A fully updated 2021 Apigee-API-Engineer Exam Dumps exam guide from training expert Real4dumps
Provides complete coverage of every objective on exam and exam preparation Apigee-API-Engineer
NEW QUESTION 17
Where in the proxy should you place a policy that modifies the flow variable target, url?
- A. proxy response flow
- B. proxy request flow
- C. any flow
- D. target response flow
- E. target request flow
Answer: D
NEW QUESTION 18
Your API generates tokens to authenticate users. You have the following requirements
1. Limited token lifetime.
2. Managed key rotation.
3. Self-verifiable content.
4 Compact data representation
5. Refresh without new challenge.
You plan to use SAML2 Which two of the above-listed requirements are satisfied by using SAML2? Choose 2 answers
- A. Compact data representation
- B. Refresh without a new challenge
- C. Self-verifiable content
- D. Limited token lifetime.
- E. Managed key rotation
Answer: B,D
NEW QUESTION 19
You have a new set of requirements for a mobile app. The product team has asked for the following.
* The app requires access to customer order information
* The app needs to allow a search function for orders by product name
Choose two development tasks that would accomplish the requirements.
- A. The design should include a new custom header X-Product-Name
- B. The Apigee proxy should allow a query parameter for q=
- C. Create a new API proxy for a GET /v1/customers/{customerid}/orders
- D. The Apigee proxy should allow a query parameter for orderld=
- E. Create a new API proxy for a GET /v1/customers/{customerid}/products/{productname}
Answer: B,D
NEW QUESTION 20
Which describe OAuth 2.0 Refresh Tokens'?
- A. can be used to generate or renew access tokens
- B. is always issued with every access token
- C. may be reused multiple times to create new access tokens
- D. can be used to reset crederfflals
Answer: A,B,C
NEW QUESTION 21
In your last release, there were unexpected errors uncovered by users within the first 24 hours The root cause analysis found that key configurations were not promoted to production You want to avoid similar release failures in your next release What should you do?
- A. Run an automated smoke test suite.
- B. Notify operations of the release
- C. Monitor the logs looking for unusual error patterns
- D. Ensure all sources are checked into source control
Answer: C
NEW QUESTION 22
Which are techniques for dynamically choosing the target endpoint at runtime? Select all that are correct
- A. use javascript to set targeturl
- B. use routing tables defined for the proxy using the MGMT API
- C. nothing is needed, done by default
- D. use route rules with conditions
Answer: B
NEW QUESTION 23
You are implementing Concurrent Rate Limit, Spike Arrest and Quota policies in your proxy You want to make sure the simplest checks run first Using the flow shown in the diagram, which order of operations should you follow?
- A. Quota > Concurrent Rate Limit > Spike Arrest
- B. Quota > Spike Arrest > Concurrent Rate Limit
- C. Concurrent Rate Limit > Spike Arrest > Quota
- D. Spike Arrest > Quota > Concurrent Rate Limit
Answer: A
NEW QUESTION 24
You are implementing Concurrent Rate Limit, Spike Arrest and Quota policies in your proxy You want to make sure the simplest checks run first Using the flow shown in the diagram, which order of operations should you follow?
- A. Quota > Concurrent Rate Limit > Spike Arrest
- B. Quota > Spike Arrest > Concurrent Rate Limit
- C. Concurrent Rate Limit > Spike Arrest > Quota
- D. Spike Arrest > Quota > Concurrent Rate Limit
Answer: A
NEW QUESTION 25
As an API Engineer you get a calendar invite for a backlog grooming session. What should you expect to take place in the meeting?
- A. Review the high level design document and ask questions
- B. Review and update the user stories and tasks in detail.
- C. Review the Epics and meet the cross functional team
- D. Update support tickets that have been sitting for x number of days
Answer: A
NEW QUESTION 26
Which is a benefit of three-legged OAuth (authonzation_code grant)'?
- A. provides end-user credentials to requesting app
- B. allows another individual to access a user's private data
- C. provides access to user-specific resources without exposing end-user credentials to the client application
- D. authorization codes can be used multiple times to obtain access tokens
Answer: A
NEW QUESTION 27
The backend API team has asked for metrics on the performance of an API. Which two pieces of data should you provide?
- A. The network latency
- B. The internet latency
- C. The backend database latency
- D. The Apigee proxy latency
- E. The backend latency
Answer: C,E
NEW QUESTION 28
Your API generates tokens to authenticate users. You have the following requirements
1. Limited token lifetime.
2. Managed key rotation.
3. Self-verifiable content.
4 Compact data representation
5. Refresh without new challenge.
You plan to use SAML2 Which two of the above-listed requirements are satisfied by using SAML2?
- A. Refresh without a new challenge
- B. Compact data representation
- C. Self-verifiable content
- D. Limited token lifetime.
- E. Managed key rotation
Answer: D
NEW QUESTION 29
Which policy can be used to restrict access to API resources based on the client IP?
- A. Regular Expression Protection policy
- B. Raise Fault policy
- C. Access Control policy
- D. Basic Authentication policy
Answer: B
NEW QUESTION 30
Which features are supported in the OAuthV2 policy? Choose 3 answers
- A. Setting different expiration for refresh and access tokens
- B. Setting custom attributes for generated access tokens
- C. Storing of external access tokens
- D. Credentials validation when password grant_type is used
Answer: A,B,D
NEW QUESTION 31
An API product in Apigee can be used to
- A. configure the quota limits for APIs
- B. restrict access to APIs in different environments
- C. restrict access to a set of APIs
- D. all of the above
Answer: C
NEW QUESTION 32
You are building a new API, and have the choice between several names for a particular field. According to Apigee recommended practices, what should you do?
- A. Survey typical consumers to determine which common name to use
- B. Use the same field name as in the back end system
- C. Pick any name, and make sure that you use that name as consistently as possible
- D. Allow each developer to make their own choice.
Answer: C
NEW QUESTION 33
You are using the Apigee ExtractVariables policy JSONPath feature, and discover that the query is not returning the expected result for the payload you are providing What should you do?
- A. Check that the Accept header is set to application/json.
- B. Check that the Accept header is set to text/json
- C. Check that the Content-Type header is set to application/json
- D. Check that the Content-Type header is set to text/json
Answer: A
NEW QUESTION 34
Which statements ate true when the following policy is used?
<SpikeArrest continueOnError="false" name="Arrest">
<Rate>5ps</Rate>
</SpikeArrest>
- A. Spike arrest is calculated separately on each message processor, so you could end up with significantly more than 5 calls in a second
- B. The rate of 5 per second indicates that 5 requests can be made at any time during a second: but the 6th and later requests dunng the same second would be rejected
- C. The continueOnError setting means that normal flow processing will resume even if the traffic exceeds the spike arrest rate
- D. It is possible to make fewer than 5 requests in a second and still cause a spike arrest
Answer: C
NEW QUESTION 35
......
Tested Material Used To Apigee-API-Engineer: https://www.real4dumps.com/Apigee-API-Engineer_examcollection.html
Steps Necessary To Pass The Apigee-API-Engineer Exam: https://drive.google.com/open?id=1sKuwuVu7YO32eIzTwty-XwwoULC-EhcQ

