Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
F5 logo

F5Certified Solution Expert, Security

Domain 4Objective 3

4.03 Determine the Appropriate Incident Response Plan Given Specific Attack Details 401 Practice Questions (Page 5)

Part of the SECURITY RESPONSE domain, which makes up ~24% of our current practice bank. F5 does not publish an official question count, but from its 105-minute exam (~40–70 total, ~10–17 in this domain), expect 3–6 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)

28questions here
6free pages
6concepts

Questions 21–25

  1. 21foundation · easy

    During a high-impact data breach that affects customer data, which communication channel is most appropriate for notifying senior management?

    Select an answer first
  2. 22expert · hard

    A company's security team detects a ransomware attack that has encrypted files on a file server. The ransomware note demands payment in cryptocurrency. The team also discovers that the attacker gained access through a compromised VPN account. The company has backups, but they are stored on the same network and may also be encrypted. What is the most appropriate incident response plan?

    Select an answer first
  3. 23application · medium

    A security analyst observes a sudden increase in outbound DNS queries from multiple internal servers to a domain that is only a few days old. The queries are occurring at regular intervals. What is the most likely classification of this activity?

    Select an answer first
  4. 24application · medium

    A government agency detects that an employee's credentials were used to access classified documents outside of working hours. The employee denies any involvement. The investigation reveals that the credentials were phished two weeks ago. Which incident response plan should be activated?

    Select an answer first
  5. 25expert · hard

    A company's security team detects a sophisticated attack that involves both a DDoS attack on their public website and a simultaneous attempt to exploit a vulnerability in their internal application. The DDoS is consuming resources, while the exploitation attempt is targeting a server that contains sensitive customer data. What is the most appropriate incident response plan?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by F5. “401” is a trademark of its owner, used for identification only.