
F5Certified Solution Expert, Security
Domain 2Objective 3
2.03 Determine the Appropriate Security Framework for an Application 401 Practice Questions (Page 3)
Part of the ARCHITECT SOLUTIONS domain, which makes up ~28% of our current practice bank. F5 does not publish an official question count, but from its 105-minute exam (~40–70 total, ~11–20 in this domain), expect 2–4 from this objective — we provide 29 practice questions to prepare you well beyond it. (estimate)
29questions here
6free pages
7concepts
Questions 11–15
- 11
An online gaming company is launching a new multiplayer game with a backend API that handles player authentication and game state. The API experiences high, sustained traffic with low latency requirements. The security team is concerned about DDoS attacks and credential stuffing. Which security framework components should be combined to address these threats without impacting performance?
Select an answer first - 12
Which security framework is most appropriate for protecting an application from distributed denial-of-service (DDoS) attacks that aim to overwhelm its network resources?
Select an answer first - 13
A company is deploying a web application that will be used by customers in the European Union and the United States. The application must comply with both GDPR and CCPA. The security team is designing the security framework and needs to decide where to store user data. Which approach best satisfies both regulations?
Select an answer first - 14
A government agency is deploying a public-facing application that allows citizens to file tax returns. The application must comply with strict data residency requirements, meaning all data must remain within the country's borders. The agency also requires strong authentication and protection against web attacks. Which security framework should be selected?
Select an answer first - 15
A company is designing a security architecture for a new application that will be deployed in a containerized environment using Kubernetes. The application consists of multiple microservices that need to communicate securely. The security team wants to implement service-to-service authentication and encryption, as well as protect the ingress traffic from web attacks. Which architecture should be used?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by F5. “401” is a trademark of its owner, used for identification only.