303
BIG-IP ASM Specialist (303)
Parte de F5 Certified Technology Specialist, BIG-IP ASM
Computer-based, multiple-choice; delivered at Pearson VUE test centers (English). Credential awarded: F5 Certified Technology Specialist, BIG-IP ASM. Prerequisite: F5 Certified BIG-IP Administrator (F5-CA); the catalog lists F5-CTS, BIG-IP ASM as a prerequisite for the Security Solutions Expert track.
Material de estudo independente, construído a partir do blueprint público da prova. Sem afiliação, autorização ou endosso da F5. Os objetivos são transcritos e mapeados à mão, então esta página pode conter erros ou estar defasada em relação ao material atual do fabricante: objetivos, versões, numeração e disponibilidade mudam sem aviso. Trate o portal de certificação da própria F5 como a fonte da verdade e confira nele antes de agendar qualquer coisa.
Section 1: ARCHITECTURE/DESIGN AND POLICY CREATION
1.01 Explain the potential effects of common attacks on web applications
O que saber:- Understand and describe how the ASM can affect clients and applications directly while in either transparent or blocking mode
- Summarize the OWASP Top Ten
1.02 Explain how specific security policies mitigate various web application attacks
O que saber:- Understand/interpret an iRule or LTM policy to map application traffic to an ASM policy
- Explain the trade-offs between security, manageability, false positives, and performance
Neste site: Blocking vs Transparent: o que o modo de enforcement do Advanced WAF realmente faz, Lidando com falsos positivos no Advanced WAF: triagem por rating, depois ajuste com escopoFerramentas: f5-irules-vs-ltm-policy1.03 Determine the appropriate policy features and granularity for a given set of requirements
O que saber:- Understand application (security) requirements and convert requirements to technical tasks
Ferramentas: f5-awaf-declarative-policy-explainer1.04 Determine which deployment method is most appropriate for a given set of requirements
O que saber:- Determine which deployment method is most appropriate given the circumstances (web services, vulnerability scanner, templates, rapid deployment model)
1.05 Explain the automatic policy builder lifecycle
O que saber:- Create any profiles required to support the policy deployment (xml, JSON, logging profiles)
- Implement anomaly detection appropriate to the web app (D/DoS protection, brute force attack, web scraping, proactive bot defense)
1.06 Review and evaluate policy settings based on information gathered from ASM (attack signatures, DataGuard, entities)
O que saber:- Configure initial policy building settings (automatic policy builder settings)
Neste site: Data Guard: mascarando dados sensíveis nas respostas, Staging de assinaturas e o período de prontidão para enforcementFerramentas: f5-awaf-learning-suggestion-interpreter1.07 Define appropriate policy structure for policy elements
O que saber:- Define appropriate policy structure for policy elements (URLs, parameters, file types, headers, sessions and logins, content profiles, CSRF protection, anomaly detection, DataGuard, proactive bot defense)
Neste site: Content Profiles do Advanced WAF: analisando JSON, XML, GraphQL e GWT com segurança, Data Guard: mascarando dados sensíveis nas respostas, Como uma política declarativa do BIG-IP Advanced WAF é estruturada, Session Tracking do Advanced WAF: encontrando e detendo o cliente por trás das requisiçõesFerramentas: f5-awaf-declarative-policy-explainer1.08 Explain options and potential results within the deployment wizard
O que saber:- Describe options within the deployment wizard (deployment method, attack signatures, virtual server, learning method
- Select the appropriate ASM deployment model given the business requirements
1.09 Explain available logging options
O que saber:- Explain the specifications of the remote logger (ports, types of logs, formats, address)
Ferramentas: syslog-pri-decoder1.10 Describe the management of the attack signature lifecycle and select the appropriate attack signatures or signature sets
O que saber:- Understand management of attack signature lifecycle (staging, enforcement readiness period) and select appropriate attack signatures or signature sets.
Ferramentas: f5-awaf-signature-accuracy-risk
Section 2: POLICY MAINTENANCE AND OPTIMIZATION
2.01 Evaluate the implications of changes in the policy to the security and functionality of the application
O que saber:- Evaluate whether the rules are being implemented effectively and appropriately to meet security and/or compliance requirements and make changes as appropriate
Neste site: Lidando com falsos positivos no Advanced WAF: triagem por rating, depois ajuste com escopoFerramentas: f5-awaf-policy-diff2.02 Explain the process to integrate natively supported third party vulnerability scan output and generic formats with ASM
O que saber:- Refine appropriate policy structure for policy elements (URLs, parameters, file types, headers, sessions and logins, content profiles, CSRF protection, anomaly protection)
- Explain how to manage policies using import, export, merge, and revert
Ferramentas: f5-awaf-policy-diff2.03 Evaluate whether rules are being implemented effectively and appropriately to mitigate violations
O que saber:- Evaluate the implications of changes in the policy to the security and vulnerabilities of the application
Neste site: Lidando com falsos positivos no Advanced WAF: triagem por rating, depois ajuste com escopoFerramentas: f5-awaf-request-log-triage2.04 Determine how a policy should be adjusted based upon available data
O que saber:- Tune an ASM policy for better performance, including use of wildcards to improve efficiency
Neste site: Lidando com falsos positivos no Advanced WAF: triagem por rating, depois ajuste com escopoFerramentas: f5-awaf-false-positive-triage2.05 Define the ASM policy management functions
O que saber:- Identify the status of the policy
- Define the violation types that exist in ASM
- Describe how to merge and differentiate between policies
Ferramentas: f5-awaf-policy-diff
Section 3: REVIEW EVENT LOGS AND MITIGATE ATTACKS
3.01 Interpret log entries and identify opportunities to refine the policy
O que saber:- Examine traffic violations, determine if any attack traffic was permitted through the ASM and modify the policy to remove false positives
- Locate and interpret reported security violations by end users and application developers
3.02 Given an ASM report, identify trends in support of security objectives
O que saber:- Understand and describe each major violation category and how ASM detects common exploits
- Generate reporting for the ASM system and review the contents of the reports (anomaly statistics, charts, requests, PCI compliance status)
Ferramentas: f5-awaf-request-log-triage3.03 Determine the appropriate mitigation for a given attack or vulnerability
O que saber:- Take appropriate action on reported security violations by end users and application developers
- Modify ASM policy to adapt to attacks
3.04 Decide the appropriate method for determining the success of attack mitigation
O que saber:- Choose an appropriate user defined attack signature to respond to particular traffic
Ferramentas: f5-awaf-signature-accuracy-risk
Section 4: TROUBLESHOOT
4.01 Evaluate ASM policy performance issues and determine appropriate mitigation strategies
O que saber:- Analyze performance graphs and statistics along with ASM configurations to determine the root cause of performance issues and appropriate remediation to the configuration based on Guaranteed Logging
4.02 Understand the impact of learning, alarm, and blocking settings on traffic enforcement
O que saber:- Ensure that the security policy is inspecting web application traffic (application is functional and the policies are parsing the traffic)
4.03 Examine policy objects to determine why traffic is or is not generating violations
O que saber:- Examine Security Event Logs and ASM configurations to determine expected violations based on the logging profile assigned to the virtual server
Neste site: Lidando com falsos positivos no Advanced WAF: triagem por rating, depois ajuste com escopoFerramentas: f5-awaf-request-log-triage4.04 Identify and interpret ASM performance metrics
O que saber:- Understand the impact of ASM iRules on performance.
- Understand the impact of traffic spikes on ASM performance and available mitigation strategies
Ferramentas: f5-irules-performance-linter4.05 Evaluate ASM system performance issues and determine appropriate mitigation strategies
O que saber:- Correlate performance issues with ASM policy changes based on security policy history information and system performance graphs
Ferramentas: f5-awaf-policy-diff4.06 Recognize ASM specific user roles and their permissions
O que saber:- Recognize differences between user roles/permissions
- Recognize ASM specific user roles
Fontes públicas, usadas de boa-fé
Estes guias são materiais de estudo independentes, montados a partir de conteúdo publicamente disponível: blueprints de exame publicados, documentação oficial de produto e catálogos de treinamento dos fabricantes. Nomes de produtos, códigos de exame e marcas pertencem a seus titulares e são usados apenas para identificar o assunto ensinado. Este site não é afiliado a nenhum fabricante aqui citado nem endossado por ele. Se você detém direitos sobre material publicado nesta página e entende que ele deve ser removido ou corrigido, envie a URL exata e uma breve nota sobre o problema pela página de contato; os pedidos são analisados com rapidez e boa-fé. Ler o aviso legal completo →