Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
F5 logo

F5Certified Solution Expert, Security

Domain 2Objective 1

2.01 Determine the Correct Solution to Mitigate a Given Threat 401 Practice Questions (Page 3)

Part of the ARCHITECT SOLUTIONS domain, which makes up ~28% of our current practice bank. F5 does not publish an official question count, but from its 105-minute exam (~40–70 total, ~11–20 in this domain), expect 2–4 from this objective — we provide 15 practice questions to prepare you well beyond it. (estimate)

15questions here
3free pages
4concepts

Questions 11–15

  1. 11foundation · easy

    An attacker sends a crafted HTTP request that exploits a vulnerability in a web application's input validation to execute arbitrary commands on the server. How should this threat be categorized?

    Select an answer first
  2. 12foundation · easy

    A team has configured a network firewall to block certain IP addresses. What is the primary purpose of running a simulation with known attack patterns before going live?

    Select an answer first
  3. 13application · medium

    A company is deploying a new BIG-IP ASM solution to protect a critical application. The security team wants to ensure that the WAF does not introduce latency that would violate the application's performance SLA. They plan to test the solution in a staging environment. Which testing approach should be used to validate performance?

    Select an answer first
  4. 14application · medium

    A healthcare organization is deploying a new patient portal that will handle sensitive personal health information. The security team requires protection against SQL injection and cross-site scripting attacks, while also needing to ensure that the application remains available during a targeted DDoS attack. The portal is fronted by BIG-IP LTM for load balancing. Which combination of F5 solutions should be implemented?

    Select an answer first
  5. 15application · medium

    A security administrator has configured BIG-IP ASM to protect a web application from SQL injection attacks. Before deploying the configuration to production, the administrator wants to validate that the WAF policy does not block legitimate user traffic. Which testing method should be used?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to 401

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by F5. “401” is a trademark of its owner, used for identification only.