
F5 Certified Administrator NGINX - Configuration:Demonstrate
Domain 4Objective 3
Describe How to Protect the SSL Certificate and Key F5N3 Practice Questions (Page 5)
Part of the Demonstrate how to configure certificates domain, which makes up ~22% of our current practice bank. F5 does not publish an official question count, but from its 30-minute exam (~10–20 total, ~2–4 in this domain), expect 1–1 from this objective — we provide 24 practice questions to prepare you well beyond it. (estimate)
24questions here
5free pages
5concepts
Questions 21–24
- 21
An administrator wants to protect an NGINX private key with a passphrase. The key is currently unencrypted. The administrator runs 'openssl rsa -aes256 -in server.key -out server_encrypted.key' and updates the NGINX configuration to use the new file. What additional step is required for NGINX to start successfully?
Select an answer first - 22
A company stores its NGINX SSL certificate and private key in /etc/nginx/ssl/. The security team requires that only the root user and the nginx worker process can read the private key. The nginx master process runs as root, and workers run as the 'nginx' user. Which command should you run to meet this requirement?
Select an answer first - 23
An administrator is configuring NGINX with an encrypted private key. The key is encrypted with a passphrase, and the administrator wants to avoid an interactive prompt at startup. The server is managed by a configuration management tool that runs NGINX as a service. What is the best way to provide the passphrase?
Select an answer first - 24
A company runs NGINX on a server where multiple applications share the same filesystem. The security team wants to ensure that SSL private keys are stored in a location that is not accessible to other applications. Which location and permission set is most appropriate?
Select an answer first
Finished these 4 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to F5N3
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by F5. “F5N3” is a trademark of its owner, used for identification only.