[Dec 16, 2021] 303 Dumps Full Questions - Exam Study Guide [Q241-Q262]

Share

[Dec 16, 2021] 303 Dumps Full Questions - Exam Study Guide

BIG-IP ASM  Free Certification Exam Material from Prep4sureGuide with 525 Questions

NEW QUESTION 241
A web server administrator informs the BIG-IP Administrator that web servers are overloaded Starting next month, the BIG-IP device will terminate SSL to reduce web server load. The BIG-IP device is ready using client SSL client profile and Rules on HTTP level. What actions should the BIG-IP Administrators to achieve the desired configuration?

  • A. Remove the server SSL profile and configure the Pool Members to use HTTP
  • B. Remove the client SSL profile and configure the Pool Members to US HTTP
  • C. Remove the chart SSL profile and change the Virtual Server to accept HTTP
  • D. Remove the server SSL profile and change the Virtual Server to accept HTTP traffic

Answer: A

 

NEW QUESTION 242
An LTM Specialist has detected that a brute force login attack is occurring against the SSH service via a BIG-IP management interface. Login attempts are occurring from many IPs within the internal company network. BIG-IP SSH access restrictions are in place as follows:

The LTM Specialist has determined that SSH access should only occur from the 192.168.1.0/24 and
172.16.254.0/23 networks.
Whichtmsh command should the LTM Specialist use to permit access from the desired networks only?

  • A. modify.sys sshd allow add {''192.168. 10/24 , '' ''172. 16 2540/23'')
  • B. modify/sys allow replace-all-with {''192.168.1.00/24'', ''192.16.254.0/23''}
  • C. modify /sys sshd login disable (''10.0.00/8'', ''172 16.0 0/12'', ''192. 168.0.0/16'')
  • D. modify/sys sshd login enable {''192.166.10/24'''' ''172.16 254 0/23

Answer: B

Explanation:
Explanation
Select C to overwrite the existing network's allow configuration over the specified network segment.

 

NEW QUESTION 243
Two LTM devices must be manually configured to restrict in the same Device Group.
What is the correct order of steps to meet this requirement?

  • A. Configure VLAN, Configure-Sync IP, Configure Failover type, Establish Device Trust, Sync Device Trust, Create type, Establish Device Sync Device Trust, Create Device Group.
  • B. Configure Self-IPs, Configure VLAN, Configure Config-Sync IP. Configure Failover type, Establish Device Trust, Sync Device Trust, Create Device Group
  • C. Configure VLAN, Configure Config-Sync IP. Configure Self-IPs. Configure Failover type. Establish Device Trust, Create Device Group
  • D. Configure VLAN, Configure Self-IPs, Configure Config-Sync IP.Configure Failover type, Establish Device Trust, Sync Device Trust, Create Device Group.

Answer: D

 

NEW QUESTION 244
-- Exhibit -

-- Exhibit --
Refer to the exhibit.
Which profile could be removed or changed on this virtual server to reduce CPU load on the LTM device without increasing server side bandwidth usage?

  • A. http
  • B. optimized-caching
  • C. httpcompression
  • D. tcp

Answer: C

 

NEW QUESTION 245
A webserver is being overloaded with HTTPS traffic. To decrease the load on the server, the LTM Specialist and the Server. Administrator decide to perform SSL offloading on the LTM device. The configuration of the virtual server is as follows:

Which change must be made to the configuration to perform SSL offloading?

  • A. Remove the severssl profile
  • B. Remove the clients profile
  • C. Remove the clientssl and serverssl profiles
  • D. Remove the clientssl and http profiles

Answer: A

 

NEW QUESTION 246
A high-availability (HA) pair configuration uses only the hardwire serial cable connection to determine device state. A power outage occurs to the PDU powering the active unit. The standby unit takes over the active role as expected.
How is the peer unit able to determine the active unit is unavailable?

  • A. voltage loss on serial cable
  • B. no data stream received on serial port
  • C. no response on management interface
  • D. no heartbeat packets received on self IPs

Answer: A

 

NEW QUESTION 247
What should an LTM Specialist configure on an LTM device to send AVR notification emails?

  • A. Email notification to be sent via iControl from the LTM device
  • B. Syslog on the LTM device to send to an SMTP server
  • C. Custom SNMP traps on the LTM device for AVR notifications
  • D. Email notification to be sent via SMTP from the LTM device

Answer: D

 

NEW QUESTION 248
A BIG-IP Administrator needs to view the CPU utilization of a particular Virtual Server. Which section of the Configuration Utility should the administrator use for this purpose?

  • A. Statistics > Module Statistics > Local Traffic > Virtual Servers
  • B. Statistics > Analytics > Process CPU Utilization
  • C. Statistics > Module Statistics > Local Traffic > Virtual Addresses
  • D. Statistics > Module Statistics > Traffic Summary

Answer: A

 

NEW QUESTION 249
An LTM device is serving an FTP virtual server that has three pool members. The FTP pool members are monitored via TCP port 21. Customers are reporting that they are able to log in, but are sometimes unable to upload files to the server.
Which monitor should the LTM Specialist configure to verify that the servers can handle file uploads?

  • A. FTP
  • B. Inband
  • C. Real Server
  • D. Scripted
  • E. External

Answer: E

 

NEW QUESTION 250
An LTM Specialistconfigures a new HTTPS virtual server that contains a valid example.com ssl certificate.
The LTM Special receives an error in the browser when connecting.
What must be added to the SSL Client profile to fix this issue?

  • A. A sell-sign certificate
  • B. A public root certificate
  • C. An intermediate certificate
  • D. A new example com certificate

Answer: C

 

NEW QUESTION 251
-- Exhibit -


-- Exhibit --
Refer to the exhibits.
Users are able to access the application when connecting directly to the web server but are unsuccessful when connecting to the virtual server.
What is the cause of the application access problem?

  • A. The virtual server is NOT configured to listen on port 80.
  • B. The client has no route to the web server.
  • C. The virtual server has SNAT disabled.
  • D. The web server is NOT responding on the correct port.
  • E. The virtual server has address translation disabled.

Answer: E

 

NEW QUESTION 252
An HTTP monitor is created and assigned to a pool with the following non-default configuration:
Interval: 7 seconds
Timeout: 22 seconds
Reverse: Yes
Send String: GET/status.htmlHTTP/1.1/r/nHost:test.example.com/r/nConnector:Close Receive String: Up The HTTP server sends the following response:

What is the resulting pool status?

  • A. Offline (Enabled)
  • B. Unavailable (Enabled)
    Available (Enabled)
  • C. Unknown (Disabled)

Answer: B

 

NEW QUESTION 253
A OneConnect profile is applied to a virtual server. The LTM Specialist would like the client source IP addresses within the 10.10.10.0/25 range to reuse an existing server side connection.
Which OneConnect profile source mask should the LTM Specialist use?

  • A. 255.255.255.255
  • B. 0.0.0.0
  • C. 255.255.255.0
  • D. 255.255.255.128
  • E. 255.255.255.224

Answer: D

 

NEW QUESTION 254
Which two subsystems could the LTM Specialist utilize to access an LTM device with lost management interface connectivity? (Choose two.)

  • A. SCCP
  • B. ALOM
  • C. AOM
  • D. ILO

Answer: A,C

 

NEW QUESTION 255
AN LTM Specialist is setting up a new HTTPS virtual server to decrypt client traffic. SNAT the traffic and send the encrypted traffic to the poor member, the client's IP address must be included in the traffic sent to the pool member.
What is a complete set of profiles that must be configured for the virtual server to meet these requirements?

  • A. TCP , Server SSL, HTTP
  • B. TCP, Client SSL, Server SSL, HTTP
  • C. TCP, Client SSL, HTTP
  • D. TCP, Client SSL, Server SSL

Answer: B

 

NEW QUESTION 256
A BIG-IP Administrator configures a Virtual Server. Users report that they always receive a TCP RST packet to the BIG-IP system when attempting to connect to it. What is the possible reason for this issue?

  • A. The virtual server Type is set to Drop
  • B. The virtual server Type is set to Internal
  • C. The virtual server Type is set to Stateless
  • D. The virtual server Type is set to Reject

Answer: D

 

NEW QUESTION 257
-- Exhibit -

-- Exhibit --
Refer to the exhibit.
A client attempts to connect from a Google Chrome browser to a virtual server on a BIG-IP LTM. The virtual server is SSL Offloaded. When the client connects, the client receives an SSL error. After trying Mozilla Firefox and Internet Explorer browsers, the client still receives the same errors.
The LTM Specialist does an ssldump on the virtual server and receives the results as per the exhibit.
What is the problem?

  • A. The BIG-IP LTM is NOT listening on port 443.
  • B. The client needs to be upgraded to the appropriate cipher-suite.
  • C. The BIG-IP LTM is NOT serving a certificate.
  • D. The SSL key length is incorrect.

Answer: C

 

NEW QUESTION 258
A BIG-IP Administrator assigns the default http health monitor to a pool that has three members listening on port 80 When the administrator connects to each pool member via the CURL utility, two of the members respond with a status of 404 Not Found while the third responds with 200 OK. What will the pool show for member availability?

  • A. All members online.
  • B. Two members online and one member offline.
  • C. All members offline.
  • D. Two members offline and one member online.

Answer: A

 

NEW QUESTION 259
An LTM Specialist defines a receive string in the HTTP monitor and then assigns it to the HTTP pool. The monitor has an interval of 5 seconds and a timeout of 16 seconds.
If the receive string is NOT seen in the the HTTP payload after 20 seconds, how does the LTM device mark the monitor status?

  • A. forced offline
  • B. offline
  • C. unknown
  • D. available
  • E. unavailable

Answer: B

 

NEW QUESTION 260
An LTM Specialist is troubleshooting an issue with a new virtual server. When connecting through the virtual server, clients receive the message "Unable to connect" in the browser, although connections directly to the pool member show the application is functioning correctly. The LTM device configuration is:
ltm virtual /Common/vs_https {
destination /Common/10.10.1.110:443
ip-protocol udp
mask 255.255.255.255
pool /Common/pool_https
profiles {
/Common/udp { }
}
translate-address enabled
translate-port enabled
vlans-disabled
}
ltm pool /Common/pool_https {
members {
/Common/172.16.20.1:443 {
address 172.16.20.1
}
}
}
What issue is the LTM Specialist experiencing?

  • A. The virtual server is configured for the incorrect protocol.
  • B. The pool member is marked down administratively.
  • C. The pool member is marked down by a monitor.
  • D. The virtual server is disabled on all VLANs.

Answer: A

 

NEW QUESTION 261
An LTM Specialist needs to modify the logging level for tcpdump execution events. Checking the BigDB Key, the following is currently configured:
sys db log.tcpdump.level {
value "Notice"
}
Which command should the LTM Specialist execute on the LTM device to change the logging level to informational?

  • A. tmsh set /sys db log.tcpdump.level status informational
  • B. tmsh set /sys db log.tcpdump.level value informational
  • C. tmsh modify /sys db log.tcpdump.level value informational
  • D. tmsh modify /sys db log.tcpdump.level status informational

Answer: C

 

NEW QUESTION 262
......

Dumps Brief Outline Of The 303 Exam: https://www.prep4sureguide.com/303-prep4sure-exam-guide.html

Use Real 303 - 100% Cover Real Exam Questions: https://drive.google.com/open?id=1bwW1WVmXGvjL1k9t6GOISYX0WrXzbL6u