Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
F5 logo

F5Certified Solution Expert, Security

Domain 1Objective 2

1.02 Analyze Threat Modeling Data to Determine Risk Profiles of the Infrastructure and Applications 401 Practice Questions (Page 3)

Part of the THREAT ANALYSIS domain, which makes up ~11% of our current practice bank. F5 does not publish an official question count, but from its 105-minute exam (~40–70 total, ~4–8 in this domain), expect 2–4 from this objective — we provide 22 practice questions to prepare you well beyond it. (estimate)

22questions here
5free pages
6concepts

Questions 11–15

  1. 11application · medium

    A company is profiling the risk of a customer relationship management (CRM) application. The application has a vulnerability that allows unauthorized access to customer data, but it requires a valid user account. The company has a policy of not enforcing password complexity. Threat intelligence shows an increase in phishing attacks targeting employees. Which factor most increases the likelihood of this vulnerability being exploited?

    Select an answer first
  2. 12expert · hard

    A security team is using a qualitative risk matrix with likelihood ratings (Low, Medium, High) and impact ratings (Low, Medium, High). They have identified a risk with a Medium likelihood and High impact. The team is debating whether to use a quantitative analysis to support their decision. Which of the following is a valid reason to supplement the qualitative assessment with a quantitative analysis?

    Select an answer first
  3. 13application · medium

    A security team is analyzing threat modeling data to profile the risk of a new internal web application. They have access to a vulnerability database that lists a critical remote code execution flaw in the web server software, but they have no information about whether the application is exposed to the internet or if any attackers are actively targeting it. Which additional data source would be most valuable to complete the risk profile?

    Select an answer first
  4. 14foundation · easy

    In a risk profile, which component is used to estimate how often a threat event is expected to occur?

    Select an answer first
  5. 15foundation · easy

    Which source of threat modeling data provides real-time information about active attack campaigns and indicators of compromise observed across the internet?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by F5. “401” is a trademark of its owner, used for identification only.