Free 401 sample questions

Real questions from the Security Solutions (401 - Security Solution Expert) practice bank, with the correct answer and an explanation for each one. No junk, no filler.

Try them in the simulator Same questions, with study, timed and flashcard modes.

Showing 6 of 12 free sample questions.

Question 1Choose one

A security analyst is reviewing external threat intelligence feeds provided by F5 Labs. The research indicates a massive, ongoing campaign utilizing a newly discovered remote code execution (RCE) vulnerability in a popular open-source web framework. The organization relies heavily on this framework for its primary customer portal, but cannot apply the vendor patch for another 30 days due to change freeze constraints. Based on the threat research, what is the MOST immediate potential impact to the organization, and which action should be prioritized?

Question 2Choose one

During a threat modeling exercise using the STRIDE methodology, an architect identifies that a legacy, monolithic application is highly susceptible to tampering and information disclosure. The application processes sensitive financial payloads but lacks robust input validation. However, the network architecture is well-segmented and the risk of infrastructure-level denial of service is determined to be negligible. Which risk profile correctly categorizes this environment, and what is the optimal F5 mitigation strategy?

Question 3Choose 2

A multinational corporation has received intelligence reports indicating that nation-state actors from specific geographic regions are actively scanning their public IP blocks for vulnerable management interfaces. Which TWO F5 features should the security architect recommend to best analyze and block this specific external threat before it reaches the application layer? (Select TWO)

Question 4Choose one

True or False: When analyzing threat modeling data to determine risk profiles, an organization with a heavily containerized microservices architecture entirely hosted in a public cloud has eliminated the need for Layer 3/Layer 4 network threat profiling, as the cloud provider inherently mitigates all infrastructure risks.

Question 5Choose one

HealthCorp is deploying a new telemedicine portal that allows patients to view medical records and conduct video consultations. The application architecture involves a frontend web server communicating with a highly sensitive backend database. During the design phase, the Chief Information Security Officer (Cisco) mandates that the solution must protect against OWASP Top 10 web vulnerabilities, enforce multi-factor authentication before any application resources are accessed, and drop malicious traffic from known botnets at the network edge to preserve bandwidth. The existing infrastructure consists of a BIG-IP LTM handling SSL termination and load balancing. The budget allows for additional F5 module licensing. Which layered F5 architecture optimally satisfies all of HealthCorp's requirements without introducing unnecessary processing overhead? graph TD Internet((Internet)) --> Edge[Edge Protection] Edge --> Auth[Authentication Layer] Auth --> AppSec[Application Security] AppSec --> Backend[Backend Servers]

Question 6Choose one

An e-commerce company is undergoing an annual Payment Card Industry Data Security Standard (PCI-DSS) audit. The auditor notes that while the web application encrypts traffic in transit, there is no explicit control in place to prevent the leakage of Primary Account Numbers (PAN) in server responses if the backend database is compromised. Which BIG-IP control should the architect determine is correct to address this specific compliance requirement?

6 more free samples are waiting

Create a free account to unlock the whole 401 sample bank, or get full access to all 150 practice questions in the simulator.

Create account