
F5Certified Technology Specialist, BIG-IP ASM (F5-CTS, BIG-IP ASM)
Domain 1Objective 3
Objective 1.03 Determine Which ASM Mitigation Is Appropriate for a Particular Vulnerability 303 Practice Questions (Page 2)
Part of the Section 1: Assess security needs and choose an appropriate ASM policy domain, which makes up ~22% of our current practice bank.
17questions here
4free pages
3concepts
Questions 6–10
- 6
A web application has a known vulnerability that allows attackers to inject malicious SQL commands into database queries. Which ASM mitigation is designed to address this vulnerability type?
Select an answer first - 7
A vulnerability assessment report lists a cross-site scripting (XSS) flaw in a web application. How does this information guide ASM policy selection?
Select an answer first - 8
An organization has a low-risk internal application that is not exposed to the internet. Which ASM mitigation approach is most suitable for this scenario?
Select an answer first - 9
A company's web application allows users to upload profile pictures. A vulnerability assessment reveals that the application does not validate file types, allowing attackers to upload malicious executable files. The security team needs an ASM mitigation that prevents the upload of dangerous file types while minimizing false positives for legitimate image uploads. Which ASM mitigation should be configured?
Select an answer first - 10
A company's web application has a login form that is vulnerable to brute force attacks. The security team wants to mitigate this vulnerability, but they are concerned about locking out legitimate users who may forget their passwords. They need a mitigation that slows down automated attempts without completely blocking access after a few failures. Which ASM mitigation should be configured?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by F5. “303” is a trademark of its owner, used for identification only.