304 · Question #9
Which of the following is NOT a security feature provided by BIG-IP APM?
The correct answer is C. Distributed Denial of Service (DDoS) protection. DDoS protection (C) is not a native feature of BIG-IP APM - that capability belongs to BIG-IP AFM (Advanced Firewall Manager) or dedicated F5 DDoS mitigation solutions like Silverline. APM is purpose-built for identity-aware access control, not volumetric or protocol-level…
Question
Which of the following is NOT a security feature provided by BIG-IP APM?
Options
- AWeb Application Firewall (WAF)
- BSSL VPN
- CDistributed Denial of Service (DDoS) protection
- DIntrusion Detection System (IDS)
How the community answered
(67 responses)- A6% (4)
- B1% (1)
- C90% (60)
- D3% (2)
Explanation
DDoS protection (C) is not a native feature of BIG-IP APM - that capability belongs to BIG-IP AFM (Advanced Firewall Manager) or dedicated F5 DDoS mitigation solutions like Silverline. APM is purpose-built for identity-aware access control, not volumetric or protocol-level attack mitigation.
- A (WAF) is wrong because APM integrates web application security controls to inspect and filter HTTP traffic as part of access policy enforcement.
- B (SSL VPN) is wrong because SSL VPN is arguably APM's flagship feature - it provides secure remote client access through encrypted tunnels.
- D (IDS) is wrong because APM performs endpoint security inspection (checking device posture, antivirus status, OS version) before granting access, which functions as an intrusion-detection layer at the access tier.
Memory tip: Think of BIG-IP APM as the "gatekeeper" - it authenticates, inspects endpoints, and tunnels users in (WAF, IDS, SSL VPN). DDoS defense is a "floodgate" job, handled upstream by AFM. If the threat is about who gets in, APM handles it; if it's about overwhelming the network, that's AFM's domain.
Topics
Community Discussion
No community discussion yet for this question.