Pass the F5 BIG-IP ASM 303 Questions and answers with CertsForce

Viewing page 2 out of 11 pages
Viewing questions 16-30 out of questions
Questions # 16:

An LTM Specialist has noticed in the audit log that there are numerous attempts to loginto the Admin account. Theses attempts are sourced from a suspicious IP address range to the Configuration Utility of the LTM device.

How should the LTM Specialist block these attempts?

Options:

A.

add the permitted source IP addresses to the httpd allow list viatmsh


B.

add the suspicious source IP addresses to the httpd deny list via tmsh


C.

add the suspicious source IP addresses to the httpd deny list via Configuration Utility


D.

add the permitted source IP addresses to the allow list viaConfiguration Utility


Expert Solution
Questions # 17:

Refer to the exhibit

The network team creates a new VLAN on the switches. The BIG-IP Administrator needs to create a

configuration on the BIG-IP device. The BIG-IP Administrator creates a new VLAN and Self IP, but the

servers on the new VLAN are NOT reachable from the BIG-IP device.

Which action should the BIG-IP Administrators to resolve this issue?

Options:

A.

Set Port Lockdown of Set IP to Allow All


B.

Change Auto Last Hop to enabled


C.

Assign a physical interface to the new VLAN


D.

Create a Floating Set IP Address


Expert Solution
Questions # 18:

An IT support engineer needs to access and modify Virtual Servers in three partitions (Common /Banking and Dev) daily on a BIG-IP device. The company operates a Least Privilege access policy. What level of access does the IT support engineer need to ensure completion of daily roles?

Options:

A.

Manager in /common/Banking, and /Dev partitions


B.

Application Editor in /Common, /Banking, and /Dev partitions


C.

Manager in all partitions


D.

Application Editor in all partitions


Expert Solution
Questions # 19:

What do the following iRule commands do when they are used in the same iRule?

set hsl [HSL::open -proto UDP -pool syslog_server_pool]

HSL::send $hsl "<190> [HTTP::host] from [whereis [IP::client_addr] country continent state city zip] , IP: [IP::client_addr]"

Options:

A.

The commands set up a high-speed logging connection and then send the geographical database to the server.


B.

The commands set up a high-speed logging connection and then send the host header and client geographical detail to the connection.


C.

The commands set up a high-speed logging connection and then send the host header, HTTP payload, and client geographical detail to the connection.


D.

The commands set up a high-speed logging connection to the LTM device and then send the host header and client geographical detail to the connection.


Expert Solution
Questions # 20:

A BIG-IP Administrator needs to make sure that the automatic update check feature works properly.

What must the administrator configure on the BIG-IP system?

Options:

A.

Update Check Schedule


B.

NTP servers


C.

DNS name servers


D.

SMTP servers


Expert Solution
Questions # 21:

An LTM Specialist is troubleshooting a problem on an eCommerce website. The user browses the online store using port 80, adding items to the shopping cart. The user then clicks the "Checkout" button on the site, which redirects the user to port 443 for the checkout process. Suddenly, the user's shopping cart is shown as empty. The shopping cart data is stored in memory on the server, and the default source address persistence profile is used on both virtual servers.

What is the issue?

Options:

A.

The port 80 pool member is deleting the user's session cookie.


B.

The port 443 pool member is deleting the user's session cookie.


C.

The port 80 and port 443 connections are balanced to the same node.


D.

The port 80 and port 443 connections are balanced to different nodes.


Expert Solution
Questions # 22:

Exhibit.

Question # 22

- The ITM devices LTM 1 and LTM2 are configured in Device Group X (Sync-Failover)

- LTM3 and LTM4 are configured in Device Group Y (Sync-Only)

- An LTM specialist configures Device Group Z (Sync-Only) to keep several profiles in (sync-Only) to keep several profiles in sync across all devices.

- Device GROUP X has four Traffic Groups A.B.C and D configured.

- Device Group Y has four Traffic Groups E, F. G, and H configured

- Auto Fallback IS NOT Enabled.

- Each Device group is healthy and able to pass traffic for any traffic groupassigned to that Device

Group.

The data center that contains LTM2 and LTM4 loses power. After 10 minutes; power is restored and all devices are up and healthy.

What is the state of each Traffic Group on each ITM device after power is restored?

A)

Question # 22

B)

Question # 22

C)

Question # 22

D)

Question # 22

Options:

A.

Option A


B.

Option B


C.

Option C


D.

Option D


Expert Solution
Questions # 23:

Which file should be modified to create custom SNMP alerts?

Options:

A.

/config/alert.conf


B.

/etc/alertd/alert.conf


C.

/config/user_alert.conf


D.

/etc/alertd/user_alert.conf


Expert Solution
Questions # 24:

An LTM Specialist is troubleshooting an issue with a new virtual server. When connecting through the virtual server, clients receive the message "Unable to connect" in the browser, although connections directly to the pool member show the application is functioning correctly. The LTM configuration is:

ltm virtual /Common/vs_https {

destination /Common/10.10.1.110:443

ip-protocol udp

mask 255.255.255.255

pool /Common/pool_https

profiles {

/Common/udp { }

}

translate-address enabled

translate-port enabled

vlans-disabled

}

ltm pool /Common/pool_https {

members {

/Common/172.16.20.1:443 {

address 172.16.20.1

}

}

}

How should the LTM Specialist resolve this issue?

Options:

A.

Remove an HTTP monitor from the pool.


B.

Add an HTTP profile to the virtual server.


C.

Enable the pool member on the correct VLAN.


D.

Select the correct protocol for the virtual server.


Expert Solution
Questions # 25:

A BIG-IP Administrator has configured a BIG-IP cluster with remote user authentication against dcOl

f5trn.com. Only local users can successfully log into the system. Configsync is also failing.

Which two tools should the 8IG-IP Administrator use to further investigate these issues? (Choose two)

Options:

A.

ntpq


B.

pam_timestamp_check


C.

passwd


D.

pwck


E.

dig


Expert Solution
Questions # 26:

Which Standard Virtual Server settings should an LTM Specialist use toload balance across routed path of two different ISPs?

Options:

A.

address translation enabled and port translation disabled


B.

both address and port translation enabled


C.

both address and port translation disabled


D.

address translation disabled and port translation enabled


Expert Solution
Questions # 27:

-- Exhibit –

Question # 27

-- Exhibit --

Refer to the exhibit.

A company uses a complex piece of client software that connects to one or more virtual servers (VS) hosted on an LTM device. The client software is experiencing issues. An LTM Specialist is tasked with finding the cause of the problem.

The LTM Specialist has the tcpdump extract and knows the client software has at least one connection to a VS on port 1990. However, when a tcpdump runs on the internal VLAN, there is no record of port 1990 in the tcpdump.

Why is there no record of port 1990 in the tcpdump?

Options:

A.

The LTM device drops the connection.


B.

Port 1990 is a well-known port, so its use is restricted.


C.

The LTM device performs a Port Address Translation (PAT).


D.

The LTM device performs a Network Address Translation (NAT).


Expert Solution
Questions # 28:

The BIG-IP Administrator configures an HTTP monitor with a specific receive string. The status is marked

'down'.

Which tool should the administrator use to identify the problem?

Options:

A.

Ping


B.

Health


C.

tcpdump


D.

ifconfig


Expert Solution
Questions # 29:

A BIG-IP Administrator applied the latest hotfix to an inactive boot location by mistake, and needs to downgrade back to the previous hotfix.

What should the BIG-IP Administrator do to change the boot location to the previous hotfix?

Options:

A.

Uninstall the newest hotfix and reinstall the previous hotfix


B.

Reinstall the base version and install the previous hotfix


C.

Reinstall the previous hotfix and re-activate the license


D.

Uninstall the base version and restore the UCS


Expert Solution
Questions # 30:

Refer to the exhibit.

Question # 30

The http monitor is applied to a pool All members are enabled One pool member stops responding TCP port 80. The server still responds to ping.

What is the resulting status ofthis pool member?

Options:

A.

Available (Enabled)


B.

Offline (Disabled)


C.

Unavailable (Disabled)


D.

Unknown (Enabled)


Expert Solution
Viewing page 2 out of 11 pages
Viewing questions 16-30 out of questions