Exit demo F50-536 BIG-IP ASM v10.x PDF format · free preview

F5 F50-536 - Questions & Answers

Free preview · every answer includes a full explanation

Product page: https://prepkeys.com/f50-536.html

Question 1
Multiple choice

Which of the following are correct regarding Wildcard entities? (Choose 2)

A.

Wildcard entities are the basis for positive security logic.

B.

Wildcard entities are the basis for negative security logic.

C.

Wildcard entities require the need to learn only from violations.

D.

Wildcard entities can be applied to file types, URLs, cookies and parameters.

Question 2
Multiple choice

Flow login allows for more granular protection of login and logout URLs within web applications.

Which of the following are components of flow login? (Choose 3)

A.

Schema

B.

Login URLs

C.

Login pages

D.

Attack signatures

E.

Access validation

Question 3
Single choice

The BIG-IP ASM System is configured with a virtual server that contains an HTTP class profile and the protected pool members are associated within the HTTP class profile pool definition. The status of this virtual server is unknown (Blue).

Which of the following conditions will make this virtual server become available (Green)?

A.

Assign a successful monitor to the virtual server

B.

Assign a successful monitor to the members of the HTTP class profile pool

C.

Associate a fallback host to the virtual server and assign a successful monitor to the fallback host

D.

Associate a default pool to the virtual server and assign a successful monitor to the pool members

Question 4
Single choice

Which of the following does not pertain to protecting the Requested Resource (URI) element?

A.

File type validation

B.

URL name validation

C.

Domain cookie validation

D.

Attack signature validation

Question 5
Single choice

Which of the following protocol protections is not provided by the Protocol Security Manager?

A.

FTP

B.

SSH

C.

HTTP

D.

SMTP

Question 6
Single choice

Which of the following is correct regarding User-defined Attack signatures?

A.

User-defined signatures use an F5-supplied syntax

B.

User-defined signatures may only use regular expressions

C.

Attack signatures may be grouped within system-supplied signatures

D.

User-defined signatures may not be applied globally within the entire policy

Question 7
Single choice

Which of the following methods of protection is not available within the Protocol Security Manager for HTTP traffic?

A.

Data guard

B.

Attack signatures

C.

Evasion techniques

D.

File type enforcement

Question 8
Multiple choice

There are many user roles configurable on the BIG-IP ASM System.

Which of the following user roles have access to make changes to ASM policies? (Choose 3)

A.

Guest

B.

Operator

C.

Administrator

D.

Web Application Security Editor

E.

Web Application Security Administrator

Question 9
Single choice

In the following configuration, a virtual server has the following HTTP class configuration: HTTP Class 1 = Host pattern www.f5.com HTTP Class 2 = No filters A request arriving for WWW.F5.
COM will be matched by which class(es)?

A.

Class 1

B.

Class 2

C.

Both Class 1 and Class 2

D.

The request will be dropped

Question 10
Multiple choice

Learning suggestions in the Policy Building pages allow for which of the following? (Choose 2)

A.

XML-based parameters and associated schema are automatically learned.

B.

Blocking response pages can be automatically generated from web site content.

C.

Flow level parameters are displayed when found and can be accepted into the current policy.

D.

The administrator may modify whether the BIG-IP ASM System will learn, alarm, or block detected violations.

E.

Maximum acceptable values for length violations are calculated and can be accepted into the security policy by the administrator.

Showing 10 of 50 questions · Unlock the full set