Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
F5 logo

F5Certified Technology Specialist, BIG-IP ASM (F5-CTS, BIG-IP ASM)

Domain 3Objective 1

Objective 3.01 Interpret Log Entries to Identify Opportunities to Refine the Policy 303 Practice Questions (Page 4)

Part of the Section 3: Maintain policy domain, which makes up ~10% of our current practice bank.

21questions here
5free pages
4concepts

Questions 16–20

  1. 16expert · hard

    A security analyst is reviewing an ASM attack log and sees a violation for "Attack signature detected" with a "severity" of "High" and a "confidence" of "Low". The analyst also sees the "enforced" field set to "true" and the "action" field set to "block". The analyst needs to determine if this is a true positive or a false positive. What should the analyst do?

    Select an answer first
  2. 17expert · hard

    An F5 administrator is reviewing ASM logs and sees a violation for "Illegal parameter value" on a parameter named "id". The "enforced" field is set to "true" and the "action" field is set to "block". The administrator notices that legitimate requests with numeric IDs are being blocked, while requests with alphanumeric IDs are allowed. The administrator needs to refine the policy to allow numeric IDs while still blocking malicious payloads. What should the administrator do?

    Select an answer first
  3. 18application · medium

    A security analyst is reviewing an ASM violation log and sees the entry "Violation: Illegal parameter value" with a "parameter_name" of "userid" and a "parameter_value" of "admin' OR '1'='1". The analyst needs to determine the likely attack type. What does this log entry indicate?

    Select an answer first
  4. 19application · medium

    A security team needs to review a history of changes made to the ASM policy, including who made the changes and when. The team wants to understand why a specific signature was disabled. Which ASM log type should they consult?

    Select an answer first
  5. 20foundation · easy

    Which BIG-IP ASM log type is primarily used to record administrative changes to the security policy, such as modifying a signature or adding a new URL?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by F5. “303” is a trademark of its owner, used for identification only.