
F5Certified Solution Expert, Security
Domain 4Objective 1
4.01 Analyze Logs or Other Data Sources for Security Incidents 401 Practice Questions (Page 5)
Part of the SECURITY RESPONSE domain, which makes up ~24% of our current practice bank. F5 does not publish an official question count, but from its 105-minute exam (~40–70 total, ~10–17 in this domain), expect 3–6 from this objective — we provide 34 practice questions to prepare you well beyond it. (estimate)
34questions here
7free pages
9concepts
Questions 21–25
- 21
Why is log normalization important when analyzing logs from different sources?
Select an answer first - 22
A security analyst is investigating a potential malware infection on a user's workstation. The endpoint detection and response (EDR) tool shows the malware was downloaded from a website. The firewall logs show the user's workstation connecting to the website's IP address. The proxy logs show the URL requested. Which additional data source would best help the analyst determine whether the malware executed and what it did?
Select an answer first - 23
A company is deploying a new SIEM and must decide how to collect logs from BIG-IP devices, firewalls, and servers. The security team wants to ensure logs are not lost during network outages and that they can be replayed once the connection is restored. Which log collection method best meets this requirement?
Select an answer first - 24
A SIEM correlation rule alerts when a user logs in to the VPN and then accesses an internal file share within 10 minutes. The rule fires for a user who is a known contractor. The analyst reviews the logs and finds the contractor logged in from a new IP address and accessed files they have never accessed before. The contractor's manager confirms the contractor is on a new project. Which action is most appropriate?
Select an answer first - 25
A SIEM receives logs from BIG-IP, Check Point firewalls, and Linux servers. The analyst is building a correlation rule to detect port scans. The BIG-IP logs use 'dest_port', the Check Point logs use 'destination_port', and the Linux logs use 'dport'. The analyst wants to write a single rule that references the destination port. What is the most efficient approach?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by F5. “401” is a trademark of its owner, used for identification only.