
F5Certified Solution Expert, Security
Domain 4Objective 3
4.03 Determine the Appropriate Incident Response Plan Given Specific Attack Details 401 Practice Questions (Page 1)
Part of the SECURITY RESPONSE domain, which makes up ~24% of our current practice bank. F5 does not publish an official question count, but from its 105-minute exam (~40–70 total, ~10–17 in this domain), expect 3–6 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)
28questions here
6free pages
6concepts
Questions 1–5
- 1
In the preparation phase of an incident response plan, which activity is most likely to be performed?
Select an answer first - 2
During a malware infection incident, which response action is most appropriate to perform first to prevent the malware from spreading to other systems?
Select an answer first - 3
A large e-commerce company experiences a ransomware attack that encrypts files on several critical servers. The attack is spreading rapidly. The incident response team has been activated. Who should be notified FIRST according to the incident response plan?
Select an answer first - 4
A company's security team discovers that an attacker has been exfiltrating sensitive customer data from a database over the past three months. The attacker used a legitimate database administrator's credentials. The company is subject to data breach notification laws. What is the most appropriate response action?
Select an answer first - 5
After a phishing incident, a company's incident response team identifies that the email security gateway failed to block a malicious attachment because it was a new variant. What should be updated in the incident response plan?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by F5. “401” is a trademark of its owner, used for identification only.