F5 Certified Administrator, NGINX Recertification Exam Free Sample Questions

Create a free account to browse all 12 sample questions. The full practice test includes 150 questions. Use the simulator for timed and flashcard mode.

Try Simulator

F5CANR Sample Questions

  1. Question 1

    Q1

    A systems architect is designing a highly available web architecture. They need a component that can terminate TLS connections, serve static assets directly from disk to reduce backend load, and distribute dynamic API requests across a pool of application servers based on their current connection count. Which NGINX role best encompasses all these requirements?

    Show answer & explanation

    Correct answer: C

    NGINX operating as a Reverse Proxy and Load Balancer perfectly fits this scenario. It can terminate TLS, serve static files using the 'root' directive before forwarding requests, and use upstream blocks with 'least_conn' to distribute dynamic traffic. While it acts as a web server for the static files, the overarching role managing the API distribution and TLS termination for backends is a reverse proxy/load balancer. A standalone web server would not distribute traffic, and a CDN Edge is a broader infrastructure concept rather than the specific NGINX role described.

  2. Question 2

    Q2

    A large enterprise is redesigning its ingress architecture for a Kubernetes-based microservices environment. The current setup experiences high latency due to TLS handshakes being renegotiated at multiple hops, and static media files are unnecessarily traversing the internal network to reach backend pods.

    The new requirements dictate:

    1. TLS must be terminated at the edge.
    2. Static media (/images/, /video/) must be served from memory or disk at the edge.
    3. API requests must be routed to the correct internal microservice based on the URI path.
    4. Microservice responses must be cached for 5 minutes unless the client sends a 'Cache-Control: no-cache' header.

    Based on these requirements, how should NGINX be positioned and configured in this architecture?

    flowchart TD Client([Client]) --> NGINX[NGINX Edge] NGINX -->|/images/| Disk[(Local SSD)] NGINX -->|/api/v1/| PodA[Auth Service] NGINX -->|/api/v2/| PodB[Data Service]
    Show answer & explanation

    Correct answer: B

    This approach correctly addresses all requirements. NGINX operates at Layer 7 to inspect URIs (routing /api/v1 vs /api/v2), terminates TLS using 'ssl_certificate', serves static files directly via the 'root' directive in a specific location, and utilizes 'proxy_cache_bypass $http_cache_control' to respect client cache-busting requests. Layer 4 load balancing (stream module) cannot inspect URIs or serve static files. Terminating TLS at the pods violates the edge-termination requirement.

  3. Question 3

    Q3

    When structuring a complex NGINX configuration using the include directive, a system administrator wants to include all .conf files located in the /etc/nginx/conf.d/ directory. However, they must ensure this include statement is placed in the correct context to load virtual host definitions. Which context is the MOST appropriate for including virtual host (server block) configuration files?

    Show answer & explanation

    Correct answer: C

    Virtual host definitions (server blocks) that handle HTTP/HTTPS traffic must reside within the 'http' context. Therefore, the 'include /etc/nginx/conf.d/*.conf;' directive intended to load these server blocks must be placed inside the 'http' block in the main nginx.conf file. Placing it in the main context would result in syntax errors because 'server' blocks are not valid in the global context.

  4. Question 4

    Q4

    True or False: The sites-available and sites-enabled directory structure is a strict requirement enforced by the core NGINX binary for proper configuration parsing.

    Show answer & explanation

    Correct answer: B

    False. The 'sites-available' and 'sites-enabled' structure is a convention popularized by Debian/Ubuntu package maintainers to easily toggle virtual hosts via symlinks. It is not a requirement of the core NGINX binary. NGINX natively uses the 'include' directive, and standard upstream packages typically use 'conf.d/*.conf' instead.

  5. Question 5

    Q5

    During a security audit, it is discovered that NGINX worker processes are running as the 'root' user, which violates the principle of least privilege. To resolve this, the administrator needs to configure NGINX to spawn worker processes as the 'nginx' user. In which configuration context MUST the user directive be placed?

    Show answer & explanation

    Correct answer: D

    The 'user' directive defines the privileges used by worker processes and MUST be placed in the 'main' (or global) context of the nginx.conf file, outside of any other blocks like 'http' or 'events'. Placing it elsewhere will result in a configuration syntax error.

  6. Question 6

    Q6Multiple answers

    An administrator recently changed the NGINX user directive from 'root' to 'www-data'. After reloading the service, they notice several issues with the web application. Which TWO of the following symptoms are most likely caused by worker processes running as an unprivileged user without proper file system permissions? (Select TWO)

    Show answer & explanation

    Correct answers: A, C

    If the worker process runs as 'www-data', it must have read permissions on the static files and execute permissions on the directory path. If files are owned by root and lack world-read permissions, NGINX will return a 403 Forbidden error.

    Worker processes need write access to log files (if opened by the worker) or temporary directories (like proxy_temp_path). If /var/log/nginx/ or specific temporary paths are strictly owned by root, the worker process cannot write to them, causing failures or missing logs.

Register free to unlock 6 more sample questions

Create a free account to continue with the rest of the F5CANR sample set.

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 150 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon