
F5Certified Technology Specialist, BIG-IP ASM (F5-CTS, BIG-IP ASM)
Domain 2Objective 1
Objective 2.01 Determine the Appropriate Criteria for Initial Policy Definition Based on Application Requirements (e.g., Wildcards, Violations, Entities, Signatures, User-Defined Signatures) 303 Practice Questions (Page 2)
Part of the Section 2: Create and customize policies domain, which makes up ~27% of our current practice bank.
14questions here
3free pages
6concepts
Questions 6–10
- 6
A company is deploying ASM in front of a custom Java-based REST API that handles JSON requests. The API is used by a mobile app and a web portal. The security team wants to protect against injection attacks without blocking legitimate JSON payloads. Which signature selection strategy is most appropriate for the initial policy?
Select an answer first - 7
Which type of violation is detected by the ASM when an attacker attempts to inject SQL code into a parameter?
Select an answer first - 8
Which of the following is considered an entity in an ASM policy?
Select an answer first - 9
Which violation type is specifically related to the modification of client-side data stored by the application?
Select an answer first - 10
Why is it important to include relevant entities in an ASM policy?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by F5. “303” is a trademark of its owner, used for identification only.