Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
F5 logo

F5Certified Solution Expert, Security

Domain 4Objective 3

4.03 Determine the Appropriate Incident Response Plan Given Specific Attack Details 401 Practice Questions (Page 4)

Part of the SECURITY RESPONSE domain, which makes up ~24% of our current practice bank. F5 does not publish an official question count, but from its 105-minute exam (~40–70 total, ~10–17 in this domain), expect 3–6 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)

28questions here
6free pages
6concepts

Questions 16–20

  1. 16foundation · easy

    During triage, an analyst classifies an incident as high severity because it involves a data breach of customer records. Which factor most directly influenced this classification?

    Select an answer first
  2. 17foundation · easy

    After resolving a phishing incident, the incident response team identifies that the email filtering rules were insufficient. What is the most appropriate action to improve the incident response plan?

    Select an answer first
  3. 18expert · hard

    After a major incident, a company's incident response team conducts a lessons learned review. They find that the response was hindered by a lack of clear roles and responsibilities, and that some team members did not know who to report to. What is the most effective improvement to the incident response plan?

    Select an answer first
  4. 19application · medium

    A mid-sized company experiences a minor malware infection on a single employee's laptop. The malware is a known trojan that has been contained and removed. The incident response team has confirmed no data exfiltration. According to the incident response plan, what is the appropriate escalation and communication step?

    Select an answer first
  5. 20expert · hard

    A company's security team detects that an attacker has been using a legitimate employee's credentials to access the company's HR system and view salary information. The employee is on vacation and has not been using the system. The credentials were not phished; they appear to have been obtained from a previous data breach. What is the most likely classification of this incident?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by F5. “401” is a trademark of its owner, used for identification only.