
F5Certified Technology Specialist, BIG-IP ASM (F5-CTS, BIG-IP ASM)
Domain 1Objective 2
Objective 1.02 Explain How Specific Security Policies Mitigate Various Web Application Attacks 303 Practice Questions (Page 5)
Part of the Section 1: Assess security needs and choose an appropriate ASM policy domain, which makes up ~22% of our current practice bank.
31questions here
7free pages
15concepts
Questions 21–25
- 21
What does ASM validate to prevent HTTP response splitting attacks?
Select an answer first - 22
Which ASM capability helps identify automated brute force attempts?
Select an answer first - 23
What does ASM do to mitigate HTTP parameter pollution (HPP) attacks?
Select an answer first - 24
A financial services company's web application accepts a 'userID' parameter that is used in SQL queries. An attacker has been observed sending requests with 'userID=1 OR 1=1' and 'userID=<script>alert(1)</script>'. The security team wants to block both attack types while minimizing false positives on legitimate user IDs that are alphanumeric. Which ASM policy configuration should be applied?
Select an answer first - 25
Which ASM mechanism is primarily responsible for detecting known SQL injection patterns in incoming requests?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by F5. “303” is a trademark of its owner, used for identification only.