Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
F5 logo

F5Certified Technology Specialist, BIG-IP ASM (F5-CTS, BIG-IP ASM)

Domain 1Objective 3

Objective 1.03 Determine Which ASM Mitigation Is Appropriate for a Particular Vulnerability 303 Practice Questions (Page 1)

Part of the Section 1: Assess security needs and choose an appropriate ASM policy domain, which makes up ~22% of our current practice bank.

17questions here
4free pages
3concepts

Questions 1–5

  1. 1foundation · easy

    A security analyst is using a vulnerability assessment tool to prepare for configuring an ASM policy. What is the primary purpose of such a tool in this context?

    Select an answer first
  2. 2application · medium

    A vulnerability assessment of a web application reveals that it is vulnerable to a newly discovered zero-day attack for which no ASM signature exists yet. The application cannot be taken offline, and the security team needs to implement a mitigation that can detect and block the attack based on its behavior rather than a known signature. Which ASM mitigation should be used?

    Select an answer first
  3. 3expert · hard

    A company has a web application that is protected by an ASM policy. A vulnerability assessment reveals that the application is vulnerable to both SQL injection and XSS. The security team wants to mitigate both vulnerabilities, but they are concerned about the performance impact of enabling multiple signature sets in blocking mode. They also need to minimize false positives. Which approach should the security team take?

    Select an answer first
  4. 4application · medium

    A security analyst is reviewing the results of a vulnerability assessment for a web application. The report categorizes vulnerabilities by severity and type, including SQL injection, XSS, and command injection. The analyst needs to prioritize which ASM mitigations to configure first. Based on the vulnerability assessment, which approach should the analyst take?

    Select an answer first
  5. 5application · medium

    A security analyst runs a vulnerability scan against a web application and discovers that the application is vulnerable to a known SQL injection flaw in a third-party library. The application team cannot patch the library for 30 days. The analyst needs to configure an ASM mitigation that provides immediate protection while the patch is pending. Which ASM mitigation should the analyst configure?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by F5. “303” is a trademark of its owner, used for identification only.