nerdexam
F5

101 · Question #174

Which of the following statements are correct regarding Attack signatures? (Choose 2)

The correct answer is A. Attack signatures can apply to requests, responses, and parameters. D. Individual Attack signatures can be assigned to the security policy. BIG-IP ASM attack signatures operate as negative security controls that can inspect requests, responses, and parameters, and can be individually toggled per security policy.

Section 4: Security Basics

Question

Which of the following statements are correct regarding Attack signatures? (Choose 2)

Options

  • AAttack signatures can apply to requests, responses, and parameters.
  • BAttack signatures are the basis for positive security logic with the BIG-IP ASM System.
  • CAny new Attack signature downloaded manually or automatically will be active and assigned
  • DIndividual Attack signatures can be assigned to the security policy.

How the community answered

(26 responses)
  • A
    88% (23)
  • B
    4% (1)
  • C
    8% (2)

Why each option

BIG-IP ASM attack signatures operate as negative security controls that can inspect requests, responses, and parameters, and can be individually toggled per security policy.

AAttack signatures can apply to requests, responses, and parameters.Correct

Attack signatures can be scoped to apply to HTTP request headers, HTTP response content, and individual parameter values, giving administrators precise control over where pattern matching occurs.

BAttack signatures are the basis for positive security logic with the BIG-IP ASM System.

Attack signatures underpin negative security logic, which blocks known bad patterns. Positive security logic - defining explicitly allowed input - is a separate model built from URL and parameter whitelists, not signatures.

CAny new Attack signature downloaded manually or automatically will be active and assigned

Newly downloaded attack signatures are placed in staging mode by default and are not immediately active or assigned - they require manual review and enablement before they are enforced.

DIndividual Attack signatures can be assigned to the security policy.Correct

Individual attack signatures can be enabled or disabled within a specific security policy, allowing per-policy customization of which threat patterns are enforced without affecting other policies.

Concept tested: BIG-IP ASM attack signature scope and assignment behavior

Source: https://techdocs.f5.com/en-us/bigip-15-1-0/big-ip-asm-implementations/working-with-attack-signatures.html

Topics

#attack signatures#positive security#signature assignment#request response

Community Discussion

No community discussion yet for this question.

Full 101 Practice