401 Sample Questions

401 Sample Questions & Answers

Configuring network-layer DoS protection and web-fraud mitigation takes the largest slice, next to sizing up external threats and risk profiles, then building controls for compliance and threat mitigation, and planning a proactive incident response.

Launch the full 401 simulator →

Showing 6 of 12 free samples.

  1. Question 1Beginner

    THREAT ANALYSIS · Analyze threat modeling data to determine risk profiles of the infrastructure and applications

    True or False: When analyzing threat modeling data to determine risk profiles, an organization with a heavily containerized microservices architecture entirely hosted in a public cloud has eliminated the need for Layer 3/Layer 4 network threat profiling, as the cloud provider inherently mitigates all infrastructure risks.

    Show answer & explanation

    Correct answer: B

    False. While cloud providers offer baseline infrastructure protection, the shared responsibility model dictates that customers are still responsible for configuring proper network security controls (such as security groups, VNET isolation, and L3/L4 DoS thresholds) for their specific workloads. Threat modeling must still include infrastructure risk profiling regardless of the hosting environment.

  2. Question 2Advanced

    ARCHITECT SOLUTIONS · Determine the correct solution to mitigate a given threat

    HealthCorp is deploying a new telemedicine portal that allows patients to view medical records and conduct video consultations. The application architecture involves a frontend web server communicating with a highly sensitive backend database. During the design phase, the Chief Information Security Officer (Cisco) mandates that the solution must protect against OWASP Top 10 web vulnerabilities, enforce multi-factor authentication before any application resources are accessed, and drop malicious traffic from known botnets at the network edge to preserve bandwidth.

    The existing infrastructure consists of a BIG-IP LTM handling SSL termination and load balancing. The budget allows for additional F5 module licensing.

    Which layered F5 architecture optimally satisfies all of HealthCorp's requirements without introducing unnecessary processing overhead?

    graph TD Internet((Internet)) --> Edge[Edge Protection] Edge --> Auth[Authentication Layer] Auth --> AppSec[Application Security] AppSec --> Backend[Backend Servers]
    Show answer & explanation

    Correct answer: C

    This architecture perfectly aligns with the layered defense requirements. BIG-IP AFM with IP Intelligence drops known botnet traffic at the network edge (saving bandwidth and processing power). BIG-IP APM handles the pre-authentication and MFA requirement before traffic reaches the application. Finally, BIG-IP ASM provides the necessary Layer 7 protection against OWASP Top 10 threats for authenticated traffic.

  3. Question 3Intermediate

    ARCHITECT SOLUTIONS · Determine the correct control to address a compliance or business requirement

    An e-commerce company is undergoing an annual Payment Card Industry Data Security Standard (PCI-DSS) audit. The auditor notes that while the web application encrypts traffic in transit, there is no explicit control in place to prevent the leakage of Primary Account Numbers (PAN) in server responses if the backend database is compromised. Which BIG-IP control should the architect determine is correct to address this specific compliance requirement?

    Show answer & explanation

    Correct answer: D

    BIG-IP ASM's Data Guard feature is specifically designed to prevent sensitive information leakage (such as credit card numbers or social security numbers) in HTTP responses. It can be configured to either mask the sensitive data or block the response entirely, directly addressing the PCI-DSS requirement to prevent PAN leakage.

  4. Question 4Beginner

    ARCHITECT SOLUTIONS · Determine when BIG-IQ is required for centralized management and visibility

    A financial institution is expanding its infrastructure from 4 standalone BIG-IP appliances to a fleet of 45 BIG-IP instances spread across on-premises data centers and two public cloud providers. The security operations team is struggling to maintain consistent WAF policies and track the licensing status across the hybrid environment. What is the primary justification for introducing BIG-IQ into this proposed architecture?

    Show answer & explanation

    Correct answer: D

    As the number of BIG-IP instances grows, managing them individually becomes inefficient and error-prone. BIG-IQ Centralized Management is specifically designed to solve this by providing a single pane of glass for managing policies (like ASM WAF policies), visibility, and licensing across dozens or hundreds of BIG-IP devices in hybrid environments.

  5. Question 5Intermediate

    ARCHITECT SOLUTIONS · Determine the appropriate security framework for an application

    A security architect is designing a WAF policy for a highly dynamic, third-party content management system (CMS) where the application paths, parameters, and file types change daily without notification from the developers. The business requirement dictates that the WAF must be deployed in blocking mode within 48 hours and must absolutely minimize false positives. Which security framework approach is most appropriate for this application?

    Show answer & explanation

    Correct answer: D

    Given the highly dynamic nature of the application, the lack of developer communication, the short 48-hour deployment window, and the low tolerance for false positives, a negative security model (blocking known bad behavior via signatures, IP intelligence, etc.) is the only viable framework. A positive security model would require extensive learning and would constantly break the application (false positives) as unannounced changes occur.

  6. Question 6IntermediateSelect 2

    ARCHITECT SOLUTIONS · Determine the correct solution to mitigate a given threat

    An organization is facing two distinct, simultaneous threats against their primary web application:

    1. A massive volumetric UDP flood targeting the application's public IP address.
    2. A sophisticated, low-and-slow credential stuffing attack utilizing distributed botnets attempting to log into user accounts.

    Which TWO F5 solutions should the architect select to mitigate these specific threats effectively? (Select TWO)

    Show answer & explanation

    Correct answers: A, B

    BIG-IP AFM (Advanced Firewall Manager) is specifically designed to handle high-capacity network-layer (L3/L4) DDoS attacks, such as UDP floods, using hardware acceleration where available to drop the malicious traffic before it impacts the system.

    Advanced WAF (or F5 Distributed Cloud Bot Defense) provides sophisticated bot mitigation capabilities, including behavioral analysis and credential stuffing protection, which are required to stop low-and-slow automated login attempts.

Ready for the real thing?

The full 401 simulator has every exam-style question, timed mode, and instant scoring.

Go to the 401 simulator →