101 · Question #174
Which of the following statements are correct regarding Attack signatures? (Choose 2)
The correct answer is A. Attack signatures can apply to requests, responses, and parameters. D. Individual Attack signatures can be assigned to the security policy. BIG-IP ASM attack signatures operate as negative security controls that can inspect requests, responses, and parameters, and can be individually toggled per security policy.
Question
Which of the following statements are correct regarding Attack signatures? (Choose 2)
Options
- AAttack signatures can apply to requests, responses, and parameters.
- BAttack signatures are the basis for positive security logic with the BIG-IP ASM System.
- CAny new Attack signature downloaded manually or automatically will be active and assigned
- DIndividual Attack signatures can be assigned to the security policy.
How the community answered
(26 responses)- A88% (23)
- B4% (1)
- C8% (2)
Why each option
BIG-IP ASM attack signatures operate as negative security controls that can inspect requests, responses, and parameters, and can be individually toggled per security policy.
Attack signatures can be scoped to apply to HTTP request headers, HTTP response content, and individual parameter values, giving administrators precise control over where pattern matching occurs.
Attack signatures underpin negative security logic, which blocks known bad patterns. Positive security logic - defining explicitly allowed input - is a separate model built from URL and parameter whitelists, not signatures.
Newly downloaded attack signatures are placed in staging mode by default and are not immediately active or assigned - they require manual review and enablement before they are enforced.
Individual attack signatures can be enabled or disabled within a specific security policy, allowing per-policy customization of which threat patterns are enforced without affecting other policies.
Concept tested: BIG-IP ASM attack signature scope and assignment behavior
Source: https://techdocs.f5.com/en-us/bigip-15-1-0/big-ip-asm-implementations/working-with-attack-signatures.html
Topics
Community Discussion
No community discussion yet for this question.