IBM Security Access Manager V7.0 Implementation Sample Questions:
1. What HTTP header field is used by an external authentication interface (EAI) server to provide to WebSEAL the user identity?
A) eai-user-id
B) am-eai-user-id
C) eai-am-user-id
D) am-user-id
2. An organization is facing the following challenge: Customers authenticate using a username and password, Business Partners are using a certificate to authenticate, and employees are using a token device. Within the WebSEAL architecture, how can this be achieved?
A) Use PDCONFIG to configure three Authorization servers each with a different authorization mechanism. Configure the receiving WebSEAL to redirect to the Authorization servers.
B) Create a WebSEAL instance; make two copies of its webseald-default.conf, naming the copies webseald-certificate.conf and webseald-token.conf. Restart WebSEAL to activate the new configuration.
C) Configure multiple authentication mechanism in the webseald-default.conf configuration file.
D) Define three WebSEAL instances and configure each with a different authentication mechanism and a different URL.
3. Which statement is FALSE regarding local response redirection?
A) When using local response redirection, WebSEAL no longer has the responsibility of generating responses to client requests.
B) When local response redirection is enabled, the redirection is used for all local WebSEAL response types: login, error, informational, and password management.
C) We need to use External authentication interface to implement local response redirection.
D) When local response redirection is enabled, change password must be handled by WebSEAL.
4. When using the IBM Security Access Manager, which ISAM component needs to be installed first?
A) IBM Security Access Manager Policy server.
B) IBM Security Access Manager Runtime.
C) IBM Security Utilities.
D) IBM Security Access Manager Authorization Server.
5. What will help reduce the volume of audit event, while preserving important audit information?
A) complete disablement of event generation
B) reconfiguration of WebSEAL to use CARS auditing instead of native auditing
C) generation of events for unsuccessful HTTP accesses only
D) generation of events for successful HTTP accesses only
Solutions:
| Question # 1 Answer: B | Question # 2 Answer: D | Question # 3 Answer: C | Question # 4 Answer: C | Question # 5 Answer: C |
We're so confident of our products that we provide no hassle product exchange.


By Stanford

