
F5Certified Technology Specialist, BIG-IP ASM (F5-CTS, BIG-IP ASM)
Domain 2Objective 3
Objective 2.03 Review and Evaluate Rules Based on Information Gathered from ASM (e.g., Attack Signatures, DataGuard, Parameters, Entities) 303 Practice Questions (Page 4)
Part of the Section 2: Create and customize policies domain, which makes up ~27% of our current practice bank.
17questions here
4free pages
5concepts
Questions 16–17
- 16
An analyst is reviewing DataGuard events and finds that a web application is returning social security numbers (SSNs) in error messages. The application team says this is a bug and they will fix it in the next release, which is two weeks away. The compliance team requires that SSNs not be exposed. What should the analyst do to mitigate the risk immediately?
Select an answer first - 17
An analyst is reviewing ASM logs and finds that a parameter 'file' is triggering 'Command Injection' signature matches. The requests are using a legitimate file name, but with a trailing semicolon and a command. The application team confirms that the 'file' parameter should only accept alphanumeric file names. The policy is in 'Blocking' mode. What should the analyst do to prevent these attacks?
Select an answer first
Finished these 2 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to 303
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by F5. “303” is a trademark of its owner, used for identification only.