Domain 7: Security/Compliance
IBM Certified Specialist - Instana · 35 questions
- A junior security analyst needs to view Instana dashboards, service maps, and metric trends to support daily operations reporting. However, the analyst must not be permitted to create or modify alert policies, edit application perspectives, or manage users. Which built-in Instana role should the administrator assign?
- Your enterprise identity team has provisioned Instana as a SAML 2.0 Service Provider and wants employees to authenticate using corporate credentials from Okta as the Identity Provider. Which configuration step must the Instana administrator complete in the Instana Settings to enable SAML SSO?
- During a security incident investigation, the SOC team discovers that an Instana API token used by an automated deployment pipeline has been exfiltrated and may have already been used to query monitoring data. What is the correct immediate remediation action for the Instana administrator?
- Your organization's data governance policy mandates that observability data — including metrics, traces, and logs — must not be retained beyond 90 days. As the Instana self-hosted administrator, which approach correctly controls the data retention period for collected monitoring data?
- A security engineer auditing Instana deployments finds that several agents are configured to communicate with the Instana backend over an unencrypted channel. Which agent configuration change ensures all agent-to-backend communication is encrypted with TLS?
- The information security team wants Instana to automatically evaluate all discovered infrastructure components against security benchmark rules — such as verifying that SSH root login is disabled and that unused network services are not running — and surface any violations in a centralized view. Which Instana capability fulfills this requirement?
- Following a suspected insider threat incident, the security team requests a complete record of all configuration changes, user logins, and administrative actions performed within the Instana tenant over the past 45 days. Which Instana feature provides this information?
- Your security architecture requires that the Instana backend not only present a valid TLS certificate to agents, but also that each agent authenticate itself to the backend using a client certificate — implementing mutual TLS (mTLS). Which configuration correctly implements this requirement?
- A cloud operations team wants Instana to automatically identify software packages running on monitored hosts that have known Common Vulnerabilities and Exposures (CVEs) and display their severity scores alongside the affected infrastructure components. Which Instana feature directly provides this capability?
- An application monitored by Instana is passing user passwords and credit card numbers as HTTP query parameters, and these values are appearing unredacted in captured trace spans visible to all Instana users with trace access. Which Instana configuration prevents this sensitive data from being stored and displayed in traces?
- A project lead is turning a proof of concept into a governed production workflow. For IBM Certified Instana Observability Administrator, the topic is data retention. What should the team do?
- A consultant is advising a customer that wants a scalable implementation. The team is focused on API security. Which recommendation is most appropriate?
- A senior engineer reviews the current plan and notices that one key control is missing. For IBM Certified Instana Observability Administrator, the topic is audit logs. What should the team do?
- A team is preparing a production rollout and needs to avoid a design mistake. The team is focused on access management. Which recommendation is most appropriate?
- A senior engineer reviews the current plan and notices that one key control is missing. For IBM Certified Instana Observability Administrator, the topic is data retention. What should the team do?
- A team is preparing a production rollout and needs to avoid a design mistake. The team is focused on API security. Which recommendation is most appropriate?
- During a design review, an architect asks which choice best matches the IBM guidance. For IBM Certified Instana Observability Administrator, the topic is audit logs. What should the team do?
- An administrator is troubleshooting a pilot deployment and wants the most appropriate next step. The team is focused on access management. Which recommendation is most appropriate?
- A project lead is turning a proof of concept into a governed production workflow. What is the best way to handle data retention while staying aligned with the certification objectives?
- A consultant is advising a customer that wants a scalable implementation. Which approach best demonstrates API security in a IBM Certified Instana Observability Administrator environment?
- A senior engineer reviews the current plan and notices that one key control is missing. What is the best way to handle audit logs while staying aligned with the certification objectives?
- A project lead is turning a proof of concept into a governed production workflow. For IBM Certified Instana Observability Administrator, the topic is audit logs. What should the team do?
- A consultant is advising a customer that wants a scalable implementation. The team is focused on access management. Which recommendation is most appropriate?
- A senior engineer reviews the current plan and notices that one key control is missing. What is the best way to handle data retention while staying aligned with the certification objectives?
- A team is preparing a production rollout and needs to avoid a design mistake. Which approach best demonstrates API security in a IBM Certified Instana Observability Administrator environment?
- During a design review, an architect asks which choice best matches the IBM guidance. What is the best way to handle audit logs while staying aligned with the certification objectives?
- An administrator is troubleshooting a pilot deployment and wants the most appropriate next step. Which approach best demonstrates access management in a IBM Certified Instana Observability Administrator environment?
- A project lead is turning a proof of concept into a governed production workflow. The team is focused on data retention. Which recommendation is most appropriate?
- An administrator is troubleshooting a pilot deployment and wants the most appropriate next step. Which approach best demonstrates API security in a IBM Certified Instana Observability Administrator environment?
- A project lead is turning a proof of concept into a governed production workflow. What is the best way to handle audit logs while staying aligned with the certification objectives?
- A consultant is advising a customer that wants a scalable implementation. Which approach best demonstrates access management in a IBM Certified Instana Observability Administrator environment?
- A senior engineer reviews the current plan and notices that one key control is missing. The team is focused on data retention. Which recommendation is most appropriate?
- A team is preparing a production rollout and needs to avoid a design mistake. For IBM Certified Instana Observability Administrator, the topic is API security. What should the team do?
- During a design review, an architect asks which choice best matches the IBM guidance. The team is focused on audit logs. Which recommendation is most appropriate?
- An administrator is troubleshooting a pilot deployment and wants the most appropriate next step. For IBM Certified Instana Observability Administrator, the topic is access management. What should the team do?