Suggested answer

API Manager policies enforce governance on APIs at runtime (applied to the API gateway layer without changing the Mule application code). Common policies:

1. Rate Limiting: Restrict number of requests per time window (per API or per client).
2. Spike Control: Queue requests exceeding limits rather than rejecting them.
3. Client ID Enforcement: Require callers to pass a valid client_id and client_secret (registered in Exchange) in headers or query params.
4. OAuth 2.0 Access Token Enforcement: Validate Bearer tokens from an external OAuth provider.
5. JWT Validation: Validate JSON Web Tokens.
6. IP Allowlist/Blocklist: Restrict or deny traffic from specific IP ranges.
7. Header Injection: Add request/response headers automatically. Policies execute before the Mule flow — they are applied and managed in API Manager independent of the application deployment.

Practice content for interview preparation; not an official vendor answer. Verify details against current product documentation.

Community comments (0)

No comments yet.

Sign in or create a free account to add a comment. Comments are moderated before they appear.

Plain text only, 3–2000 characters. A moderator reviews every comment before it is published.