
F5Certified Solution Expert, Security
Domain 2Objective 1
2.01 Determine the Correct Solution to Mitigate a Given Threat 401 Practice Questions (Page 2)
Part of the ARCHITECT SOLUTIONS domain, which makes up ~28% of our current practice bank. F5 does not publish an official question count, but from its 105-minute exam (~40–70 total, ~11–20 in this domain), expect 2–4 from this objective — we provide 15 practice questions to prepare you well beyond it. (estimate)
15questions here
3free pages
4concepts
Questions 6–10
- 6
A security analyst notices a large number of HTTP requests to a login page, each with a different username and password combination. The requests originate from a small number of IP addresses and are spaced a few seconds apart. The application is protected by BIG-IP LTM. Which type of threat is this, and which F5 solution should be used to mitigate it?
Select an answer first - 7
An organization plans to deploy a WAF in front of its existing web servers. Which consideration is most important to ensure the WAF does not introduce unacceptable latency for legitimate users?
Select an answer first - 8
A large e-commerce company expects a significant increase in traffic during an upcoming sales event. The security team is concerned about a potential DDoS attack targeting the website. They need a mitigation strategy that can absorb large volumetric attacks without impacting the performance of legitimate transactions. The company currently uses BIG-IP LTM for load balancing and has a hybrid cloud infrastructure. Which approach should be recommended?
Select an answer first - 9
A security analyst observes a flood of UDP packets targeting a single server port, consuming all available network bandwidth. Which category of threat does this scenario best represent?
Select an answer first - 10
A financial services company is experiencing intermittent availability issues with its customer-facing web application. Analysis of traffic logs shows a high volume of SYN packets from a distributed set of IP addresses, with no corresponding ACK responses. The application remains responsive to legitimate users, but the load balancer is consuming significant CPU resources processing the incomplete connections. Which F5 solution should be used to mitigate this threat?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by F5. “401” is a trademark of its owner, used for identification only.