A10-CPSA-4 Sample Questions & Answers
Free A10 Certified Professional System Administration 4 practice questions with worked answers and explanations. See how the ExamJungle simulator prepares you — then jump into the full test.
Launch the full A10-CPSA-4 simulator →Showing 6 of 12 free samples.
- Question 1Advanced
aXAPI Overview · aXAPI Authentication and Authorization
An administrator is using the aXAPI to automate the deployment of new virtual servers. After a successful login and receiving a signature, subsequent POST requests to
/axapi/v3/slb/virtual-serverare failing with an HTTP 403 Forbidden error. The same administrator account can create virtual servers via the GUI and CLI. What is the most likely cause of this issue?Show answer & explanation
Correct answer: B
A 403 Forbidden error indicates that the server understood the request but refuses to authorize it. This is a permissions issue, not an authentication issue (which would be a 401 Unauthorized). ACOS maintains separate privilege sets for different management interfaces. It is possible for a role to have write access in the GUI and CLI but be denied access to the corresponding aXAPI endpoints. The administrator needs to verify the RBAC configuration for aXAPI access.
- Question 2Beginner
Centralized Configuration Management (aVCS) · aVCS Failure Scenarios
True or False: In an ACOS 4.x aVCS environment, if a vBlade loses network connectivity to the vMaster but remains operational, it will immediately reboot to attempt to rejoin the chassis.
Show answer & explanation
Correct answer: B
This is false. If a vBlade loses connectivity to the vMaster, it enters a standalone state. It will continue to process traffic based on its last known configuration but will cease to receive updates from the vMaster. It does not automatically reboot. An administrator must intervene to troubleshoot the connectivity issue and manually reintegrate the vBlade into the aVCS cluster.
- Question 3Intermediate
Initial ACOS Configuration · Changes to Default Behavior
A system administrator observes that after upgrading from ACOS 4.0 to 4.1.4, the default behavior of the WAF
sql-checkfeature has changed. What is the key difference in behavior for this feature in ACOS 4.1.4 and later?Show answer & explanation
Correct answer: A
According to the ACOS 4.x documentation, a key change in default behavior is that the WAF 'sql-check' feature, which previously checked cookies for malicious SQL keywords, no longer does so in release 4.1.4 and later. This change was made to reduce false positives and improve performance.
- Question 4Intermediate
Role-based Administration · Custom Role Creation
A new role, 'SSL-Admin', has been created for a team that manages SSL certificates. This role should only allow users to import, view, and delete SSL certificates and keys, and bind them to SSL templates. Which is the most effective way to configure this role while adhering to the principle of least privilege?
Show answer & explanation
Correct answer: D
ACOS provides a granular Role-Based Administration framework. The principle of least privilege dictates that a user should only have the exact permissions necessary to perform their job. Creating a custom role and assigning specific, narrow privileges for SSL-related objects is the most secure and effective method.
- Question 5Advanced
Application Delivery Partitions (ADP) · L3V Object Management
Case Study
Company Background:
SecureCloud Hosting provides managed infrastructure for various clients. They use a large A10 Thunder ADC appliance running ACOS 4.x, heavily leveraging L3V partitions to provide isolated environments for each customer. Each L3V partition has its own routing table, interfaces, and application delivery objects. Customer 'Alpha' and customer 'Bravo' have both been assigned the same private IP address space (10.1.1.0/24) within their respective L3V partitions,alpha-prodandbravo-prod.Current Situation:
An administrator from customer 'Alpha' needs to set up a new GSLB service. As part of this, they need to create an SNMP health monitor to check the status of a server at 10.1.1.50. However, when they create thehealth monitorobject within theiralpha-prodpartition, administrators for the 'Bravo' partition report that their monitoring is now failing for an unrelated service. Investigation shows that the new health monitor from thealpha-prodpartition is somehow being used by a service in thebravo-prodpartition.Requirements:
The CTO requires a solution that guarantees strict isolation of common objects like health monitors between L3V partitions. A health monitor created in one partition must not be visible or usable in another partition unless explicitly shared by a system-level administrator. The solution must prevent accidental cross-partition object usage.Architectural Diagram:
+---------------- ACOS Appliance ----------------+ ¦ ¦ ¦ +-- L3V: alpha-prod --+ +-- L3V: bravo-prod --+ ¦ ¦ ¦ ¦ ¦ ¦ ¦ ¦ ¦ [VIP: 203.0.113.10] ¦ ¦ [VIP: 203.0.113.20] ¦ ¦ ¦ ¦ [Server: 10.1.1.50] ¦ ¦ [Server: 10.1.1.100] ¦ ¦ ¦ ¦ [HealthMon: alpha-hm] ¦ ¦ [HealthMon: bravo-hm] ¦ ¦ ¦ ¦ ¦ ¦ ¦ ¦ ¦ +-----------------------+ +-----------------------+ ¦ ¦ ¦ ¦ [Shared Partition Management] ¦ +------------------------------------------------+Which configuration setting is the root cause of this issue and how should it be corrected?
Show answer & explanation
Correct answer: B
By default, some objects like health monitors in ACOS are created as global objects, making them visible across all partitions. This can lead to naming conflicts and unintended sharing. The root cause is that the health monitor was not explicitly defined as private to its partition. The solution is to delete the existing monitor and recreate it using the
partition-privateoption, which ensures it is only accessible within the partition it was created in. - Question 6Intermediate
Initial ACOS Configuration · aFleX Migration Limitations
What is a key limitation of the
RESOLVE::lookupcommand in aFleX scripts on ACOS 4.x?Show answer & explanation
Correct answer: A
According to ACOS documentation on aFlex migration limitations, the
RESOLVE::lookupcommand, while enhanced for TCP-Proxy ports, has a specific limitation where it does not support being called within theCLIENT_ACCEPTEDandCLIENT_DATAevents for virtual ports of type HTTP or HTTPS. This is a critical consideration when designing aFleX scripts that perform DNS lookups early in the TCP connection lifecycle for HTTP-based services.
Ready for the real thing?
The full A10-CPSA-4 simulator has every exam-style question, timed mode, and instant scoring.