401 Exam Questions
157 real 401 exam questions with expert-verified answers and explanations. Page 3 of 4.
- Question #101Section 5: Network and Application Security Architecture
Which component is typically used to implement outbound SSL visibility?
SSL decryptionSSL visibilitytraffic inspectionoutbound security - Question #102Section 5: Network and Application Security Architecture
In troubleshooting F5 technology, what is a common step when dealing with performance issues?
F5 BIG-IPperformance troubleshootingbandwidth optimizationnetwork performance - Question #103Section 3: Attack Vectors and Mitigation
Which F5 feature can be used to protect against SYN flood attacks?
SYN floodDoS protectionrate limitingF5 AFM - Question #104Section 6: Threat Management and Incident Response
Scenario: Your organization has detected a ransomware attack. The response team is unsure of the best course of action. What should they prioritize?
ransomwareincident responsecontainmentisolation - Question #105Section 3: Attack Vectors and Mitigation
When configuring F5 technology to provide network layer DoS protection, which setting should be adjusted first?
DoS protectionrate limitingF5 configurationnetwork layer - Question #106Section 3: Attack Vectors and Mitigation
Which F5 feature protects against credential-stuffing attacks by analyzing login behavior?
credential stuffingBot Defenselogin protectionF5 - Question #107Section 5: Network and Application Security Architecture
What is the primary purpose of SSL Orchestrator?
SSL OrchestratorSSL inspectiontraffic decryptionre-encryption - Question #108Section 5: Network and Application Security Architecture
Which BIG-IP module provides stateful network firewall capabilities?
AFMBIG-IP modulesstateful firewallnetwork firewall - Question #109Section 3: Attack Vectors and Mitigation
What type of attack does iRules help mitigate most effectively?
iRulesapplication-layer attacksF5traffic manipulation - Question #110Section 6: Threat Management and Incident Response
Which security solution integrates threat intelligence feeds to block known malicious IPs?
IP Intelligencethreat intelligence feedsmalicious IPsF5 - Question #111Section 2: Security Policy and Compliance
Scenario: Your organization needs to implement a solution to address a new GDPR compliance requirement. The proposed solution must integrate with existing systems and ensure data p...
GDPRcompliance integrationdata protectionregulatory requirements - Question #112Section 6: Threat Management and Incident Response
What factors should be considered when analyzing the risk profiles of infrastructure and applications? (Choose two.)
risk analysissystem vulnerabilitiesattacker motivationrisk assessment - Question #113Section 5: Network and Application Security Architecture
In what scenario is BIG-IQ typically required for centralized management and visibility?
BIG-IQcentralized managementmulti-site deploymentF5 - Question #114Section 2: Security Policy and Compliance
When proposing a new security control for a company, what should be included in the justification? (Select all that apply)
security controlsbusiness justificationcost-benefit analysisbusiness impact - Question #115Section 6: Threat Management and Incident Response
When determining the correct solution to mitigate a known threat, what should be prioritized?
threat mitigationsolution effectivenesssecurity controlsrisk management - Question #116Section 6: Threat Management and Incident Response
When analyzing external threat research, what is the significance of monitoring security blogs and forums?
threat intelligencesecurity blogsexternal researchOSINT - Question #117Section 2: Security Policy and Compliance
When addressing compliance requirements related to credit card data, which control is essential for PCI DSS (Payment Card Industry Data Security Standard) compliance?
PCI DSSdata encryptioncredit card securitycompliance - Question #118Section 6: Threat Management and Incident Response
In the event of a malware outbreak affecting multiple endpoints in an organization, what should be one of the first steps in the incident response plan?
malware outbreakincident responsenetwork containmentendpoint isolation - Question #119Section 6: Threat Management and Incident Response
Threat modeling data helps in:
threat modelingrisk prioritizationsecurity riskthreat assessment - Question #120Section 5: Network and Application Security Architecture
Scenario: A network performance issue has been identified after the deployment of F5 technology. The issue seems to be related to traffic congestion during peak hours. What steps s...
network performancetraffic analysiscongestion troubleshootingF5 - Question #121Section 6: Threat Management and Incident Response
When responding to a ransomware attack, what should be a priority in the incident response plan?
ransomwareincident responsesystem isolationcontainment - Question #122Section 4: Authentication and Authorization
How can you mitigate web fraud when configuring web application security settings?
MFAweb fraudweb application securityauthentication - Question #123Section 6: Threat Management and Incident Response
When responding to an incident, what is the importance of documenting the incident and lessons learned?
incident documentationlessons learnedpost-incident reviewincident response - Question #124Section 6: Threat Management and Incident Response
Which sources of threat data are most likely to provide actionable insights for enhancing an organization's security posture? (Choose two.)
threat intelligence feedsthreat datasecurity postureintelligence sources - Question #125Section 5: Network and Application Security Architecture
In F5 ASM, what does learning mode do?
F5 ASMlearning modeWAF policytraffic baseline - Question #126Section 5: Network and Application Security Architecture
Which protocol is most commonly targeted by SSL Orchestrator for inspection?
SSL OrchestratorHTTPSSSL inspectionprotocol targeting - Question #127Section 3: Attack Vectors and Mitigation
What type of attack is cross-site scripting (XSS)?
XSScross-site scriptingapplication-layer attackweb vulnerabilities - Question #128Section 4: Authentication and Authorization
Which F5 solution provides context-aware access control based on user identity, device posture, and location?
F5 APMcontext-aware accessdevice postureidentity-based access - Question #129Section 6: Threat Management and Incident Response
What is the primary benefit of integrating BIG-IP security modules with external SIEM tools?
SIEM integrationcentralized loggingBIG-IPthreat visibility - Question #130Section 3: Attack Vectors and Mitigation
What is a common method to configure F5 technology for network layer DOS (Denial of Service) protection?
DoS protectionACLnetwork layerF5 AFM - Question #131Section 5: Network and Application Security Architecture
Scenario: You have configured F5 technology to provide outbound SSL visibility. However, during routine monitoring, it was found that not all traffic is being decrypted and inspect...
SSL decryptionoutbound SSL visibilitytraffic inspectionSSL Orchestrator - Question #132Section 6: Threat Management and Incident Response
Which factor should be considered when creating an incident response plan for ransomware attacks?
ransomware responsesystem isolationincident response planningcontainment - Question #133Section 7: Security Best Practices
Scenario: During a security incident, the team identifies a potential vulnerability that could have been exploited. However, there is no evidence that it was used during the breach...
vulnerability managementpatch prioritizationincident responsesecurity hardening - Question #134Section 7: Security Best Practices
What is the primary purpose of troubleshooting F5 technology?
F5 troubleshootingperformance issuesfunctionalitynetwork management - Question #135Section 5: Network and Application Security Architecture
Which scenario would necessitate the use of BIG-IQ for centralized management and visibility in an organization?
BIG-IQcentralized managementmulti-datacenterenterprise security - Question #136Section 6: Threat Management and Incident Response
Which logs are most relevant for investigating a suspected data breach? (Choose two.)
forensic investigationaccess logsnetwork traffic logsdata breach - Question #137Section 5: Network and Application Security Architecture
What is the primary purpose of BIG-IQ in a network security infrastructure?
BIG-IQcentralized managementnetwork visibilityF5 platform - Question #138Section 7: Security Best Practices
Scenario: An organization has recently adopted a new financial application. During a threat analysis, it was discovered that similar applications have been targeted by cybercrimina...
vulnerability managementthreat analysispatch prioritizationapplication security - Question #139Section 6: Threat Management and Incident Response
Scenario: Following a DDoS attack, your organization's website experienced significant downtime. The incident response plan was found to be inadequate in addressing such a large- s...
DDoS mitigationincident response planningtraffic reroutingbusiness continuity - Question #140Section 5: Network and Application Security Architecture
What is the primary purpose of centralized management in BIG-IQ?
BIG-IQcentralized managementdevice visibilitysecurity management - Question #141Section 6: Threat Management and Incident Response
Which security measure helps identify and block malicious IP addresses in real-time?
threat intelligence feedsmalicious IP blockingIDS vs IPSreal-time threat detection - Question #142Section 2: Security Policy and Compliance
To address compliance with GDPR (General Data Protection Regulation), which control is essential for protecting user data privacy?
GDPRencryption in transitdata privacycompliance controls - Question #143Section 3: Attack Vectors and Mitigation
To protect against insider threats, what solution can be employed within an organization? (Select all that apply)
insider threatsNIDSemployee background checksthreat mitigation - Question #144Section 6: Threat Management and Incident Response
Which factors should be considered when developing an incident response plan for DDoS attacks? (Choose two.)
DDoSincident response planningcritical servicesbandwidth allocation - Question #145Section 6: Threat Management and Incident Response
Scenario: Your organization is undergoing a threat analysis to evaluate the potential impact of a recently discovered vulnerability in its primary web application. The application...
vulnerability assessmentexploitability analysisrisk prioritizationthreat analysis - Question #146Section 5: Network and Application Security Architecture
How can you protect against known bad actors in a network?
access controlsnetwork protectionbad actorsperimeter defense - Question #147Section 5: Network and Application Security Architecture
What is a recommended step when configuring F5 technology for DOS protection against ICMP flood attacks?
ICMP floodrate limitingDoS protectionF5 technology - Question #148Section 2: Security Policy and Compliance
Which factor is least important when proposing a new security control to meet business requirements?
security controlsbusiness alignmentcost-benefit analysissecurity governance - Question #149Section 1: Cryptography and PKI
How can encryption be used to mitigate data exfiltration threats? (Select all that apply)
data exfiltrationencryption at restencryption in transitdata protection - Question #150Section 2: Security Policy and Compliance
Which security framework is most appropriate for ensuring the protection of sensitive customer data in a global e-commerce platform?
PCI DSScompliance frameworkse-commerce securitycustomer data protection