technical implementation. One or more APIs are packaged into a Product, which is the unit of lifecycle management and visibility. Within the Product, you define one or more Plans (e.g., Basic, Premium). Each Plan specifies rate limits and which APIs/operations are accessible. A consumer application subscribes to a specific Plan within a Product to gain access.
Ready for the real thing?
The full C1000-138 simulator has every exam-style question, timed mode, and instant scoring.