nerdexam
Exams101Questions#259
F5

101 · Question #259

101 Question #259: Real Exam Question with Answer & Explanation

The correct answer is C: Incoming requests with these IP addresses will automatically be accepted into the security. Trusted IPs in Policy Builder identify traffic sources whose requests are automatically accepted into the security policy, typically used for internal or QA traffic to accelerate accurate policy building.

Question

What is the purpose of the IP addresses listed in the Trusted IP section when using Policy Builder?

Options

  • AIncoming requests with these IP addresses will never get blocked by BIG-IP ASM.
  • BIncoming requests with these IP addresses will not be taken into account as part of the learning
  • CIncoming requests with these IP addresses will automatically be accepted into the security
  • DIncoming requests with these IP addresses will be used by Policy Builder to create an alternate

Explanation

Trusted IPs in Policy Builder identify traffic sources whose requests are automatically accepted into the security policy, typically used for internal or QA traffic to accelerate accurate policy building.

Common mistakes.

  • A. Trusted IPs influence Policy Builder's learning behavior, not enforcement - a request from a trusted IP can still be blocked if it violates an already-configured policy rule.
  • B. Trusted IP traffic is specifically included in learning, not excluded - the feature exists precisely so that this traffic is used as a trusted learning source.
  • D. Policy Builder builds a single unified security policy; trusted IPs do not trigger creation of an alternate or separate policy for that traffic.

Concept tested. BIG-IP ASM Policy Builder Trusted IP learning behavior

Reference. https://techdocs.f5.com/en-us/bigip-15-1-0/big-ip-asm-implementations/automatically-building-a-security-policy.html

Community Discussion

No community discussion yet for this question.

Full 101 Practice