Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
F5 logo

F5Certified Technology Specialist, BIG-IP ASM (F5-CTS, BIG-IP ASM)

Domain 3Objective 1

Objective 3.01 Interpret Log Entries to Identify Opportunities to Refine the Policy 303 Practice Questions (Page 3)

Part of the Section 3: Maintain policy domain, which makes up ~10% of our current practice bank.

21questions here
5free pages
4concepts

Questions 11–15

  1. 11foundation · easy

    A BIG-IP ASM log entry shows a violation with an 'enforcement mode' of 'transparent'. What does this indicate about the request?

    Select an answer first
  2. 12application · medium

    A security analyst is reviewing an ASM attack log and sees the field "request_uri" with a value of "/login.php?id=1&user=admin". The analyst needs to identify the parameters that were sent in the request. Which field in the log entry provides this information?

    Select an answer first
  3. 13expert · hard

    An F5 administrator is reviewing ASM logs and sees a violation for "Attack signature detected" with a "signature_name" of "SQL Injection" and a "severity" of "High". The administrator also sees the "enforced" field set to "true" and the "action" field set to "block". The administrator notices that the same signature is also appearing in the logs for requests that are NOT being blocked. What is the most likely explanation?

    Select an answer first
  4. 14expert · hard

    A security analyst is reviewing ASM logs and sees a violation for "Attack signature detected" with the "staging" field set to "true" and the "action" field set to "log". The analyst also sees the "enforced" field set to "false". The analyst needs to determine if the signature is ready to be moved to blocking mode. What should the analyst do?

    Select an answer first
  5. 15expert · hard

    An F5 administrator is investigating a security incident and needs to correlate ASM attack logs with system-level events to understand the full scope of the attack. The administrator needs to find the BIG-IP system logs that correspond to the time of the attack. Which log type should the administrator consult?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by F5. “303” is a trademark of its owner, used for identification only.