Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
F5 logo

F5Certified Technology Specialist, BIG-IP ASM (F5-CTS, BIG-IP ASM)

Domain 1Objective 3

Objective 1.03 Determine Which ASM Mitigation Is Appropriate for a Particular Vulnerability 303 Practice Questions (Page 3)

Part of the Section 1: Assess security needs and choose an appropriate ASM policy domain, which makes up ~22% of our current practice bank.

17questions here
4free pages
3concepts

Questions 11–15

  1. 11application · medium

    A company's web application has a file upload feature that is vulnerable to command injection. The security team wants to mitigate this vulnerability, but they are concerned about blocking legitimate file uploads that may contain special characters. Which ASM mitigation should be configured?

    Select an answer first
  2. 12application · medium

    A company's web application has a file upload feature that is vulnerable to path traversal attacks, allowing attackers to upload files to unintended directories. The security team needs an ASM mitigation that prevents this specific attack. Which ASM mitigation should be configured?

    Select an answer first
  3. 13expert · hard

    A company's web application has a search feature that is vulnerable to both reflected XSS and SQL injection. The security team wants to mitigate both vulnerabilities, but they are concerned about the performance impact of enabling multiple signature sets. They also need to minimize false positives. Which approach should the security team take?

    Select an answer first
  4. 14application · medium

    A financial services company has a public-facing login portal. A vulnerability assessment identifies that the portal is susceptible to credential stuffing attacks, where attackers use lists of stolen usernames and passwords. The security team needs to reduce the success rate of these attacks without blocking legitimate users who may have mistyped their password a few times. Which ASM mitigation should be implemented?

    Select an answer first
  5. 15application · medium

    A company's web application has a search feature that reflects user input in the response without proper encoding. A vulnerability scan identifies this as a reflected XSS vulnerability. The development team is working on a fix, but the security team needs an immediate ASM mitigation to protect users. Which ASM mitigation should be configured?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by F5. “303” is a trademark of its owner, used for identification only.