C1000-197 Sample Questions

C1000-197 Sample Questions & Answers

Free IBM Guardium Data Protection v12.x Administrator - Professional practice questions with worked answers and explanations. See how the ExamJungle simulator prepares you — then jump into the full test.

Launch the full C1000-197 simulator →

Showing 6 of 12 free samples.

  1. Question 1Advanced

    Architecture / Planning / Designing · Risk Spotter

    A financial institution is enhancing its insider threat detection framework. The security operations team notices that static audit policies fail to capture novel, suspicious DBA behavior because auditing every SQL query creates unacceptable collector load, while logging only static groups leaves gaps during credential compromise.

    The team wants to leverage Guardium's machine learning capabilities to evaluate multiple risk dimensions (such as cross-department data access, volume anomalies, and after-hours execution) to rank users dynamically, and automatically create a policy that focuses granular logging only on individuals identified as high-risk.

    Which Guardium advanced analytics capability and workflow satisfies these technical requirements?

    flowchart LR A[Monitored Database Activity] --> B[Machine Learning Risk Engine] B --> C[Score & Identify Risky Users] C --> D[Generate Dynamic Policy] D --> E[Granular Audit on Risky Users]
    Show answer & explanation

    Correct answer: A

    Risk Spotter uses artificial intelligence and machine learning algorithms across multiple weighted risk indicators to evaluate user behaviors and generate holistic risk profiles. A key capability of Risk Spotter is that administrators can take its scored findings and directly generate a Dynamic Auditing Policy, allowing collectors to selectively capture full details for dynamically flagged high-risk users without overwhelming appliances with blanket logging. Outliers Detection flags individual metric anomalies against a baseline but does not natively generate dynamic auditing policies. Active Threat Analytics categorizes threats and manages security incident cases rather than generating dynamic user-targeted policies.

  2. Question 2Intermediate

    Deploy and Configure · Leverage and distribute configuration profiles to managed units

    An administrator managing a fleet of 25 Guardium collectors needs to standardize operational parameters across all units. Specifically, the data archive schedule, SMTP alerter configurations, and system backup settings must be identical across all collectors. However, the Central Manager itself must retain a different backup destination and must not archive data locally.

    How can the administrator distribute these configurations efficiently from the Central Manager without altering the Central Manager's own local configuration?

    Show answer & explanation

    Correct answer: C

    Guardium Central Management provides Configuration Profiles (accessible via Central Management > Distribute Configuration). This functionality enables an administrator to define configuration templates for components such as Alerter, Data Archive, System Backup, and Anomaly Detection, and push them to specific managed units or managed unit groups without applying those settings to the Central Manager's local operational engine. Exporting CLI profiles or editing sqlguard.conf manually across 25 collectors is inefficient and error-prone.

  3. Question 3Advanced

    Deploy and Configure · Universal Connector

    A systems engineer is configuring a Guardium Universal Connector on a collector to ingest audit logs from an unsupported proprietary data store. The raw JSON logs contain complex nested timestamp formats and custom session identifiers that must be transformed and standardized before reaching the primary Guardium filter plug-in. How can custom preprocessing logic be integrated into the Universal Connector filter pipeline?

    Show answer & explanation

    Correct answer: B

    Guardium Universal Connector is built on a Logstash pipeline architecture comprising input and filter stages. To handle non-standard, deeply nested, or proprietary data formats, administrators can embed custom Ruby code using Logstash's native ruby { code => "..." } filter plug-in within the filter configuration. This executes preprocessing transformations on log fields before standard Guardium normalization logic processes the event for the sniffer. Guardium does not load custom C++ libraries into the sniffer or run Python hooks on the sniffer buffer.

  4. Question 4Intermediate

    Deploy and Configure · Universal Connector

    When deploying two separate Filebeat-based Universal Connectors on the same Guardium collector to monitor two distinct database platforms, which configuration practice is mandatory in the filter configuration files to avoid event collisions and significant processing bottlenecks?

    Show answer & explanation

    Correct answer: C

    According to official Guardium Universal Connector documentation, when running more than one Filebeat connector on a single managed unit or collector, administrators must define unique values for the 'tags' parameter in the input and filter configurations. Because all connector pipelines share underlying Logstash event routing on the appliance, non-unique tags cause events from one database to be evaluated against the filter logic of the other, resulting in parse errors and severe performance degradation.

  5. Question 5IntermediateSelect 2

    Deploy and Configure · Manage KDC definitions in Guardium (authentication using Kerberos)

    A database administrator is configuring a Guardium datasource definition to authenticate against an enterprise Oracle database using Kerberos KDC authentication. Which TWO configuration artifacts or parameters must be provided to Guardium when defining the Kerberos KDC profile? (Select TWO)

    Show answer & explanation

    Correct answers: C, D

    Configuring Kerberos KDC authentication for Guardium datasources requires the Kerberos client configuration file (krb5.conf), which defines realm and KDC server connection details, along with either a Kerberos Password or a binary Kerberos Keytab file (which contains service principal names and encrypted keys). SSL certificate authority truststores and S-TAP encryption certificates are not components of the KDC definition itself.

    Kerberos authentication requires credentials supplied either via an explicit Kerberos password or via an uploaded binary Keytab file containing principal cryptographic keys, paired with the krb5.conf configuration.

  6. Question 6Intermediate

    Deploy and Configure · Defining Guardium datasources to access CyberArk

    A financial enterprise mandates that static passwords must not be stored in Guardium datasource definitions. The administrator needs Vulnerability Assessment and Classification processes to dynamically retrieve database credentials from a CyberArk Enterprise Password Vault at runtime. What is required when configuring the Guardium datasource to use CyberArk?

    Show answer & explanation

    Correct answer: A

    Guardium v12.x integrates with external credential vaults such as CyberArk. When creating or editing a datasource definition, the administrator configures external password retrieval properties (referencing the CyberArk Application ID, Safe, Folder, and Object name). Guardium queries the vault over its API at connection time rather than saving static password strings locally. Installing an S-TAP on the CyberArk server or running CLI purge scripts is incorrect.

Ready for the real thing?

The full C1000-197 simulator has every exam-style question, timed mode, and instant scoring.