nerdexam
F5

101 · Question #408

Which item is NOT a function of a properly deployed and configured ASM?

The correct answer is B. Stops hackers from attacking. ASM mitigates the impact of attacks by blocking malicious traffic, but it cannot stop threat actors from attempting to attack a system in the first place.

Section 2: F5 Solutions and Technology

Question

Which item is NOT a function of a properly deployed and configured ASM?

Options

  • ADetects attacks
  • BStops hackers from attacking
  • CProvides protection visibility
  • DProvides security agility

How the community answered

(38 responses)
  • A
    5% (2)
  • B
    87% (33)
  • C
    3% (1)
  • D
    5% (2)

Why each option

ASM mitigates the impact of attacks by blocking malicious traffic, but it cannot stop threat actors from attempting to attack a system in the first place.

ADetects attacks

Detecting attacks through signature matching and behavioral anomaly analysis is a primary and well-documented ASM function.

BStops hackers from attackingCorrect

A WAF like ASM operates on traffic that has already reached the application tier; it has no mechanism to prevent a hacker from initiating an attack attempt from the internet. ASM can detect, block, and log malicious requests, but the act of attempting an attack originates outside its control plane. The correct framing is that ASM protects applications from successful exploitation, not from being targeted.

CProvides protection visibility

Providing protection visibility via dashboards, logs, and security reports is a core ASM capability that lets administrators monitor threats.

DProvides security agility

Security agility - the ability to rapidly update policies, signatures, and rules - is a key benefit of a software-based WAF like ASM.

Concept tested: ASM WAF capabilities and inherent limitations

Source: https://techdocs.f5.com/en-us/bigip-15-1-0/big-ip-asm-getting-started-guide/big-ip-application-security-manager-overview.html

Topics

#ASM#web application firewall#security functions

Community Discussion

No community discussion yet for this question.

Full 101 Practice