
F5Certified Technology Specialist, BIG-IP ASM (F5-CTS, BIG-IP ASM)
Domain 1Objective 1
Objective 1.01 Explain the Potential Effects of Common Attacks on Web Applications 303 Practice Questions (Page 4)
Part of the Section 1: Assess security needs and choose an appropriate ASM policy domain, which makes up ~22% of our current practice bank.
24questions here
5free pages
4concepts
Questions 16–20
- 16
A security team is reviewing an ASM report and finds a high number of violations triggered by requests containing XML with external entity references. The application parses XML data from partner integrations. Which OWASP Top Ten risk is being targeted, and what is the most severe potential impact?
Select an answer first - 17
A company is deploying ASM to protect a web application that uses both REST APIs and a traditional HTML front-end. The security team wants to protect against OWASP Top Ten risks, but the API endpoints have different characteristics than the HTML pages (e.g., JSON payloads, no session cookies). Which approach is the MOST effective?
Select an answer first - 18
A successful SQL injection attack exfiltrates customer credit card numbers from a retail web application. Which business impact is most directly associated with this incident?
Select an answer first - 19
An organization is deploying BIG-IP ASM to protect a legacy web application that is known to have a cross-site scripting (XSS) vulnerability in its search functionality that cannot be fixed immediately. Which ASM configuration is MOST appropriate to mitigate this risk while maintaining application functionality?
Select an answer first - 20
Which OWASP Top Ten risk involves an attacker exploiting a flaw in the application's authentication or session management functions to impersonate a legitimate user?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by F5. “303” is a trademark of its owner, used for identification only.