
F5Certified Solution Expert, Security
Domain 1Objective 1
1.01 Analyze External Threat Research to Determine the Potential Impact to an Organization 401 Practice Questions (Page 4)
Part of the THREAT ANALYSIS domain, which makes up ~11% of our current practice bank. F5 does not publish an official question count, but from its 105-minute exam (~40–70 total, ~4–8 in this domain), expect 2–4 from this objective — we provide 22 practice questions to prepare you well beyond it. (estimate)
22questions here
5free pages
4concepts
Questions 16–20
- 16
A threat intelligence report reveals a vulnerability in a widely used network firewall that could allow remote code execution. What is the most important factor to consider when assessing the impact of this threat on an organization?
Select an answer first - 17
A security team reviews two threat reports. Report A describes a vulnerability in a widely used web server that is actively exploited in the wild. Report B describes a vulnerability in a niche legacy application that is not exposed to the internet and has no known exploits. The team has limited resources. Which threat should be prioritized?
Select an answer first - 18
A healthcare organization reads a government advisory about a ransomware group that has been targeting the sector. The advisory lists the group's preferred initial access vector as phishing emails with malicious LNK files. The organization's security team wants to reduce the risk of a successful attack. Which control is most directly aligned with the threat intelligence?
Select an answer first - 19
An organization's security team is analyzing a threat report about a new malware strain. The report includes a detailed analysis of the malware's behavior, including its persistence mechanism and C2 communication. The team wants to create a detection rule for their SIEM. Which information from the report is most useful for creating a host-based detection rule?
Select an answer first - 20
A threat intelligence report describes a phishing campaign that uses a specific subject line and a malicious attachment. The report includes the attachment's hash and the sender's email address. An organization wants to block this campaign at the email gateway. Which intelligence is most directly useful?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by F5. “401” is a trademark of its owner, used for identification only.