
F5Certified Technology Specialist, BIG-IP ASM (F5-CTS, BIG-IP ASM)
Domain 2Objective 4
Objective 2.04 Refine Policy Structure for Policy Elements (e.g., URLs, Parameters, Files Types, Headers, Sessions and Logins, Content Profiles, CSRF Protection, Anomaly Protection) 303 Practice Questions (Page 4)
Part of the Section 2: Create and customize policies domain, which makes up ~27% of our current practice bank.
24questions here
5free pages
8concepts
Questions 16–20
- 16
A web application has a URL /admin that should only be accessible from internal IP addresses. The ASM policy is in blocking mode. You need to enforce this access control. What should you configure?
Select an answer first - 17
When customizing a content profile for JSON, what is a typical configuration you might adjust?
Select an answer first - 18
What is the primary function of an ASM header policy?
Select an answer first - 19
A web application experiences periodic traffic spikes that are legitimate, but the ASM policy is blocking requests during these spikes because the anomaly detection threshold is too low. You need to allow the legitimate traffic while still protecting against real attacks. What should you configure?
Select an answer first - 20
A web application uses a custom header 'X-Client-Version' to indicate the client version. The application only supports versions 1.0, 1.1, and 2.0. Clients with other versions should be blocked. The ASM policy is in blocking mode. What should you configure to enforce this?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by F5. “303” is a trademark of its owner, used for identification only.