Pass the F5 BIG-IP ASM 303 Questions and answers with CertsForce

Viewing page 7 out of 11 pages
Viewing questions 91-105 out of questions
Questions # 91:

An LTM Specialist has detected that a brute force login attack is occurring against the SSH service via a BIG-IP management interface. Login attempts are occurring from many IPs within the internal company network. BIG-IP SSH access restrictions are in place as follows:

Question # 91

The LTM Specialist has determined that SSH access should only occur from the 192.168.1.0/24 and 172.16.254.0/23 networks.

Whichtmsh command should the LTM Specialist use to permit access from the desired networks only?

Options:

A.

modify.sys sshd allow add {''192.168. 10/24 , '' ''172. 16 2540/23'')


B.

modify /sys sshd login disable (''10.0.00/8'', ''172 16.0 0/12'', ''192. 168.0.0/16'')


C.

modify/sys allow replace-all-with {''192.168.1.00/24'', ''192.16.254.0/23''}


D.

modify/sys sshd login enable {''192.166.10/24'''' ''172.16 254 0/23


Expert Solution
Questions # 92:

An LTM Specialist loads a UCS file generated on a different LTM device and receives the following error message:

"mcpd[2395]: 01070608:0: License is not operational (expired or digital signature does not match contents)"

Which command should the LTM Specialist use to prevent the error?

Options:

A.

tmsh show /sys license


B.

tmsh show /sys hardware


C.

bigpipe config save /config.ucs


D.

tmsh load /sys /ucs rma


E.

tmsh load /sys ucs no-license


Expert Solution
Questions # 93:

A new HITP server has been deployed on an LTM device. The application running on the server must be monitored by the LIM device. The following is required:

A new HITP server has been deployed on an LTM device. The application running on theserver must be monitored by the LIM device. The following is required:

When the server is unavailable, it will send an HTTP status code of 200 in response to a request for the status html page.

When the server is available. I will send and HTTP status code of 201 in response to a request for the status html page.

When the 200 status code is received, the pool member should receive No new connections.

Which configuration change should be made to meet these requirements?

Options:

A.

set the Send String to GET/status html and the Receive String to 200 and Receive Disable String to 201.


B.

set the Send String to GET Arian and the Receive String to 200 and Receive Disable String to 201.


C.

set the Send String to GET Arian and the Receive Disable String to 200 andReceive String to 201.


D.

set the Send String to Get /status html and the Receive Disable String to 200 and Receive String to 201.


Expert Solution
Questions # 94:

An LTM HTTP pool has an associated monitor that sends a string equal to 'GET /test.html'.

Which two configurations could an LTM Specialist implement to allow server administrators to disable their pool member servers without logging into the LTM device? (Choose two.)

Options:

A.

Set monitor to transparent and ask the server team to set string ‘TRANSPARENT’ in test.html.


B.

Set ‘receive string’ equal to 'SERVER UP and ask the server team to set string ‘SERVER DOWN’ in test.html.


C.

Set ‘alias’ equal to 'SERVER DOWN’ and ask the server team to set string ‘SERVER DOWN’ in test.html.


D.

Set ‘receive disable string’ equal to 'SERVER DOWN’ and ask the server team to set string ‘SERVER DOWN’ in test.html.


E.

Set ‘disable pool member’ equal to 'SERVER UP’ and ask the server team to set string ‘SERVER DOWN’ in test.html.


Expert Solution
Questions # 95:

Refer to the exhibit.

Question # 95

A BIG-IP Administrator needs to deploy an application on the BIG-IP system to perform SSL offload and

re-encrypt the traffic to pool members.

During testing, users are unable to connect to the application.

What must the BIG-IP Administrator do to resolve the issue?

Options:

A.

Remove the configured SSL Profile (Client)


B.

Configure Protocol Profile (Server) as splitsession-default-tcp


C.

Enable Forward Proxy in the SSL Profile (Client)


D.

Configure an SSL Profile (Server)


Expert Solution
Questions # 96:

A BIG-IP Administrator is configuring an SSH Pool with five members.

Which Health Monitor should be applied to ensure that available pool members are monitored

accordingly?

Options:

A.

https


B.

udp


C.

http


D.

tcp


Expert Solution
Questions # 97:

An LTM Specialist discovers an issue with the custom http monitor that returns in a false positive status.

The end users cannot get the right website, but thehttp monitor marks the pool member UP.

What is causing the false positive result?

Question # 97

Options:

A.

The end user should use another type of browser.


B.

The response is chunked.


C.

The response is compressed.


D.

The Content-Type has value "iso-8859-200".


Expert Solution
Questions # 98:

Some users who connect to a busy Virtual Server have connections reset by the BIG-IP system. Pool member resources are NOT a factor in this behavior. What is a possible cause for this behavior?

Options:

A.

The Connection Rate Limit is set too high


B.

The server SSL Profile has NOT been reconfigured.


C.

The Connection Limit is set too low.


D.

The Rewrite Profile has NOT been configured.


Expert Solution
Questions # 99:

An LTM device receives a response string containing "error"

Which monitor type and parameter will mark the HTTP server as down?

Options:

A.

HTTP monitor, Receive String "error", and set the Reverse option to Yes


B.

HTTP monitor and Receive String "error'' ... flag is up


C.

HTTP monitor. Receive String "down", and set the Reverse option to Yes .... flag is


D.

HTTP monitor and Receive DisableString "error'' .... flag is disable


Expert Solution
Questions # 100:

A BIG-IP Administrator receives an RMA replacement for a failed F5 device. The BIG-IP Administrator

tries to restore a UCS taken from the previous device, but the restore fails. The following error appears

inthe/var/log/itm.

mcpd [****J: •*****»;0; License is not operational (expired or digital signature does not match

contents.)

What should the BIG-IP Administrator do to avoid this error?

Options:

A.

Use the appropriate tmsh command with the no-license option


B.

Revoke the license prior to restoring


C.

Reactivate the license on the new device using the manual activation method


D.

Remove the license information from the UCS archive


Expert Solution
Questions # 101:

Which two items can be logged by the Application Visibility Reporting analytics profile? (Choose two.)

Options:

A.

User Agent


B.

HTTP version


C.

HTTP Response Codes


D.

Per Virtual Server CPU Utilization


Expert Solution
Questions # 102:

An LTM Specialist must reconfigure a BIG-IP system that load balances traffic to a web application. The security department has informed the LTM Specialist that the following cipher string must be used for TLS connections from BIG-IP to the web application.

NATIVE:IMDS:EXPORT:IDHE:EDH@SPEED

In which virtual server profile should the cipher string be configured?

Options:

A.

Server SSL

CB. Client SSL


B.

SPDY profile


C.

Rewrite profile


Expert Solution
Questions # 103:

in which Application Visibility and Reporting (AYR) profile must the SMTP profile be defined to configure notifications via email?

Options:

A.

App analytics profile


B.

virtual server profile


C.

customanalytics profile


D.

default analytics profile


Expert Solution
Questions # 104:

A BIG-IP Administrator needs to purchase new licenses for a BIG-IP appliance.

The administrator needs to know if a module is licensed and the memory requirement for that module.

Where should the administrator view this information in the System menu?

Options:

A.

Resource Provisioning


B.

Configuration > Device


C.

Software Management


D.

Configuration >OVSDB


Expert Solution
Questions # 105:

An HA pair of LTM devices configured in Active-Standby mode stops responding to traffic and causes an outage. The Active device becomes Standby, but the partner device stays in Standby mode instead of taking over as Active. A reboot and restart of the services brings the LTM device to Active mode for a short time, but then it goes into Standby mode again.

Which two configuration components caused this condition? (Choose two.)

Options:

A.

VLAN Fail-safe


B.

System Fail-safe


C.

Gateway Fail-safe


D.

Switch Board Failure


E.

Link down on Failover


Expert Solution
Viewing page 7 out of 11 pages
Viewing questions 91-105 out of questions