100% satisfaction guarantee Immediately available after payment Both online and in PDF No strings attached 4.2 TrustPilot
logo-home
Exam (elaborations)

WAF01-05 Web Application Firewall - Foundation Questions with Correct Answers

Rating
-
Sold
-
Pages
10
Grade
A+
Uploaded on
28-05-2025
Written in
2024/2025

WAF01-05 Web Application Firewall - Foundation

Institution
Barracuda
Course
Barracuda









Whoops! We can’t load your doc right now. Try again or contact support.

Written for

Institution
Barracuda
Course
Barracuda

Document information

Uploaded on
May 28, 2025
Number of pages
10
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers

Subjects

Content preview

WAF01-05 Web Application Firewall -
Foundation

The WAF passive mode... - answer. Can be configured as a global setting for all
services.
...blocks traffic that triggers security violations.
*...logs traffic that triggers security violations. *
*...allows traffic even if it triggers security violations. *
...does not log traffic that triggers security violations.

Bot mitigation policies can be used... - answer...to enforce limits in the TCP window
size.
*...to enable credential stuffing protection.*
*...to limit the amount of total requests to a specific part of a web application.*
...to enforce limits in HTTP headers.

When an 'action' is changed in the global ACLs... - answer...all services are affected.
*...all services sharing the same security policy are affected.*
...all security policies are affected.

What services are provided by the WAF's Access Control feature? -
answerAuthentication and credential stuffing protection.
*Authentication and authorization.*
Authentication, authorization, and auditing.
Authentication, authorization, and accounting.

URL Protection... - answer...limits the number of cookies that can be present in an
HTTP request.
*...limits the number of file uploads.*
*...specifies the allowed methods in HTTP requests headers.*
...limits the size of the file uploads.

In the One-Arm Proxy deployment... - answer...a WAN and a LAN interface are used.
*...only the WAN interface is used for traffic.*
...backend servers could be reached directly, bypassing the WAF. (f)
(F)

When the Encryption Tamper Proof mode is enabled, legitimate cookies might be
blocked if the Max Cookie Value Length limit, specified in the Request Limits, is not
changed accordingly. - answerTrue

The predefined security policies... - answer...cannot be deleted.

, *...can be assigned to several services.*
*...can be customized.*

A newly created service has the following security policy associated to it: - answerNew
services do not have any security policies by default.
Passive
Custom
*Default*
Active

Extended Match rules can only be used in Bot mitigation policies. - answerFalse

By using the WAF Access Control feature, Audit logs can be used to track the activity of
users logged into the web application. - answerFALSE

The WAF configuration can be changed using: - answer*SSH*
*The web interface* (1,2)
*REST APIs* (2)
*The local shell access* (1,2)
(F)

Select all the requirements for deploying the WAF in high availability. - answer*Both
systems must have the same 'Cluster Shared Secret'.*
Both systems must have the same hostname.
*Both systems must be of the same model.*
*Both systems must run the same firmware version.*
Both systems must have at least one service configured.

What are the available untrusted levels in Exception Profiling? - answerTrusted Hosts
*High*
*Low*
*Medium*
Very High

Antivirus signatures are updated even if the Energize Updates license has expired. -
answerfalse

What do you have to configure to enforce the antivirus scan for file uploads in some
parts of your web applications? - answerBrute Force Prevention
*Bot mitigation policies*
Allow/Deny rules
Data Theft policies

The Barracuda WAF is licensed by the number of web applications protected. -
answerFALSE

Get to know the seller

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
julianah420 Phoenix University
View profile
Follow You need to be logged in order to follow users or courses
Sold
656
Member since
2 year
Number of followers
324
Documents
33901
Last sold
3 days ago
NURSING,TESTBANKS,ASSIGNMENT,AQA AND ALL REVISION MATERIALS

On this page, you find all documents, package deals, and flashcards offered by seller julianah420

4.3

149 reviews

5
101
4
20
3
8
2
5
1
15

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Frequently asked questions