Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
F5 logo

F5Certified Solution Expert, Security

Domain 1Objective 2

1.02 Analyze Threat Modeling Data to Determine Risk Profiles of the Infrastructure and Applications 401 Practice Questions (Page 1)

Part of the THREAT ANALYSIS domain, which makes up ~11% of our current practice bank. F5 does not publish an official question count, but from its 105-minute exam (~40–70 total, ~4–8 in this domain), expect 2–4 from this objective — we provide 22 practice questions to prepare you well beyond it. (estimate)

22questions here
5free pages
6concepts

Questions 1–5

  1. 1expert · hard

    A security architect is evaluating the risk of a legacy application that processes credit card payments. The application has a known SQL injection vulnerability that has not been patched because the vendor is no longer providing updates. The application is isolated on a separate network segment with strict firewall rules, and threat intelligence shows no active exploitation of this specific vulnerability. The company has a high risk tolerance for legacy systems but a low tolerance for data breaches. What is the most appropriate risk treatment?

    Select an answer first
  2. 2application · medium

    A company is profiling the risk of its internal network. Network telemetry shows a high volume of outbound traffic from a server to an external IP address that is listed in a threat intelligence feed as a known command-and-control (C2) server. The server is not supposed to communicate externally and contains proprietary data. What is the most appropriate immediate risk determination?

    Select an answer first
  3. 3foundation · easy

    Which component of a risk profile represents the financial or operational importance of an asset to the organization?

    Select an answer first
  4. 4expert · hard

    A company is analyzing the risk profile of its infrastructure. They have a public-facing web server with a critical vulnerability that is being actively exploited. They also have an internal database server with a high-severity vulnerability that is not being exploited. The web server contains no sensitive data, while the database contains customer PII. The company has limited resources and must choose one server to patch first. Which server should be prioritized?

    Select an answer first
  5. 5foundation · easy

    When analyzing threat modeling data for a server, which factor is most directly related to the server's exposure to network-based attacks?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by F5. “401” is a trademark of its owner, used for identification only.