
F5Certified Technology Specialist, BIG-IP DNS
Domain 1Objective 7
Objective 1.07 Identify DNS Security Concepts and Their Purpose [DDOS, DNSSEC, AnyCast, DNSFirewall, Site Validation, iRules, and Impacts of Floating self-IP Versus Non-Floating self-IP Listener] 302 Practice Questions (Page 3)
Part of the Section 1: Concepts domain, which makes up ~46% of our current practice bank.
25questions here
5free pages
7concepts
Questions 11–15
- 11
Which security property does DNSSEC provide for DNS data?
Select an answer first - 12
A global e-commerce company runs authoritative DNS from two data centers. During a recent volumetric attack, one data center's DNS infrastructure was overwhelmed, causing resolution failures for customers worldwide. The company wants to distribute the attack load across both sites and ensure that queries continue to be answered even if one site is saturated. Which approach should they implement?
Select an answer first - 13
A company's authoritative DNS server is being targeted by a DNS amplification attack, where the attacker sends spoofed queries with a small source IP and the server responds with large responses, flooding the victim. The company wants to mitigate this attack on the BIG-IP DNS server itself. Which configuration should they implement?
Select an answer first - 14
What is the purpose of site validation in DNS load balancing?
Select an answer first - 15
A content delivery network operates authoritative DNS servers in 10 locations worldwide. They want to ensure that a DDoS attack targeting a single DNS server IP does not take down the entire service. They also want to minimize latency for users. Which deployment strategy best meets these requirements?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by F5. “302” is a trademark of its owner, used for identification only.