
Explore practical web application firewall concepts for the F5 Big-IP ASM/WAF Specialist course, using demonstrations on a Hack IT auction site with the filter3 daemon, Firefox, and a USB module.
Navigate the F5 303 exam preparation course flow, including lab setup and destination web server provisioning, then master security policy deployment, tuning, attack signatures, cookie headers, reporting, and bot protection.
Build and explore the F5 BIG-IP ASM/WAF lab using VMware ESXi or VMware Workstation, with free courses and a quick guide to provisioning the HACKET auction site.
Explore a lab topology for F5 Big-IP ASM/WAF: configure a new virtual server and pool, route client traffic to an auction site, and manage devices over the 192.168.254.0/24 network.
Download the lab resources, unzip the zip file, and verify two directories: slides with presentation files and ASME files with sample XML vulnerabilities and scripts.
Navigate deployment workflow to configure a security policy, balancing learning mode, enforcement mode, application language, and server technologies, with signature staging and a seven-day enforcement readiness period.
Enable the log profile under security tab policies to capture HTTP events, view event logs with headers and user agents, and filter by illegal requests and security policies.
Protect data from cryptographic failures by applying data guard to mask sensitive information in HTTP responses, including credit cards and social security numbers.
Demonstrates enabling and testing data guard on F5 BIG-IP ASM/WAF, showing how credit card data is masked, applying policy changes, and reviewing data guard violation logs.
Observe HTTP traffic after initial policy setup, progressively enforce rules, and tune the WAF to reduce false positives by distinguishing entity violations from item violations.
Discover how signature inspection buffers HTTP requests using URI content, value content (query strings, post body, cookies), header content, and the entire request, with normalization before the signature engine.
Explore attack signature structure in F5 BIG-IP ASM/WAF, combining multiple conditions across content, header, and URI buffers with no case and object only options to form precise signatures.
Create a user defined attack signature in the signature pool, build a hacker set for other application attacks on var system, attach it to a security policy, and verify violations.
Explore positive security policy building within the F5 BIG-IP ASM/WAF framework, offering a concise overview to aid exam preparation.
Apply a positive security model to HTTP transactions by constraining file types, URLs, and parameters and gradually allow only approved entities, including file extensions, methods, and input lengths.
Explain how ASEM processes cookies, distinguishing allowed and enforced cookies. See how session cookies, encrypted and signed by ASEM, are handled, and tampering triggers the 'modified the main cookie' violation.
Demonstrates header tampering on the HTTP referrer to trigger attack signatures in F5 BIG-IP ASM/WAF, enabling enforcement and showing blocked requests with event logs.
Get an overview of reporting and logging for the F5 BIG-IP ASM/WAF specialist course, aligned with exam preparation.
Shows how to produce PCI compliance reports for F5 BIG-IP, enable https on a new https vts, and map rapid deploy policies to achieve encrypt transmission of cardholder data.
Explore how logging profiles on a virtual server filter traffic, enable logging for illegal requests, and configure storage as local or remote using CSV, key-value, or common event format.
Create a rapid deploy log profile enabling application security to send local and remote logs to a syslog server via UDP 514. Observe audit events as you apply blocking policies.
Compare two security policies using policy diff to contrast file types, server technologies, and learning settings; learn how to merge configurations and apply policies in F5 BIG-IP ASM/WAF.
Export and compare compact and non-compact XML configurations, switch enforcement to transparent, set max http header length to 5000, remove 503, and import the updated XML to replace policy B.
Create and apply a static parameter protection policy, learn and restrict parameter values, and observe blocking of illegal static parameter values like wire transfer, with logging.
Copy the static param security policy to a dynamic param policy, bind it to the virtual server, and enable extraction for the nick parameter to prevent illegal dynamic parameter values.
Welcome to F5 303 Exam Preparation. Passing the Exam will achieve F5 Certified Technology Specialist, Application Security Manager (ASM)
This course will help you pass F5 303 ASM Specialist Exam v12.1 (2022), this will also provides you a solid foundation in Web Application Firewall Technologies.
F5 Certified Technology Specialist, ASM! Enables skills in Web Application Security and Web Application Firewall (WAF).
This 12 hour course will help you understand the underlying technologies running in our Web Server Farms and how to protect from OWASP Top 10 Vulnerabilities.
This course is filled with Config Demonstration. This will help you understand the concepts and how to configure F5 ASM/WAF
I am proud to be one of the few instructors in Udemy who records themselves during the course delivery. Whether I am presenting, whiteboarding or doing lab demonstration, you will always see me. I do this so that I will be more CONNECTED TO YOU.
The course includes setting up F5 BIG-IP with ASM Lab. This will definitely helps you understand ASM and helps you prepare passing the exam.
Target Audience
F5-CA and F5 303 or F5-CTS, ASM Candidate
F5 ASM/Adv WAF Specialist
Web Application Security Specialist
Web App Penetration Testers
Expectations
Will not cover basic HTTP
Will not cover basic web vulnerabilities
Will not cover basic web attacks
Above are covered in a separate course: Python Security – Web Attacks