F5 BIG-IP DNS Specialist (302) Certification Sample Questions
Getting knowledge of the F5 302 exam structure and question format is vital in preparing for the F5 BIG-IP DNS Specialist certification exam. Our F5 BIG-IP DNS Specialist sample questions offer you information regarding the question types and level of difficulty you will face in the real exam. The benefit of using these F5 302 sample questions is that you will get to check your preparation level or enhance your knowledge by learning the unknown questions. You will also get a clear idea of the exam environment and exam pattern you will face in the actual exam with the F5 BIG-IP DNS Specialist Sample Practice Test. Therefore, solve the F5 BIG-IP DNS sample questions to stay one step forward in grabbing the F5 Certified Technology Specialist, BIG-IP DNS credential.
These F5 302 sample questions are simple and basic questions similar to the actual F5 BIG-IP DNS Specialist questions. If you want to evaluate your preparation level, we suggest taking our F5 BIG-IP DNS Specialist Premium Practice Test. You might face difficulties while solving the real-exam-like questions. But, you can work hard and build your confidence on the syllabus topics through unlimited practice attempts.
F5 302 Sample Questions:
01. One BIG-IP DNS device answers a company's public zones on the address internet resolvers query, and answers its staff on a second address inside the network. Repeated lookups of external names should be served to staff from the device itself, while a resolver out on the internet must never be able to make the device resolve a name it holds no zone for.
How should the cache be brought into that configuration?
a) Reference it from the DNS profile on the public listener, so the answers outside resolvers ask for most often are held ready
b) Reference it from the DNS profile on both listeners, since the zones are answered first and only names the device lacks reach it
c) Reference it from the DNS profile on the internal listener alone, leaving the profile on the public listener with no cache at all
d) Create it without referencing it from either profile, since a cache holds on to answers that pass through the device
02. Users report that a service reached through a wide IP failed for a period the previous evening. The system log for the GSLB pool in that data center records each of its members transitioning between available and unavailable at different points across the period rather than together.
Which two observations in the log would establish that the pool itself could still supply a member throughout the period?
(Choose two.)
a) The servers behind each member answered requests sent to them directly during the period.
b) At every point in the period at least one member had last transitioned to available.
c) The members' unavailable intervals were each brief, and none of them recurred later in the period.
d) The zone carrying the wide IP's name was current on the device, and its SOA serial matched the primary's.
e) The pool's own recorded status did not change, only the status of the members beneath it.
03. Every virtual server configured beneath one server object reports unavailable at the same moments, while other server objects in the same data center stay stable. Each of those virtual servers carries its own monitor, and the services they represent are confirmed to be running throughout.
Which change is the right response?
a) Remove the monitors from the virtual servers and let the pool determine availability.
b) Replace each virtual server's monitor with one that checks the service rather than the host.
c) Correct the probing of the server object itself, since the availability of the objects beneath it follows.
d) Move the affected virtual servers into a pool of their own, so their availability is evaluated separately.
04. Two BIG-IP DNS devices in a sync group are not exchanging state, and an engineer plans to capture the traffic between them with tcpdump to see what is happening. Which two choices make that capture capable of answering the question?
(Choose two.)
a) Capture on the VLAN that carries the self-IP addresses configured for iQuery.
b) Filter the capture on the peer's address as it is recorded on the server object.
c) Capture on the VLAN facing the monitored virtual servers, since the reported state originates there.
d) Filter the capture on the listener address clients use, since it identifies the device to its peers.
e) Capture on the management VLAN, since device state is exchanged over the administrative connection.
05. While one sync group member is offline for an upgrade, users of an application that had been resolving to the local data center begin to be sent to the remote one. The local application servers stay healthy and reachable throughout, and no configuration change was made.
Which explanation best accounts for this?
a) Resolvers cached the remote data center's address before the window began, and kept handing it out to their clients until it expired
b) The upgrade removed the wide IP's local pool from the configuration, leaving the remote pool as the sole source of answers
c) The remaining member retained the offline member's last reported status for those objects, so the local data center stayed on offer
d) With the member that probed those objects offline, the remaining member had no current status for them and load balanced to the remote pool
06. A customer states that name resolution for a public application must continue when an entire site is lost, including whatever DNS system is running inside it.
Which two pieces of information about the customer's existing DNS service must be gathered before that requirement can be judged achievable?
(Choose two.)
a) Which name servers the zone's delegation currently lists, and who is able to change that list
b) Whether each authoritative server for the zone can serve independently of the site holding the master copy
c) Which software the customer's operations staff use today to edit and publish the zone
d) Which recursive resolvers the customer's own staff and applications are configured to query
e) The number of records the zone publishes, and which of those record types the new system would have to serve
07. Two data centers each contain a BIG-IP DNS device, and a firewall separates them. The security team asks which direction it has to permit so the two devices can exchange status. What should the engineer tell them?
a) The connection is opened when a query for the remote data center arrives
b) Each device waits to be contacted, so a rule permitting either device inbound is sufficient
c) Each device opens its own connection to the other, so the path must be permitted both ways
d) The remote device registers itself, so only inbound rules on the local device matter
08. An engineer must review the trusted certificate information held on a BIG-IP DNS device before rebuilding the trust that iQuery communication depends on. Which utility produces that information directly?
a) dig, issued against the peer device's name, so the certificate details published for that host are returned.
b) openssl, run against the stored certificate, so its subject, issuer and validity fields can be read.
c) tcpdump, taken on the VLAN that carries iQuery, so the certificate fields can be read out of the captured session.
d) nslookup, run from the peer device, so the two members can be compared for agreement on the certificate.
09. Internal clients point at the company's existing name servers and that configuration will not be changed. Those servers must stay responsible for resolving names, but a BIG-IP DNS system now sits in the path and should serve repeat answers without going on to them every time.
Which DNS Cache configuration fits?
a) A resolver cache, which performs the resolution itself beginning from the root name servers
b) A DNS Express zone, which answers from a transferred copy and never queries the existing servers
c) A validating resolver cache, which resolves the name and then checks the signatures it receives
d) A transparent cache, which stores answers passing through and forwards anything it does not hold
10. A design spans two data centers. One holds BIG-IP LTM systems whose virtual servers the BIG-IP DNS system must track. The other is a hosting provider's site containing third-party web servers with no F5 device present, reachable only over one particular network path.
Which two design choices give the BIG-IP DNS system usable availability information for both sites?
(Choose two.)
a) Enable persistence on the wide IPs so requests stay on whichever site last answered successfully
b) Attach a health monitor to the wide IP so the whole name is marked down when either site fails
c) Define the hosting site's web servers as generic host server objects and attach health monitors to them
d) Define the hosting site's web servers as members of a DNS Express zone, so their state arrives with each transfer
e) Rely on iQuery from the LTM systems to report the state of the virtual servers those systems own
Answers:
|
Question: 01 Answer: c |
Question: 02 Answer: b, e |
Question: 03 Answer: c |
Question: 04 Answer: a, b |
Question: 05 Answer: d |
|
Question: 06 Answer: a, b |
Question: 07 Answer: c |
Question: 08 Answer: b |
Question: 09 Answer: d |
Question: 10 Answer: c, e |
Note: For any error in F5 BIG-IP DNS Specialist (302) certification exam sample questions, please update us by writing an email on feedback@certfun.com.
