Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
F5 logo

F5Certified Solution Expert, Security

Domain 1Objective 2

1.02 Analyze Threat Modeling Data to Determine Risk Profiles of the Infrastructure and Applications 401 Practice Questions (Page 4)

Part of the THREAT ANALYSIS domain, which makes up ~11% of our current practice bank. F5 does not publish an official question count, but from its 105-minute exam (~40–70 total, ~4–8 in this domain), expect 2–4 from this objective — we provide 22 practice questions to prepare you well beyond it. (estimate)

22questions here
5free pages
6concepts

Questions 16–20

  1. 16expert · hard

    A security analyst is correlating threat intelligence feeds with network telemetry to profile the risk of a critical application server. The threat intelligence feed reports a new zero-day vulnerability in the server's operating system. The network telemetry shows no unusual traffic to or from the server. The server is internet-facing and contains sensitive data. What is the most accurate risk assessment?

    Select an answer first
  2. 17foundation · easy

    Which risk should be prioritized first when using a likelihood-impact approach?

    Select an answer first
  3. 18foundation · easy

    Which application security factor is most directly related to the risk of injection attacks?

    Select an answer first
  4. 19application · medium

    A security analyst is compiling threat modeling data for a data center. They have vulnerability scan results showing a critical unpatched vulnerability in a database server. They also have threat intelligence indicating that this vulnerability is being actively exploited in the wild. Which additional data source would best help determine the likelihood of this server being attacked?

    Select an answer first
  5. 20application · medium

    An e-commerce company is profiling the risk of its customer-facing application. The application has a vulnerability in its authentication mechanism that allows brute-force attacks, and it stores customer credit card data. Threat intelligence shows an increasing number of credential-stuffing attacks against similar platforms. The company has a limited security budget and must prioritize fixes. Which risk should be addressed first?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by F5. “401” is a trademark of its owner, used for identification only.