Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
F5 logo

F5Certified Technology Specialist, BIG-IP ASM (F5-CTS, BIG-IP ASM)

Domain 1Objective 1

Objective 1.01 Explain the Potential Effects of Common Attacks on Web Applications 303 Practice Questions (Page 2)

Part of the Section 1: Assess security needs and choose an appropriate ASM policy domain, which makes up ~22% of our current practice bank.

24questions here
5free pages
4concepts

Questions 6–10

  1. 6application · medium

    A healthcare organization's patient portal was compromised. An attacker exploited a vulnerability in a third-party component to upload a webshell and gain persistent access to the server. The organization must now report the breach to regulators. Which OWASP Top Ten category does this vulnerability belong to, and what is the primary business impact?

    Select an answer first
  2. 7expert · hard

    A security analyst is investigating an incident where an attacker used a cross-site scripting (XSS) payload to steal session cookies from authenticated users. The stolen cookies were then used to access user accounts and change email addresses. Which combination of OWASP Top Ten risks and impacts does this incident represent?

    Select an answer first
  3. 8expert · hard

    A company is deploying ASM to protect a web application that processes credit card payments. The security team must ensure compliance with PCI DSS, which requires protecting cardholder data. The application has a known vulnerability that could allow an attacker to extract card numbers via a response-based attack. Which ASM feature is MOST critical to deploy to mitigate this specific risk?

    Select an answer first
  4. 9expert · hard

    A large enterprise runs a critical web application that handles both authenticated user sessions and public content. The security team must choose between two ASM policies: Policy A has strict signature enforcement and blocks all suspicious requests; Policy B has signature enforcement in 'Alarm' mode and relies on bot defense and rate limiting. The application has a history of false positives that caused customer-facing outages. Which policy is MORE appropriate, and why?

    Select an answer first
  5. 10foundation · easy

    Which BIG-IP ASM policy element is used to enforce a positive security model by defining expected input patterns for a specific parameter, thereby mitigating injection attacks?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by F5. “303” is a trademark of its owner, used for identification only.