BIG-IP DNS Specialist Free Sample Questions

Create a free account to browse all 12 sample questions. The full practice test includes 160 questions. Use the simulator for timed and flashcard mode.

Try Simulator

302 Sample Questions

  1. Question 1

    Q1

    A financial enterprise is migrating its global application delivery infrastructure to F5 BIG-IP DNS. The architecture team needs to understand how DNS queries will flow from end users to the BIG-IP DNS listeners to ensure proper security and routing configurations.

    The enterprise currently uses a mix of internal caching resolvers and external public DNS services. The security team has mandated that BIG-IP DNS must not perform recursive lookups for external domains to prevent potential DNS amplification attacks.

    In a standard DNS query dataflow where a client queries a public domain hosted on the BIG-IP DNS, how does the BIG-IP DNS handle the resolution process, and what is the primary difference between iterative and recursive queries in this context?

    Show answer & explanation

    Correct answer: B

    In a standard DNS flow, the client asks its Local DNS (LDNS) to resolve a name recursively. The LDNS then performs iterative queries to the Root, TLD, and eventually the authoritative nameserver (the BIG-IP DNS). The BIG-IP DNS answers the iterative query authoritatively. It does not perform recursion for the client unless explicitly configured as a caching resolver.

  2. Question 2

    Q2Multiple answers

    A government agency requires all public-facing DNS zones to be secured using DNSSEC to prevent DNS spoofing and cache poisoning. When configuring BIG-IP DNS to sign these zones, which TWO of the following resource record types are automatically generated and used to establish the chain of trust and verify the authenticity of the response? (Select TWO)

    Show answer & explanation

    Correct answers: A, C

    RRSIG (Resource Record Signature) contains the cryptographic signature for a resource record set (RRset). It is generated during DNSSEC signing to prove authenticity.

    DNSKEY holds the public key that resolvers use to verify the RRSIG signatures. Both RRSIG and DNSKEY are fundamental DNSSEC record types used in BIG-IP DNS implementations.

  3. Question 3

    Q3

    True or False: In BIG-IP DNS ZoneRunner, a 'Stub' zone contains only the SOA, NS, and A records necessary to identify the authoritative servers for that zone, whereas a 'Hint' zone is used to find the root servers of the DNS namespace.

    Show answer & explanation

    Correct answer: A

    This is True. A stub zone is a copy of a zone that contains only those resource records necessary to identify the authoritative DNS servers for that zone (SOA, NS, and glue A records). A hint zone (often called the root hints file) contains the IP addresses of the root DNS servers used to bootstrap resolution.

  4. Question 4

    Q4

    An administrator is configuring topology-based load balancing on a BIG-IP DNS system. They need to route traffic based on the geographic location of the client making the request. Based on standard DNS architecture, which source IP address will the BIG-IP DNS evaluate against its topology records when it receives the query?

    graph TD Client[Client IP: 203.0.113.5] --> LDNS[LDNS IP: 198.51.100.10] LDNS --> Root[Root Servers] LDNS --> GTM[BIG-IP DNS Listener: 201.10.10.1]
    Show answer & explanation

    Correct answer: B

    In a traditional DNS hierarchy, the client sends a recursive query to its Local DNS (LDNS). The LDNS then performs the iterative query to the BIG-IP DNS. Therefore, the source IP packet arriving at the BIG-IP DNS belongs to the LDNS, not the client. Topology records will evaluate the LDNS IP (unless EDNS0 Client Subnet is specifically implemented and utilized).

  5. Question 5

    Q5

    A network engineer is configuring a BIG-IP DNS listener to support an environment transitioning to IPv6. The organization currently only has IPv4 routing configured to the BIG-IP DNS appliance, but clients are requesting IPv6 addresses for backend web servers. Which statement accurately describes how BIG-IP DNS handles this scenario?

    Show answer & explanation

    Correct answer: B

    DNS transport (IPv4 vs IPv6) is independent of the DNS query type (A vs AAAA). A client or LDNS can easily connect to an IPv4 listener on the BIG-IP DNS (IPv4 transport) and ask for an AAAA record (IPv6 query type). The BIG-IP DNS will successfully return the IPv6 address inside the payload of the IPv4 UDP/TCP packet.

  6. Question 6

    Q6

    When defining GTM objects, what is the primary purpose of configuring a 'Prober Pool' in BIG-IP DNS?

    Show answer & explanation

    Correct answer: B

    A prober pool is used to dictate exactly which BIG-IP systems (LTMs or GTMs running big3d) are responsible for sending health monitor probes to generic host servers or non-F5 devices. This allows administrators to control from which data center or network path the monitoring traffic originates.

Register free to unlock 6 more sample questions

Create a free account to continue with the rest of the 302 sample set.

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 160 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon