C1000-166 Sample Questions & Answers
Free IBM Cloud Professional Sales Engineer v2 practice questions with worked answers and explanations. See how the ExamJungle simulator prepares you — then jump into the full test.
Launch the full C1000-166 simulator →Free C1000-166 Sample Questions with Answers
Real questions from the IBM Cloud Professional Sales Engineer v2 practice test — answers and explanations included. Showing 10 of 20 free samples.
- Question 1
A developer needs to store large, unstructured data files, such as video assets and application backups, in a highly durable and cost-effective manner. The data will be accessed infrequently but must be readily available when needed. Which IBM Cloud service is the most appropriate for this use case, and what feature should be used to minimize long-term storage costs?
Show answer & explanation
Correct answer: C
IBM Cloud Object Storage is designed for storing large amounts of unstructured data. For data that is accessed infrequently but requires durability, the 'Archive' storage class is the most cost-effective option. It has the lowest storage cost but higher retrieval costs and latency, which aligns perfectly with the requirements for application backups and long-term asset storage.
- Question 2
A developer is configuring a web application fronted by IBM Cloud Internet Services (CIS). To enhance security, they want to prevent common web attacks like SQL injection and cross-site scripting (XSS) before traffic reaches their origin server. Which CIS feature should be enabled and configured to achieve this goal?
Show answer & explanation
Correct answer: D
The Web Application Firewall (WAF) is a core feature of IBM Cloud Internet Services designed specifically to protect against common web vulnerabilities and attacks at the application layer (Layer 7), such as SQL injection and XSS. It inspects incoming HTTP/HTTPS requests and applies rulesets to block malicious traffic before it reaches the application's origin.
- Question 3
A development team is building a mobile application that requires users to log in using their social media accounts (e.g., Google, Facebook) as well as a traditional email and password. The team wants a managed service on IBM Cloud that handles the entire authentication flow, including social identity federation, user profile management, and the issuance of JWT tokens for securing backend APIs, without building the security infrastructure from scratch. Which service is designed for this purpose?
Show answer & explanation
Correct answer: C
IBM Cloud App ID is the service specifically created to add authentication and authorization to applications. It provides social login integration (federation), a cloud directory for email/password users, user profile management, and secures backend APIs using OAuth 2.0 and JWT tokens. This directly matches all the requirements without requiring the developer to implement complex security protocols.
- Question 4
When deploying a containerized application to IBM Cloud Kubernetes Service (IKS), a developer must ensure the container image is stored in a private, secure, and geographically close location to the cluster for fast pulls. Additionally, the images must be scanned for known vulnerabilities. What is the primary purpose of the IBM Cloud Container Registry in this workflow?
Show answer & explanation
Correct answer: B
The IBM Cloud Container Registry is a managed service that provides a private, secure location to store and share container images. Key features include multi-tenancy through namespaces, integration with IAM for access control, and a built-in Vulnerability Advisor for scanning images for security issues. This makes it the central hub for images deployed to IKS or OpenShift clusters.
- Question 5
A developer needs to create a CI/CD pipeline that builds a Docker image, pushes it to IBM Cloud Container Registry, and then deploys it to a Red Hat OpenShift cluster. They want to use an integrated, managed solution on IBM Cloud that provides a visual editor for the pipeline and seamless integration with Git repositories and issue tracking. Which IBM Cloud service provides this comprehensive, integrated DevOps experience?
Show answer & explanation
Correct answer: C
IBM Cloud DevOps Toolchains provide a fully integrated set of tools, including Git repos, issue tracking, and the Continuous Delivery service (which uses Tekton pipelines). This combination allows developers to create, manage, and visualize the entire CI/CD workflow from a central location, making it the ideal solution for the scenario described. Standalone Tekton provides the pipeline engine but not the integrated toolchain experience.
- Question 6Select 2
A developer is building a voice-controlled kiosk application. The application needs to convert spoken user commands into text for processing, and then read the text-based responses back to the user in a natural-sounding voice. Which TWO IBM Watson APIs are required to implement this functionality? (Select TWO).
Show answer & explanation
Correct answers: A, D
The scenario requires two distinct conversions: audio to text and text to audio. Watson Speech to Text is used for the first part (transcribing spoken commands). Watson Text to Speech is used for the second part (synthesizing spoken responses from text). Together, they form the core of a voice interaction system.
- Question 7
A security administrator is hardening a microservice running in a pod on IBM Cloud Kubernetes Service. The microservice only needs to read
ConfigMapsand list other pods in its own namespace; it should have no other permissions. What is the Kubernetes-native, best-practice approach to grant these specific, limited permissions to the application?Show answer & explanation
Correct answer: C
This follows the principle of least privilege in Kubernetes. A dedicated
ServiceAccountshould be created for the application. A namespace-scopedRoleshould define the exact permissions (e.g., verbs 'get', 'list' on resources 'configmaps', 'pods'). Finally, aRoleBindingconnects theServiceAccountto theRolewithin that namespace. UsingClusterRoleis incorrect as the permissions are namespace-specific. - Question 8
A team is choosing between deploying their containerized application on IBM Cloud Kubernetes Service (IKS) or Red Hat OpenShift on IBM Cloud. A key requirement is to have an integrated, out-of-the-box solution for building container images directly from source code within the cluster, without needing an external CI/CD tool. Which platform provides this capability natively?
Show answer & explanation
Correct answer: B
A key differentiator of Red Hat OpenShift is its native, developer-focused features. It includes the concept of
BuildConfigsand the Source-to-Image (S2I) toolchain, which allow developers to build container images directly from application source code stored in a Git repository. IKS is a more standard Kubernetes distribution and does not include this functionality out-of-the-box; it requires an external tool like Tekton or Jenkins. - Question 9
A developer is implementing a DevSecOps pipeline. A critical requirement is to centralize and analyze all application and system logs from their Kubernetes cluster to detect security anomalies and troubleshoot operational issues. Which IBM Cloud service is specifically designed for aggregating, searching, and creating alerts from log data?
Show answer & explanation
Correct answer: C
IBM Cloud Log Analysis is the service dedicated to log management. It automatically collects logs from various IBM Cloud services, including Kubernetes, and provides a centralized platform for searching, filtering, visualizing, and alerting on log data. While Monitoring handles metrics and Activity Tracker handles audit events, Log Analysis is the primary tool for application and system logs.
- Question 10
A company is storing sensitive customer documents in an IBM Cloud Object Storage bucket. According to security policy, all API keys, database credentials, and encryption keys used by applications must be stored in a centralized, highly available secrets management system. The system must support automatic rotation of secrets and provide fine-grained access control. Which is the most appropriate service to fulfill these requirements?
Show answer & explanation
Correct answer: C
IBM Cloud Secrets Manager is the purpose-built service for managing the entire lifecycle of secrets. It supports storing various secret types, defining rotation policies, integrating with IAM for access control, and providing audit trails. While Key Protect manages encryption keys, Secrets Manager is the comprehensive solution for all types of application secrets, including API keys and credentials.
10 more sample questions — free with an ExamJungle account, plus the full C1000-166 simulator with 199 exam-style questions.
Ready for the real thing?
The full C1000-166 simulator has every exam-style question, timed mode, and instant scoring.