
F5 Certified Administrator NGINX - Configuration:Demonstrate
Domain 4Objective 3
Describe How to Protect the SSL Certificate and Key F5N3 Practice Questions (Page 3)
Part of the Demonstrate how to configure certificates domain, which makes up ~22% of our current practice bank. F5 does not publish an official question count, but from its 30-minute exam (~10–20 total, ~2–4 in this domain), expect 1–1 from this objective — we provide 24 practice questions to prepare you well beyond it. (estimate)
24questions here
5free pages
5concepts
Questions 11–15
- 11
A company is decommissioning a server that hosted NGINX with SSL. The security policy requires that the private key be securely destroyed. Which method is most appropriate?
Select an answer first - 12
What is the purpose of key rotation in SSL/TLS management?
Select an answer first - 13
A company requires that SSL private keys be backed up securely, but the backup team uses a shared storage system that is accessible to multiple departments. The security policy states that private keys must not be exposed to unauthorized personnel. Which backup strategy best meets the requirement?
Select an answer first - 14
Which file permissions are recommended for an SSL private key file on a Linux system?
Select an answer first - 15
A company's security team requires that SSL private keys be encrypted with a passphrase and that the passphrase be stored in a hardware security module (HSM). The NGINX server must use the key without exposing the passphrase in a file. What is the best approach?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by F5. “F5N3” is a trademark of its owner, used for identification only.