Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
F5 logo

F5Certified Solution Expert, Security

Domain 4Objective 3

4.03 Determine the Appropriate Incident Response Plan Given Specific Attack Details 401 Practice Questions (Page 2)

Part of the SECURITY RESPONSE domain, which makes up ~24% of our current practice bank. F5 does not publish an official question count, but from its 105-minute exam (~40–70 total, ~10–17 in this domain), expect 3–6 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)

28questions here
6free pages
6concepts

Questions 6–10

  1. 6foundation · easy

    An incident response team discovers a low-impact malware infection on a single workstation. According to the escalation procedures, what is the most appropriate action?

    Select an answer first
  2. 7application · medium

    A hospital's IT team discovers that a phishing email was opened by a staff member, and the attacker has gained access to a database containing patient records. The database is on a server that also hosts other critical applications. What is the most appropriate immediate response action?

    Select an answer first
  3. 8application · medium

    A financial services company's security team detects a large-scale SYN flood targeting their public-facing web application. The attack is consuming all available connection slots, causing legitimate users to experience timeouts. The source IPs are distributed across multiple countries and appear to be spoofed. Which incident response plan should the team activate?

    Select an answer first
  4. 9foundation · easy

    A security analyst discovers that an employee has been exfiltrating sensitive company data to a personal cloud storage account. Which incident response plan is most appropriate to select?

    Select an answer first
  5. 10application · medium

    A security analyst notices unusual outbound traffic from a single workstation to an external IP address known to be a command-and-control server. The workstation has been sending encrypted data packets at regular intervals. What is the most likely classification of this incident?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by F5. “401” is a trademark of its owner, used for identification only.