
F5Certified Technology Specialist, BIG-IP ASM (F5-CTS, BIG-IP ASM)
Domain 2Objective 4
Objective 2.04 Refine Policy Structure for Policy Elements (e.g., URLs, Parameters, Files Types, Headers, Sessions and Logins, Content Profiles, CSRF Protection, Anomaly Protection) 303 Practice Questions (Page 2)
Part of the Section 2: Create and customize policies domain, which makes up ~27% of our current practice bank.
24questions here
5free pages
8concepts
Questions 6–10
- 6
A web application serves JSON responses to AJAX requests. The ASM policy is in blocking mode and is generating false positives because it is applying HTML content checks to the JSON responses. You need to ensure that JSON responses are checked appropriately without false positives. What should you configure?
Select an answer first - 7
In an ASM file type policy, which two properties are typically configured for a file type?
Select an answer first - 8
In ASM CSRF protection, what is the role of the 'Origin' header check?
Select an answer first - 9
A web application has a form that submits a request to change a user's email address. The application uses CSRF tokens to protect against cross-site request forgery. However, the ASM policy is blocking legitimate requests because the token is not being recognized. You need to ensure that CSRF protection works without blocking legitimate requests. What should you configure?
Select an answer first - 10
What is the purpose of anomaly protection in ASM?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by F5. “303” is a trademark of its owner, used for identification only.