101 · Question #343
Requests that do not meet the ASM security policies can:
The correct answer is C. All of the above. F5 ASM (Application Security Manager) provides multiple response options for policy violations, including blocking, logging, and generating learning suggestions - all simultaneously configurable.
Question
Requests that do not meet the ASM security policies can:
Options
- AGenerate learning suggestions
- BBe blocked
- CAll of the above
- DBe logged
How the community answered
(28 responses)- A7% (2)
- B4% (1)
- C89% (25)
Why each option
F5 ASM (Application Security Manager) provides multiple response options for policy violations, including blocking, logging, and generating learning suggestions - all simultaneously configurable.
While generating learning suggestions is a valid ASM capability, selecting only this option ignores blocking and logging, which are equally valid and important policy enforcement actions.
Blocking is a valid ASM response, but selecting it alone excludes logging and learning suggestions, which are also documented ASM behaviors for non-compliant requests.
ASM enforces security policies by evaluating incoming requests against defined rules, and it supports all three responses: requests can be blocked to prevent malicious traffic, logged for audit and forensic purposes, and flagged to generate learning suggestions that help refine the policy over time. These options are not mutually exclusive and can be applied together.
Logging is a valid ASM response, but selecting it alone excludes blocking and learning suggestions, making it an incomplete answer.
Concept tested: F5 ASM policy enforcement response options
Source: https://techdocs.f5.com/en-us/bigip-15-1-0/big-ip-asm-implementations.html
Topics
Community Discussion
No community discussion yet for this question.