Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
F5 logo

F5Certified Solution Expert, Security

Domain 4Objective 1

4.01 Analyze Logs or Other Data Sources for Security Incidents 401 Practice Questions (Page 4)

Part of the SECURITY RESPONSE domain, which makes up ~24% of our current practice bank. F5 does not publish an official question count, but from its 105-minute exam (~40–70 total, ~10–17 in this domain), expect 3–6 from this objective — we provide 34 practice questions to prepare you well beyond it. (estimate)

34questions here
7free pages
9concepts

Questions 16–20

  1. 16application · medium

    During an incident investigation, the analyst has logs from the firewall, BIG-IP, and a compromised Linux server. The firewall log timestamps are in UTC, the BIG-IP logs are in local time (UTC-5), and the Linux server logs are in UTC. The analyst needs to determine the exact order of events. What is the first step to ensure an accurate timeline?

    Select an answer first
  2. 17foundation · easy

    Which factor most directly determines how long logs should be retained?

    Select an answer first
  3. 18application · medium

    A security analyst is reviewing BIG-IP ASM logs and notices a sudden increase in requests to a login page with unusual parameters, such as 'id=1 OR 1=1'. The requests come from a single IP address that has never appeared in the logs before. Which type of log analysis would most directly identify this as a potential SQL injection attempt?

    Select an answer first
  4. 19foundation · easy

    Which of the following is an example of correlating log events to detect a security incident?

    Select an answer first
  5. 20application · medium

    A SIEM analyst is correlating login failures from BIG-IP APM, a Linux server's /var/log/auth.log, and a Windows Active Directory domain controller. The BIG-IP logs use 'user', the Linux logs use 'username', and the Windows logs use 'sAMAccountName' for the same field. The analyst wants to write a single correlation rule that matches on the username across all three sources. What must be done first to make this rule work?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by F5. “401” is a trademark of its owner, used for identification only.