
F5Certified Technology Specialist, BIG-IP ASM (F5-CTS, BIG-IP ASM)
Domain 3Objective 1
Objective 3.01 Interpret Log Entries to Identify Opportunities to Refine the Policy 303 Practice Questions (Page 1)
Part of the Section 3: Maintain policy domain, which makes up ~10% of our current practice bank.
21questions here
5free pages
4concepts
Questions 1–5
- 1
A security analyst reviews an ASM violation log and sees the entry "Violation: Illegal parameter value" with a "parameter_name" of "redirect" and a "parameter_value" of "https://evil.com". The analyst needs to determine the likely attack type. What does this log entry indicate?
Select an answer first - 2
A security analyst needs to review the details of a specific security violation that occurred on a web application. Which BIG-IP ASM log type should they examine?
Select an answer first - 3
An analyst is reviewing an ASM attack log and sees the field "request_status" with a value of "200". The analyst wants to confirm that the request was successfully processed by the backend server despite a violation being logged. Which field in the log entry provides this confirmation?
Select an answer first - 4
In a BIG-IP ASM log entry, which field indicates whether the policy is in blocking mode or transparent mode for a specific violation?
Select an answer first - 5
A security analyst is reviewing ASM logs and sees a violation for "Illegal parameter value" with a "parameter_name" of "file" and a "parameter_value" of "../../etc/passwd". The "enforced" field is set to "true" and the "action" field is set to "block". The analyst needs to determine if this is a true positive or a false positive. What should the analyst do?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by F5. “303” is a trademark of its owner, used for identification only.