
F5Certified Technology Specialist, BIG-IP ASM (F5-CTS, BIG-IP ASM)
Domain 1Objective 1
Objective 1.01 Explain the Potential Effects of Common Attacks on Web Applications 303 Practice Questions (Page 1)
Part of the Section 1: Assess security needs and choose an appropriate ASM policy domain, which makes up ~22% of our current practice bank.
24questions here
5free pages
4concepts
Questions 1–5
- 1
An online banking application is found to have a flaw where an authenticated user can modify the 'account_id' parameter in a URL to view another customer's account details. The bank discovers this after a customer complains about unauthorized transactions. Which OWASP Top Ten category does this vulnerability belong to, and what is the primary impact?
Select an answer first - 2
Which BIG-IP ASM feature is specifically designed to detect and block SQL injection attempts as part of mitigating the OWASP Injection risk?
Select an answer first - 3
A company's web application stores credit card numbers in a database. An attacker exploits a SQL injection vulnerability to extract the data. The company's ASM policy is configured with a Data Guard feature. How could Data Guard have helped mitigate the impact of this attack?
Select an answer first - 4
Which BIG-IP ASM mechanism is specifically designed to identify and mitigate automated attacks such as credential stuffing and web scraping?
Select an answer first - 5
An e-commerce site is experiencing a surge of automated login attempts using credential stuffing lists. The attempts are coming from a distributed botnet and are causing account lockouts for legitimate users. Which ASM feature is BEST suited to mitigate this specific attack while minimizing impact on real customers?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by F5. “303” is a trademark of its owner, used for identification only.