
F5Certified Solution Expert, Security
Domain 2Objective 3
2.03 Determine the Appropriate Security Framework for an Application 401 Practice Questions (Page 4)
Part of the ARCHITECT SOLUTIONS domain, which makes up ~28% of our current practice bank. F5 does not publish an official question count, but from its 105-minute exam (~40–70 total, ~11–20 in this domain), expect 2–4 from this objective — we provide 29 practice questions to prepare you well beyond it. (estimate)
29questions here
6free pages
7concepts
Questions 16–20
- 16
A healthcare organization is deploying a patient portal that allows users to view medical records and schedule appointments. The portal must comply with HIPAA, requiring encryption of data in transit and at rest, and strong user authentication. The application is hosted on-premises behind an F5 BIG-IP device. Which combination of security framework components should the architect select to meet these requirements?
Select an answer first - 17
An application requires that only authenticated users be able to access its administrative interface. Which security framework component should be mapped to this requirement?
Select an answer first - 18
An application processes credit card payments and must comply with PCI DSS. Which security framework component is most directly required by PCI DSS?
Select an answer first - 19
A financial services company is deploying a customer-facing web application that handles account transfers. The application is built as a set of REST APIs served from a Kubernetes cluster, with a JavaScript single-page application (SPA) delivered from a CDN. The security team requires protection against OWASP Top 10 web attacks, including SQL injection and cross-site scripting, with minimal added latency for API responses. Which security framework component should be placed in front of the API endpoints?
Select an answer first - 20
A multinational company is deploying a web application that processes credit card payments. The application must comply with PCI DSS. The architecture includes an F5 BIG-IP with ASM and an application server. Which configuration is required to meet PCI DSS requirements for the web application layer?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by F5. “401” is a trademark of its owner, used for identification only.