402 Sample Questions & Answers
Designing cloud infrastructure and licensing ties with orchestrating services through F5's RESTful APIs for the heaviest weighting, alongside cloud business models, identity access management, migration planning, and sizing instances for deployment.
Launch the full 402 simulator →Showing 6 of 12 free samples.
- Question 1Beginner
FOUNDATIONAL CLOUD CONCEPTS · Cloud business models and technologies
True or False: In a purely Software as a Service (SaaS) cloud business model, the customer is responsible for managing the operating system patching and application framework updates of the deployed solution.
Show answer & explanation
Correct answer: B
False. In a SaaS model, the cloud provider manages the entire stack, including the underlying infrastructure, operating systems, application frameworks, and the application software itself. The customer is typically only responsible for user data and access management.
- Question 2Advanced
FOUNDATIONAL CLOUD CONCEPTS · Application bursting and mobility
An organization is configuring BIG-IP DNS (formerly GTM) to support application bursting to AWS. Which load balancing method on the Wide IP is MOST appropriate to ensure traffic only flows to AWS when the on-premises BIG-IP LTM virtual server reaches 80% of its maximum connection capacity?
Show answer & explanation
Correct answer: A
In a cloud bursting scenario, Global Availability is often used. The on-premises virtual server is prioritized as the primary pool member. By setting a hard connection limit on the LTM virtual server, BIG-IP DNS will detect when this limit is reached (or when it goes offline due to capacity) and automatically fall back to the secondary pool member (the AWS environment).
- Question 3Intermediate
FOUNDATIONAL CLOUD CONCEPTS · Cloud Identity Access Management
A cloud engineer is analyzing Identity and Access Management (IAM) flows for a multi-cloud deployment. They need to allow a custom internal application hosted in GCP to programmatically manage BIG-IP VE configurations in AWS without embedding static credentials. Which IAM mechanism is BEST suited for this machine-to-machine authentication?
Show answer & explanation
Correct answer: C
The OAuth 2.0 Client Credentials grant type is specifically designed for machine-to-machine (M2M) communications where no user interaction is possible. It allows the GCP application to request a short-lived access token using its own client identity to interact securely with the BIG-IP REST API. SAML is designed for human browser-based SSO.
- Question 4Intermediate
CLOUD INFRASTRUCTURE DESIGN · SDN constraints on F5 components
When architecting an active/standby High Availability (HA) pair of BIG-IP Virtual Editions in Microsoft Azure, a cloud architect discovers that traditional Layer 2 failover mechanisms do not work. What specific Software-Defined Networking (SDN) constraint in public clouds prevents traditional F5 HA from functioning natively?
Show answer & explanation
Correct answer: B
Traditional F5 BIG-IP HA relies on Gratuitous ARP (GARP) and MAC masquerading to quickly move IP addresses between physical interfaces during a failover. Public cloud SDNs (like AWS, Azure, GCP) use strict mapping of IP addresses to ENIs/vNICs and drop unauthorized GARP broadcasts. Therefore, F5 requires Cloud Failover Extension (CFE) to make API calls to the cloud provider to update route tables or IP associations.
- Question 5Beginner
CLOUD INFRASTRUCTURE DESIGN · F5 licensing and support characteristics
An enterprise is planning to deploy BIG-IP Virtual Editions in AWS using an auto-scaling architecture to handle unpredictable traffic spikes. They require the ability to spin up instances dynamically without manually applying registration keys, while keeping operational costs directly tied to hourly usage. Which F5 licensing model BEST meets these requirements?
Show answer & explanation
Correct answer: C
Pay-As-You-Go (PAYG) is the optimal licensing model for auto-scaling environments with unpredictable workloads. Instances are billed hourly by the cloud provider based on usage, and they automatically license themselves upon boot without requiring external license managers (like BIG-IQ) or manual key entry.
- Question 6Intermediate
CLOUD INFRASTRUCTURE DESIGN · Single and multi-tier F5 products
A solutions architect is designing a multi-tier application delivery architecture in a green-field cloud data center. The requirements mandate that Layer 4 transport load balancing (TCP/UDP) scales independently from Layer 7 Web Application Firewall (WAF) inspections. Which architecture provides the most efficient scaling and resource isolation for this scenario?
Show answer & explanation
Correct answer: C
A multi-tier architecture separates networking functions by layer. By using a highly scalable Layer 4 load balancer (like AWS NLB or Azure Standard LB) as Tier 1, it can distribute traffic to a dynamically scaling Tier 2 composed of computationally heavy BIG-IP Advanced WAF instances. This meets the requirement for independent scaling and resource isolation.
flowchart TD Client --> NLB[Tier 1: Cloud Native L4 LB] NLB --> WAF1[Tier 2: BIG-IP WAF VE 1] NLB --> WAF2[Tier 2: BIG-IP WAF VE 2] WAF1 --> App[Application Servers] WAF2 --> App
Ready for the real thing?
The full 402 simulator has every exam-style question, timed mode, and instant scoring.