IBM Exam C IBM Tivoli Federated Identity Manager V6.2.2 Implementation Version: 6.0 [ Total Questions: 134 ]

Similar documents
PASS4TEST. IT Certification Guaranteed, The Easy Way! We offer free update service for one year

IBM EXAM - C IBM Tivoli Federated Identity Manager V6.2.2 Implementation. Buy Full Product.

IBM Tivoli Federated Identity Manager V6.2.2 Implementation Exam.

Vendor: IBM. Exam Code: Exam Name: IBM Tivoli Federated Identity Manager V6.2.2 Implementation. Version: Demo

TestKings.C _120,QA

SelfTestEngine.C _135,Q&A

C IBM. IBM Tivoli Federated Identity Manager V6.2.2 Implementation

IBM IBM IBM Tivoli Federated Identity Manager V6.1. Practice Test. Version

IBM InfoSphere Information Server Single Sign-On (SSO) by using SAML 2.0 and Tivoli Federated Identity Manager (TFIM)

Federated Identity Manager Business Gateway Version Configuration Guide GC

Qualys SAML & Microsoft Active Directory Federation Services Integration

Configuration Guide - Single-Sign On for OneDesk

ISAM Federation STANDARDS AND MAPPINGS. Gabriel Bell IBM Security L2 Support Jack Yarborough IBM Security L2 Support.

SAML-Based SSO Solution

CA SiteMinder. Federation Manager Guide: Legacy Federation. r12.5

Enhancing cloud applications by using external authentication services. 2015, 2016 IBM Corporation

SAML-Based SSO Solution

IBM Security Access Manager Version January Federation Administration topics IBM

IBM Tivoli Federated Identity Manager Version Installation Guide GC

API Security Management SENTINET

IBM Security Access Manager Version 9.0 October Product overview IBM

Exam Name: IBM Tivoli Federated Identity Manager V6.1

Tivoli Federated Identity Manager. Sven-Erik Vestergaard Certified IT Specialist Security architect SWG Nordic

Introduction... 5 Configuring Single Sign-On... 7 Prerequisites for Configuring Single Sign-On... 7 Installing Oracle HTTP Server...

SSO Integration Overview

Integration Guide. PingFederate SAML Integration Guide (SP-Initiated Workflow)

Identity management. Tuomas Aura CSE-C3400 Information security. Aalto University, autumn 2014

1z0-479 oracle. Number: 1z0-479 Passing Score: 800 Time Limit: 120 min.

Novell Access Manager 3.1

CA SiteMinder Federation

SINGLE SIGN ON SOLUTIONS FOR ICS PRODUCTS

Using Your Own Authentication System with ArcGIS Online. Cameron Kroeker and Gary Lee

Enterprise SOA Experience Workshop. Module 8: Operating an enterprise SOA Landscape

CA SiteMinder Federation

Morningstar ByAllAccounts SAML Connectivity Guide

April Understanding Federated Single Sign-On (SSO) Process

Authentication. Katarina

Integration Guide. SafeNet Authentication Manager. Using SAM as an Identity Provider for PingFederate

ISA 767, Secure Electronic Commerce Xinwen Zhang, George Mason University

Single Sign-On (SSO)Technical Specification

Configuring SAML-based Single Sign-on for Informatica Web Applications

PASS4TEST. IT Certification Guaranteed, The Easy Way! We offer free update service for one year

CA CloudMinder. SSO Partnership Federation Guide 1.53

Oracle Utilities Opower Solution Extension Partner SSO

API Security Management with Sentinet SENTINET

Configuring Alfresco Cloud with ADFS 3.0

Exam : Title : IBM Tivoli Federated Identity Manager V6.1. Version : DEMO

TECHNICAL GUIDE SSO SAML. At 360Learning, we don t make promises about technical solutions, we make commitments.

Exam Name: ibm tivoli fenerated identity manager v6.0

RealMe. SAML v2.0 Messaging Introduction. Richard Bergquist Datacom Systems (Wellington) Ltd. Date: 15 November 2012

Entrust Identification Server 7.0. Entrust Entitlements Server 7.0. Administration Guide. Document issue: 1.0. Date: June 2003

RECOMMENDED DEPLOYMENT PRACTICES. The F5 and Okta Solution for High Security SSO

CA CloudMinder. SSO Partnership Federation Guide 1.51

Identity Provider for SAP Single Sign-On and SAP Identity Management

Oracle Access Manager Configuration Guide

RSA SecurID Ready Implementation Guide. Last Modified: December 13, 2013

Upland Qvidian Proposal Automation Single Sign-on Administrator's Guide

Test Plan for Liberty Alliance SAML Test Event Test Criteria SAML 2.0

Microsoft ADFS Configuration

Warm Up to Identity Protocol Soup

Lesson 13 Securing Web Services (WS-Security, SAML)

Integrating YuJa Active Learning into ADFS via SAML

Contents Introduction... 5 Configuring Single Sign-On... 7 Configuring Identity Federation Using SAML 2.0 Authentication... 29

Unified Contact Center Enterprise (UCCE) Single Sign On (SSO) Certificates and Configuration

CA SiteMinder. Federation in Your Enterprise 12.51

Network Security Essentials

National Identity Exchange Federation. Web Services System- to- System Profile. Version 1.1

IBM Domino WEB Federated Login

All about SAML End-to-end Tableau and OKTA integration

IBM Exam IBM WebSphere Message Broker V8.0 System Administration Version: 6.0 [ Total Questions: 55 ]

Access Manager Applications Configuration Guide. October 2016

October 14, SAML 2 Quick Start Guide

How to Use ADFS to Implement Single Sign-On for an ASP.NET MVC Application

[GSoC Proposal] Securing Airavata API

Identity management. Tuomas Aura T Information security technology. Aalto University, autumn 2011

U.S. E-Authentication Interoperability Lab Engineer

Introduction to application management

API Gateway. Version 7.5.1

IBM Security Access Manager Version December Release information

C exam. IBM C IBM WebSphere Application Server Developer Tools V8.5 with Liberty Profile. Version: 1.

CA SiteMinder. Federation Release Notes 12.52

Kerberos for the Web Current State and Leverage Points

Single Sign-On for PCF. User's Guide

IBM Security Access Manager Version December Product overview IBM

D9.2.2 AD FS via SAML2

ArcGIS Enterprise Security: An Introduction. Gregory Ponto & Jeff Smith

Web Access Management Token Translator. Version 2.0. User Guide

Web Based Single Sign-On and Access Control

SAML 2.0 SSO Implementation for Oracle Financial Services Lending and Leasing

AdminCamp Christian Henseler, Christian Henseler,

Add OKTA as an Identity Provider in EAA

Testpassport.

Access Manager 4.2 Service Pack 2 (4.2.2) supersedes Access Manager 4.2 Service Pack1 (4.2.1).

PingFederate 6. Getting Started

Business White Paper IDENTITY AND SECURITY. Access Manager. Novell. Comprehensive Access Management for the Enterprise

ITdumpsFree. Get free valid exam dumps and pass your exam test with confidence

Entrust GetAccess 7.0 Technical Integration Brief for IBM WebSphere Portal 5.0

IBM Fundamentals of Applying Tivoli Security and Compliance Management Solutions V2.

WebSphere Integration Kit. Version User Guide

Integration Documentation. Automated User Provisioning Common Logon, Single Sign On or Federated Identity Local File Repository Space Pinger

Transcription:

s@lm@n IBM Exam C2150-575 IBM Tivoli Federated Identity Manager V6.2.2 Implementation Version: 6.0 [ Total Questions: 134 ]

IBM C2150-575 : Practice Test Question No : 1 What is the default file name of the IBM Tivoli Directory Integrator log? A. tdi.log B. ibmdi.log C. ibmdisrv.log D. ibmdirectoryintegrator.log Question No : 2 Click the Exhibit button. Which three statements are true regarding this SAML 1.1 flow diagram? (Choose three.) A. The HTTP request in Step 3 is a GET. B. The assertion is sent with an HTTP 200 response in Step 2. C. An artifact value is sent with an HTTP 302 response in Step 2. D. This is a Browser/POST profile, so in Step 3 the assertion is sent to the Assertion Consumer Service endpoint through an HTTP POST of an HTML form. E. The HTTP response in Step 5 must be a 302 redirect based upon the resource requested and the user's authorized access which is determined by the response in Step 4. 2

F. This is a Browser/Artifact profile, so the artifact received in Step 2 must be sent to the Artifact Resolution Service in Step 3, and the assertion must be retrieved through a SOAP backchannel in Step 4. Answer: A,C,F IBM C2150-575 : Practice Test Question No : 3 What is XSLT? A. A concatenative language for transforming input XML documents into new documents, which typically takes an XML source document and applies template rules to subexpressions, producing a new output document. B. A declarative language for transforming input XML documents into new documents, which typically takes an XML source document and applies template rules in an XSLT stylesheet to it, producing a new output document. C. An imperative language for transforming input XML documents into new documents, which typically takes an XML source document and applies template rulesin an XSLT stylesheet to it, producing a new output document. D. A automata-based language for transforming input XML documents into new documents, which typically takes an XML source document and applies template rules to transition element states, producing a new output document. Question No : 4 What is always required when creating an IBM Tivoli Federated Identity Manager V6.2.2 (TFIM) Single Sign-On federation partner? A. A signer certificate B. A login protocol endpoint C. A metadata filecontaining the partner definitions D. A federation default or partner-specific mapping rule or function Question No : 5 3

IBM C2150-575 : Practice Test Which HTTP status code is always issued by an identity provider using SAML 1.1 Browser/POST when communicating with theassertion Consumer Service? A. 101 B. 200 C. 206 D. 302 Question No : 6 Custom Java mapping functions must be deployed into which IBM Tivoli Federated Identity Manager V6.2.2 directory? A. Plug-ins B. Add-ins C. Mappings D. Extensions Answer: A Question No : 7 What is always required when deploying the IBM Tivoli Federated Identity Manager V6.2.2 runtime and management service? A. WebSEAL B. IBM HTTP Server C. IBM Tivoli Identity Manager D. IBM WebSphere Application Server Question No : 8 What does this XSL code do? 4

IBM C2150-575 : Practice Test <xsl:template match-'@* node()"> <xsl:copy> <xsl:apply-templates select="@* node()"/> </xsl:copy> </xsl:template> A. It makes a copy of the template transforms on the input document. B. It performs a series of transforms on a copy of the input document. C. It creates a new copy of the input document, copying all attributes, but not elements. D. It creates a new copy of the input document, copying all elements, but not attributes. Question No : 9 Given IBM Tivoli Federated Identity Manager V6.2.2 configured as an OpenID provider, what is a correct statement regarding processing of attributes when using an IBM Tivoli Directory Integrator AssemblyLine as a mapping function? A. Only requested attributes can be returned. B. All attributes requested must be BASE64 encoded to ensure proper handling. C. The AssemblyLine must assure that values for non-optional attributes are returned. D. Requested attributes that have an empty value (not an empty string)must be removed and cannot be returned. Answer: C Question No : 10 Which statement is true regarding event pages when creating a federation in IBM Tivoli Federated Identity Manager V6.2.2 (TFIM)? A. Event pages are tied to a protocol and not to a specific federation. B. Event pages must be created (or copied from the defaults) and stored in the federation event directory. C. Event pages can use the @FEDSTATUS@ macro to provide detailed Single Sign-On 5

status information to the user. D. When creatingevent pages for a federation, it is important to append the federation name to the event page filename so the TFIM runtime will use that instead of the default protocol event page. Answer: A IBM C2150-575 : Practice Test Question No : 11 A customer uses WebSEAL as the point of contact for IBM Tivoli Federated Identity Manager V6.2.2 (TFIM) where IBM Tivoli Access Manager (TAM) is configured to support Federal Information Processing Standards (FIPS). When running the tfimcfg.jar tool this error is received: FBTTAC1161 The SSL handshake failed. Retrying connection with certificate validation disabled What must be done? A. TFIM must be configured for SSL communication. B. FIPS must be enabled on all TFIM WebSphere servers. C. The TAM public certificates must be imported to thewebsphere trust store. D. The tfimcfg.jar tool needs to run with the-sslfactory TLS argument. Question No : 12 What is a trust service chain in IBM Tivoli Federated Identity Manager V6.2.2 (TFIM)? A. It is a defined set of WS-Trust security tokens, which together form a proof of trust and are organized sequentially in their correct order of precedence. B. It is a defined set of WS-Security trust tokens, which together form a proof of claim and are organized sequentially in their correct order of precedence. C. It is a defined set of individual processing module instances, collectively executed in a specific order, with the interface to and roles for each module conforming to the WS-Trust model. D. It is a defined set of individual processing module instances which are always executed in the specific order required by the authentication flow, with the interface to and roles for 6

each module conforming to the WS-Trust model. Answer: C IBM C2150-575 : Practice Test Question No : 13 Which partner vouches for the identity of a user in a Single Sign-On federation? A. Relying party B. Attribute party C. Service provider D. Identity provider Question No : 14 When configuring WebSEAL as the point of contact for IBM Tivoli Federated Identity Manager V6.2.2 using thewebseal No ACLD profile, which configuration requirement(s) are relevant? A. This option must be set: Disable Access Manager (IVCred) credential issuing (requires EAI to be configured). B. This option must be cleared: Enable Access Manager (IVCred) credential issuing (requires PDJRTE to be configured). C. This option must be set: Disable Access Manager (IVCred) credential issuing (requires EAI to be configured); and the no-acid tag value attribute must be defined in the WebSEAL configuration. D. This option must be cleared: Enable Access Manager (IVCred) credential issuing (requires PDJRTE to be configured); and the no-acid tag value attribute must be defined in the WebSEAL configuration. Question No : 15 Which statement is true about the IBM Tivoli Federated Identity Manager V6.2.2 Business Gateway? 7

A. Users can use several gateway protocols. B. Users can access external Web services. C. Users can create Federated Single Sign-On partnerships with multiple providers. D. Users cannot create Federated Single Sign-On partnerships with multiple providers. Answer: C IBM C2150-575 : Practice Test Question No : 16 What does SAML stand for? A. System Access Markup Language B. Security Assertion Markup Language C. Server Authenticated Markup Language D. Secure Authentication MarkupLanguage Question No : 17 A company wants to establish a Federated Single Sign-On (FSSO) relationship with a partner identity provider to allow partner administrator access. This company provides services for credit card processing. What isthe most secure choice for the FSSO protocol? A. OpenID using Associate Mode B. SAML 2.0 using HTTP Redirect/POST bindings, signed response, and signed assertion C. SAML 1.1 using a Browser/POST profile, signed response and assertion, and a narrow assertion validity window of only a few seconds D. SAML 2.0 using an HTTP-Artifact binding, signed response and assertion, an encrypted assertion, and a narrow assertion validity window of only a few seconds Question No : 18 Which roles are typicallydefined in an IBM Tivoli Federated Identity Manager V6.2.2 Single Sign-On federation configuration? 8

A. Relying Party or Service Provider B. Asserting Party or Service Provider C. Identity Provider or Asserting Party D. Identity Provider or Service Provider IBM C2150-575 : Practice Test Question No : 19 When is IBM WebSphere Application Server required for IBM Tivoli Federated Identity Manager V6.2.2 (TFIM)? A. It is always required for TFIM. B. When it is used as the point of contact. C. When the Management Console GUI isused. D. When Web Services Security Management is used Answer: A Question No : 20 A client has installed IBM Tivoli Federated Identity Manager V6.2.2 (TFIM) and is establishing a SAML 1.1 Single Sign-On (SSO) configuration with a service provider (SP). The client wants to provide SP-initiated Federated SSO. How can this be accomplished? A. A link or redirect to the SP login endpoint with the parameters SP_PROVIDER_ID and target can be used to initiate the protocol at the SP. The SP will then redirect theuser to the corresponding identity provider (IdP) login endpoint. B. A link or redirect to the SP login endpoint with the parameters IDP_PROVIDER_ID and target can be used to initiate the protocol at the SP. The SP will then redirect the user to the corresponding IdP login endpoint. C. Because a SP-initiated sign-on is not supported in SAML 1.1, this can be simulated by using a link or an HTTP 302 redirect to the IdP login endpoint with the query string parameters SP_PROVIDER_ID and TARGET to initiate theprotocol. D. Because a SP-initiated sign-on is not supported in SAML 1.1, and only an HTTP POST to the IdP can be used to initiate the protocol, the SP must generate an HTTP 200 response containing a form with the SP_PROVIDER_ID and target values which isselfposted to the IdP login endpoint. Answer: C 9

IBM C2150-575 : Practice Test Question No : 21 What is required to use an IBM Tivoli Director/ Integrator (TDI) AssemblyLine as an IBM Tivoli Federated Identity Manager (TFIM) mapping function? A. The TDI api.remote.on property for the solution must be set to True. B. The TDI api.remote.on property for the solution must be set to False. C. The TDI solution directory must be located under the TFIM TDI Mapping directory. D. The DirectoryIntegratorSTSModule.jar file needs to be copied tothe TDI solutions directory. Answer: A Question No : 22 A customer would like to give third-party applications scoped access to a protected resource on behalf of the resource owner. What is the appropriate protocol? A. SAML B. OAuth C. Liberty D. WS-Federation Question No : 23 What is a registry configuration requirement when used with IBM Tivoli Federated Identity Manager V6.2.2 User Self Care (USC)? A. IBM WebSphere Application Server (WAS) federated repositories must be used. B. WASfederated repositories cannot be used. C. The USC schema extensions must be applied to the managed registry. D. The managed registry must support WS-Provisioning extensions, and the extensions must be enabled. 10