Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
F5 logo

F5Certified Technology Specialist, BIG-IP APM

Domain 1Objective 2

Objective 1.02 Identify Which APM Tool(s) Should Be Used to Mitigate a Specific Authentication Attack 304 Practice Questions (Page 1)

Part of the Section 1: Assess security needs and requirements to create an APM policy domain, which makes up ~17% of our current practice bank. F5 does not publish an official question count, but from its 90-minute exam (~35–60 total, ~6–10 in this domain), expect 1–1 from this objective — we provide 19 practice questions to prepare you well beyond it. (estimate)

19questions here
4free pages
4concepts

Questions 1–5

  1. 1foundation · easy

    Which BIG-IP APM tool would be most appropriate to mitigate session hijacking by ensuring that session tokens are invalidated after a period of inactivity?

    Select an answer first
  2. 2application · medium

    A BIG-IP APM administrator is configuring a new access policy for a web application. The administrator wants to ensure that if a user closes the browser and reopens it, the user does not have to re-authenticate for a period of 8 hours. Which APM setting should be configured to achieve this?

    Select an answer first
  3. 3application · medium

    A BIG-IP APM administrator is configuring an access policy for a web application. The administrator wants to ensure that the session cookie is not accessible to client-side scripts, to mitigate the risk of cross-site scripting (XSS) attacks stealing the cookie. Which cookie attribute should be enabled?

    Select an answer first
  4. 4application · medium

    A company's BIG-IP APM is currently using a forms-based authentication method for its remote access portal. The security team has noticed a high volume of failed login attempts coming from a small set of IP addresses, each targeting a single user account with a list of common passwords. The company wants to block these attempts without affecting legitimate users who occasionally mistype their password. Which APM feature should be configured to address this specific attack?

    Select an answer first
  5. 5application · medium

    A BIG-IP APM administrator is troubleshooting an issue where users are frequently being prompted to re-authenticate when accessing a web application. The administrator suspects that the session cookie is being deleted by the browser when it is closed. Which APM setting should be adjusted to ensure the session persists across browser restarts?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by F5. “304” is a trademark of its owner, used for identification only.