An administrator is troubleshooting a pilot deployment and wants the most appropriate next step. Which approach best demonstrates API security in a IBM Certified Instana Observability Administrator environment?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal: you would not ship a production change with no owner and no rollback plan. The same common sense applies here. In this scenario, answer C is the practical move because it keeps the implementation tied to the real IBM capability instead of chasing a shortcut.
Full explanation below image
Full Explanation
Here's the deal: you would not ship a production change with no owner and no rollback plan. The same common sense applies here. In this scenario, answer C is the practical move because it keeps the implementation tied to the real IBM capability instead of chasing a shortcut. The other choices sound tempting, but they either skip governance, ignore operational reality, or solve the wrong problem.
The correct answer is C. Protect API tokens and scope them to the automation task. That aligns with the Domain 7: Security/Compliance objective because it applies the feature or practice in the context where IBM expects a practitioner to use it. It also keeps the design reviewable, supportable, and realistic for a production environment.
Let's examine why the other options are incorrect: - Option A is incorrect because it sounds related, but it does not solve the API security requirement described in the scenario. - Option B is incorrect because it sounds related, but it does not solve the API security requirement described in the scenario. - Option D is incorrect because it sounds related, but it does not solve the API security requirement described in the scenario. For the exam, connect the feature to the operational outcome: the right answer is the one that preserves control, accuracy, and maintainability instead of relying on a brittle shortcut. The correct answer is 'Protect API tokens and scope them to the automation task.'. The incorrect options — 'Put tokens in public dashboards', 'Use personal admin tokens in shared scripts', 'Never rotate tokens' — are wrong because they do not align with IBM Instana's architecture or recommended practices for this scenario. Understanding this concept is essential for the Domain 7: Security/Compliance domain of the IBM Instana Observability certification.