
F5Certified Solution Expert, Security
Domain 4Objective 1
4.01 Analyze Logs or Other Data Sources for Security Incidents 401 Practice Questions (Page 6)
Part of the SECURITY RESPONSE domain, which makes up ~24% of our current practice bank. F5 does not publish an official question count, but from its 105-minute exam (~40–70 total, ~10–17 in this domain), expect 3–6 from this objective — we provide 34 practice questions to prepare you well beyond it. (estimate)
34questions here
7free pages
9concepts
Questions 26–30
- 26
A SIEM correlation rule flags an event when a user logs in to the VPN and then accesses an internal server within 5 minutes. The rule fires frequently for a specific user who is a system administrator. The analyst reviews the logs and finds that the admin's VPN login is always followed by a scheduled script that connects to the server. What is the most appropriate action to reduce false positives?
Select an answer first - 27
A company is required to retain security logs for 3 years for compliance. They currently store logs in a SIEM with a 1-year hot retention and then archive to cold storage. During a forensic investigation of an incident that occurred 2 years ago, the analyst needs to search the archived logs. The cold storage retrieval takes 24 hours. The incident response plan requires initial findings within 4 hours. What is the best approach to meet both the compliance and investigation requirements?
Select an answer first - 28
A security analyst is investigating a suspected data breach. The BIG-IP ASM logs show a successful SQL injection attack against a web application at 2:00 PM. The database server logs show a large data export at 2:15 PM. However, the firewall logs show no outbound traffic from the database server at that time. The analyst must determine whether data was actually exfiltrated. Which conclusion is best supported by the available evidence?
Select an answer first - 29
A company must retain security logs for 12 months to meet a regulatory requirement. They currently store BIG-IP, firewall, and Active Directory logs on each device locally, with only 30 days of history. The security team needs a central repository to search all logs quickly during an investigation. Which approach best satisfies both the retention and searchability requirements?
Select an answer first - 30
A company aggregates logs from BIG-IP, Cisco ASA firewalls, and Windows servers into a SIEM. The analyst notices that the source IP field is sometimes populated with the client IP and sometimes with the proxy IP, depending on the log source. This inconsistency is causing correlation rules to miss attacks. What is the most effective way to resolve this issue?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by F5. “401” is a trademark of its owner, used for identification only.