
Introduce the F5 303 exam preparation course, outlining the scope of BIG-IP ASM/WAF concepts and an effective study plan for exam readiness.
Explore practical web application firewall concepts for the F5 Big-IP ASM/WAF Specialist course, using demonstrations on a Hack IT auction site with the filter3 daemon, Firefox, and a USB module.
Meet Dean Armada, a certified instructor for Arista, Dell, EMC and Pure Storage, sharing expertise in containers, Python, and cybersecurity, highlighting 60+ IT certifications and Certified Kubernetes Administrator.
Explain the f5 303 exam prerequisites, path to the f5 certified technology specialist application security manager, and the exam duration, format, and regional time adjustments.
Navigate the F5 303 exam preparation course flow, including lab setup and destination web server provisioning, then master security policy deployment, tuning, attack signatures, cookie headers, reporting, and bot protection.
Plan to complete brute force web scraping mitigation, layer seven DoS mitigation, and ISM rules by January 2023, and deliver one and a half to two hours of course material.
Gain a clear overview of the F5 ASM/WAF lab, aligning with F5 BIG-IP ASM/WAF Specialist exam objectives to support exam preparation.
Build and explore the F5 BIG-IP ASM/WAF lab using VMware ESXi or VMware Workstation, with free courses and a quick guide to provisioning the HACKET auction site.
Explore a lab topology for F5 Big-IP ASM/WAF: configure a new virtual server and pool, route client traffic to an auction site, and manage devices over the 192.168.254.0/24 network.
Download the lab resources, unzip the zip file, and verify two directories: slides with presentation files and ASME files with sample XML vulnerabilities and scripts.
Install Fiddler and 3CDaemon on a Windows client, download via provided links, configure browser proxy, and verify web debugging output and SES log server setup.
Explore how to deploy security policies for F5 BIG-IP ASM/WAF, with an overview of policy deployment strategies and exam-focused best practices.
Explore how a web application firewall defines entities such as file types, URLs, parameters, cookies, and redirect domains, and builds policies with positive or negative security models.
Explore policy templates and the security policy workflow for virtual servers, including standalone and parent policies, rapid deployment, fundamentals, vulnerability scanner, and automatic versus manual policy building.
Demonstrates creating a virtual server and pool for a PHP auction site behind F5 BIG-IP, then configuring security policies with rapid deployment templates and key options.
Compare automatic learning mode with manual mode, noting automatic mode reduces human intervention and updates policies and attack signatures automatically as applications change.
Utilize manual learning mode to understand how ASM works, requiring full knowledge of your web applications and coordinated work with developers and admins to distinguish false positives from attacks.
Explore policy template considerations for F5 BIG-IP ASM/WAF, comparing rapid deployment, fundamental, and comprehensive templates, including rapid deployment's minimal config, negative security model, and PCI compliance by default.
Create a standalone rapid deploy security policy, enable advanced options like UTF-8, learning mode, and manual enforcement, and activate server technologies such as Apache, PHP, and Unix/Linux for attack signatures.
Navigate deployment workflow to configure a security policy, balancing learning mode, enforcement mode, application language, and server technologies, with signature staging and a seven-day enforcement readiness period.
Configure enforcement mode, learning settings, and server technologies to enable attack signatures, then enable the HDB profile and associate the Rapid Deploy policy on the virtual server.
Logging profiles are per VMS, not per security policy, with defaults: log all HTTP requests, log illegal HTTP requests, and log dose protection; use log old traffic for learning.
Enable the log profile under security tab policies to capture HTTP events, view event logs with headers and user agents, and filter by illegal requests and security policies.
Apply rapid deployment security checks to enable attack signatures and comprehensive web application protection. Enforce HTTP compliance, normalization and canonicalization, and detect encoded evasion techniques to improve attack signature accuracy.
Protect data from cryptographic failures by applying data guard to mask sensitive information in HTTP responses, including credit cards and social security numbers.
Demonstrates enabling and testing data guard on F5 BIG-IP ASM/WAF, showing how credit card data is masked, applying policy changes, and reviewing data guard violation logs.
Demonstrates configuring a data guard custom pattern in f5 big-ip asm to mask numeric data in item descriptions, test the pattern, and review violations for information leakage.
Explore policy tuning and violations in F5 BIG-IP ASM/WAF, with an overview designed to prepare for the F5 303 exam.
Observe HTTP traffic after initial policy setup, progressively enforce rules, and tune the WAF to reduce false positives by distinguishing entity violations from item violations.
Examine violation categories in F5 BIG-IP ASM/WAF, including positive and negative security models, file types, URL and parameter violations, attack signatures, ratings from 1 to 5 with source IP checks.
Demo shows how to trigger and view violations in F5 BIG-IP ASM/WAF, from deleting logs to inspecting cross-site scripting and SQL injection events in the event logs.
Signature staging tests attack signatures and entities like file sizes, URLs, domains, and cookies in a seven day learning period without blocking, preserving user experience while tuning the policy.
Enforcement mode removes attack signatures from staging and either logs in transparent mode or blocks violations in blocking mode, with two modes and per-entity signature staging controls.
Enforcement readiness period builds trust between staging items and the security policy through a seven-day, transparent testing window that may reset on configuration changes or violations.
Learn to build security policies with the F5 BIG-IP ASM/WAF policy builder, reduce false positives through white listing of files, URLs, parameters, cookies, and redirects, using manual or automatic learning.
Explore learning suggestions across security logs and traffic learning to identify legitimate traffic, monitor violations, and apply accept, delete, or ignore to refine the policy.
Demonstrates configuring learning and blocking settings in F5 BIG-IP ASM/WAF, enabling attack signatures and traffic learning to accept learning suggestions such as fiddler web debugging proxy.
Demo shows handling a learning suggestion for illegal HTTP methods by identifying an HTTP OPTIONS violation, accepting suggestion to allow OPTIONS, applying the policy, and retesting to see normal traffic.
Explore how blocking works in F5 big-ip asm/waf, including blocking flag, attack signatures, violation logging, blocking vs transparent mode, alarm flag usage, and customizing the blocking response page with redirects.
Demonstrate enforcing and staging application security policies with F5 BIG-IP ASM/WAF, switching from monitor to blocking, and validating policy changes through traffic learning and event logs.
Explore how to view, customize, and test the block response page in F5 BIG-IP ASM/WAF, including default headers, custom HTML, web objects, and redirect options.
Explore attack signatures overview and how they relate to F5 BIG-IP ASM/WAF security features, aiding exam preparation.
Learn how attack signatures in web application firewalls use the Snort rule engine to detect web attacks, apply signatures to requests or responses, and trigger violations or blocks.
Discover how signature inspection buffers HTTP requests using URI content, value content (query strings, post body, cookies), header content, and the entire request, with normalization before the signature engine.
Explore attack signature structure in F5 BIG-IP ASM/WAF, combining multiple conditions across content, header, and URI buffers with no case and object only options to form precise signatures.
Create and manage user defined attack signatures using simple and advanced modes, leveraging keyword filters and optional regular expressions to detect hacker content in HTTP transactions and trigger alarms.
Signature sets group signatures and must be assigned to security policies. Must be assigned as sets, not individual signatures, including system supplied or user defined, with generic detection sets for OWA and WebSphere.
Explore attack signature sets and security policy creation in F5 BIG-IP ASM/WAF, filtering signatures by server technologies and managing signature lists and sets.
Create a user defined attack signature in the signature pool, build a hacker set for other application attacks on var system, attach it to a security policy, and verify violations.
Explore how signature staging manages system and user defined attack signatures in the signature pool and moves them from learning to production, as administrators evaluate false positives and enforce blocking.
Demonstrate configuring and enforcing attack signatures in F5 BIG-IP ASM/WAF, moving signatures from staging to enforcement, testing blocking behavior, and analyzing event logs for cross-site scripting and hacker signatures.
Update attack signatures for F5 BIG-IP ASM/WAF using scheduling or manual modes, and automatic or manual delivery, with encrypted, digitally signed files and six-week update logs.
Navigate to system, software management, and live updates to review and install updated attack signatures, including added, modified, and deleted entities, with real-time or scheduled updates.
Explore positive security policy building within the F5 BIG-IP ASM/WAF framework, offering a concise overview to aid exam preparation.
Apply a positive security model to HTTP transactions by constraining file types, URLs, and parameters and gradually allow only approved entities, including file extensions, methods, and input lengths.
Discover how wild cards support learning entities (file types, URLs, parameters) in a default negative security policy, with allow patterns, staging, and enforcement that prevents false positives.
Learn about never wildcard, a global representation of all entities in the negative security model. See how ASM avoids adding new entities and uses attribute changes to the global wildcard.
Create a new F5 BIG-IP application security policy, set learning to manual and enforcement to transparent, using Unicode UTF-8 and never wildcard settings; apply to a virtual server.
Discover always mode in f5 big-ip asm/waf: it creates explicit entities for each item, potentially generating many entities such as file types and urls, requiring careful management and learning settings.
Configure a new always learning security policy in F5 BIG-IP ASM, set manual enforcement, enable traffic learning for Apache, MySQL, and PHP, and refine file types and parameters.
Explore selective mode as an intermediate between always and never in wildcard protection, learning and suggesting explicit entities only when their attributes differ from the wildcard configuration.
Create a selective security policy in f5 big-ip asm/waf, enable manual learning, trigger a violation for parameter q length, review logs, and apply a value adjustment to meet the suggestion.
Explore how traffic learning and enforcement readiness screens classify violations, show accepted issues, and guide enforcement of file types and attributes as readiness progresses.
Create a learning and enforcement policy in F5 BIG-IP ASM with manual enforcement and UTF eight. Learn illegal file types and parameter violations via traffic learning.
Explore cookies and other headers in the context of F5 BIG-IP ASM/WAF, providing essential concepts for exam preparation.
Explore how the main ASM cookies secure sessions—validating the TS cookie, MD5 signature, message key, and timestamp—while defending against bot, brute force, and CSRF, via set-cookie handling.
Explain how ASEM processes cookies, distinguishing allowed and enforced cookies. See how session cookies, encrypted and signed by ASEM, are handled, and tampering triggers the 'modified the main cookie' violation.
Watch how to create a BIG-IP security policy for headers and cookies, enable staging, and tamper a session cookie to demonstrate cookie hijacking and enforcement in ASM/WAF.
Configure http headers in F5 303 exam prep by enforcing mandatory headers, applying attack signatures and normalization, including default headers like cookie, authorization, and referrer, to protect web apps.
Demonstrates header tampering on the HTTP referrer to trigger attack signatures in F5 BIG-IP ASM/WAF, enabling enforcement and showing blocked requests with event logs.
Get an overview of reporting and logging for the F5 BIG-IP ASM/WAF specialist course, aligned with exam preparation.
Compare security overview, widgets, and reporting, with time-based graphical reports and top attackers, sessions, and policies across ASEM, WAF, AFM, and related security solutions.
Explore F5 BIG-IP ASM/WAF reporting with security overview analytics, customizable widgets, and dashboards for top violations, blocking policies, and traffic insights across application security policies.
Monitor ASEM resource reports to track CPU and memory utilization, swap size, and bypass events; receive alerts on thresholds and troubleshoot ACM-related resource limitations affecting ASM performance.
Explore ACM resource reports and ASM resource alerts, view security reporting settings for thresholds, configure SMTP notifications, and troubleshoot CPU, memory, and bypass resource limitations with time-range data.
Learn how PCI compliance reporting demonstrates ACM and web application security to auditors, with printable PDF PCI executive summaries mapping to PCI DSS 3.0 requirements.
Shows how to produce PCI compliance reports for F5 BIG-IP, enable https on a new https vts, and map rapid deploy policies to achieve encrypt transmission of cardholder data.
Explore traffic learning graphs page to view pending, ignored, and accepted learning suggestions, monitor enforcement readiness, and track enforcement status and changes by the administrator or automatic policy builder.
Explore the traffic learning graph on the traffic learning screen to review pending, ignored, and accepted learning suggestions and the enforcement status of entities for the header cookie security policy.
Explore how the big IP uses unix syslog on port 514 to log messages to files. Learn about facilities and log levels for elements like DNS and ASM, with cron log rotation.
Explore how logging profiles on a virtual server filter traffic, enable logging for illegal requests, and configure storage as local or remote using CSV, key-value, or common event format.
Create a rapid deploy log profile enabling application security to send local and remote logs to a syslog server via UDP 514. Observe audit events as you apply blocking policies.
Create and enable a response logging profile in application security, then test it on a virtual server to capture response details for data guard violations and cross-site scripting events.
Compare policy differences and review administration concepts for F5 BIG-IP ASM/WAF, equipping you to prepare effectively for the F5 303 exam.
Explore how user roles and partitions govern access in F5 BIG-IP ASM/WAF, detailing administrator and editor permissions, and the use of common and partition-specific resources.
Create and manage user roles and partitions in F5 BIG-IP ASM/WAF, assign partition access, and modify application security policies with read and write permissions.
Compare security policies on big IP system to audit differences, view diffs, and decide on work on copy, work on original, or make a copy with auto or manual merge.
Compare two security policies using policy diff to contrast file types, server technologies, and learning settings; learn how to merge configurations and apply policies in F5 BIG-IP ASM/WAF.
Export and import F5 BIG-IP ASM/WAF security policies in xml, edit xml attributes, manage wildcard entities and indexes, and use policy history to restore or copy versions.
Export and compare compact and non-compact XML configurations, switch enforcement to transparent, set max http header length to 5000, remove 503, and import the updated XML to replace policy B.
Explore ASM deployments for BIG-IP—from standalone devices with a single pool member to in-line setups with LTM or AZM licensing, including hybrid hardware and virtual editions.
Master advanced parameter handling concepts for the F5 BIG-IP ASM/WAF platform, aligning with the F5 303 exam preparation.
Explore parameter types in web applications, including user input values and static preset values. Learn how ACM enforces global, URL-specific, and flow parameters for get and post requests.
Learn how to identify form parameters in search, browse, and login forms, including q, username, and password, inspect post data and multi-value payment[] selections for security policies.
Secure parameters by configuring data types, volumetric characters, and attack signatures at the parameter level. Manage meta characters and encoding rules to prevent false positives and complexity in large apps.
Create and apply a static parameter protection policy, learn and restrict parameter values, and observe blocking of illegal static parameter values like wire transfer, with logging.
Explore dynamic parameters created on the fly by application logic, their frequent changes, and how F5 ASM extracts them from urls or links to prevent tampering (session IDs, account numbers).
Learn how the ASM cookie extracts dynamic parameters, storing name-value pairs in the ASME cookie and ACM frame cookie, with tampering detected across requests and 237-parameter limits.
Copy the static param security policy to a dynamic param policy, bind it to the virtual server, and enable extraction for the nick parameter to prevent illegal dynamic parameter values.
Welcome to F5 303 Exam Preparation. Passing the Exam will achieve F5 Certified Technology Specialist, Application Security Manager (ASM)
This course will help you pass F5 303 ASM Specialist Exam v12.1 (2022), this will also provides you a solid foundation in Web Application Firewall Technologies.
F5 Certified Technology Specialist, ASM! Enables skills in Web Application Security and Web Application Firewall (WAF).
This 12 hour course will help you understand the underlying technologies running in our Web Server Farms and how to protect from OWASP Top 10 Vulnerabilities.
This course is filled with Config Demonstration. This will help you understand the concepts and how to configure F5 ASM/WAF
I am proud to be one of the few instructors in Udemy who records themselves during the course delivery. Whether I am presenting, whiteboarding or doing lab demonstration, you will always see me. I do this so that I will be more CONNECTED TO YOU.
The course includes setting up F5 BIG-IP with ASM Lab. This will definitely helps you understand ASM and helps you prepare passing the exam.
Target Audience
F5-CA and F5 303 or F5-CTS, ASM Candidate
F5 ASM/Adv WAF Specialist
Web Application Security Specialist
Web App Penetration Testers
Expectations
Will not cover basic HTTP
Will not cover basic web vulnerabilities
Will not cover basic web attacks
Above are covered in a separate course: Python Security – Web Attacks