F5CANR Sample Questions

F5CANR Sample Questions & Answers

Demonstrating how to manage connections and bandwidth, restrict access, and configure logging carries the most weight, alongside NGINX permissions and directory structure, setting up load-balancing, caching, and web-serving roles, and TLS troubleshooting.

Launch the full F5CANR simulator →

Showing 6 of 12 free samples.

  1. Question 1Beginner

    NGINX Management · Explain the NGINX configuration directory structure

    True or False: The sites-available and sites-enabled directory structure is a strict requirement enforced by the core NGINX binary for proper configuration parsing.

    Show answer & explanation

    Correct answer: B

    False. The 'sites-available' and 'sites-enabled' structure is a convention popularized by Debian/Ubuntu package maintainers to easily toggle virtual hosts via symlinks. It is not a requirement of the core NGINX binary. NGINX natively uses the 'include' directive, and standard upstream packages typically use 'conf.d/*.conf' instead.

  2. Question 2Intermediate

    NGINX Management · Demonstrate how to manage user permissions

    During a security audit, it is discovered that NGINX worker processes are running as the 'root' user, which violates the principle of least privilege. To resolve this, the administrator needs to configure NGINX to spawn worker processes as the 'nginx' user. In which configuration context MUST the user directive be placed?

    Show answer & explanation

    Correct answer: B

    The 'user' directive defines the privileges used by worker processes and MUST be placed in the 'main' (or global) context of the nginx.conf file, outside of any other blocks like 'http' or 'events'. Placing it elsewhere will result in a configuration syntax error.

  3. Question 3IntermediateSelect 2

    NGINX Management · Demonstrate how to manage user permissions

    An administrator recently changed the NGINX user directive from 'root' to 'www-data'. After reloading the service, they notice several issues with the web application. Which TWO of the following symptoms are most likely caused by worker processes running as an unprivileged user without proper file system permissions? (Select TWO)

    Show answer & explanation

    Correct answers: B, E

    If the worker process runs as 'www-data', it must have read permissions on the static files and execute permissions on the directory path. If files are owned by root and lack world-read permissions, NGINX will return a 403 Forbidden error.

    Worker processes need write access to log files (if opened by the worker) or temporary directories (like proxy_temp_path). If /var/log/nginx/ or specific temporary paths are strictly owned by root, the worker process cannot write to them, causing failures or missing logs.

  4. Question 4Beginner

    NGINX Management · Demonstrate how to manage user permissions

    A developer uploaded a new batch of images to the /var/www/html/images directory as the 'root' user. NGINX worker processes are running as the 'nginx' user. Visitors are now seeing 403 Forbidden errors when trying to load these new images. Which Linux command should the administrator use to grant the NGINX worker processes ownership of these files?

    Show answer & explanation

    Correct answer: D

    The 'chown' (change owner) command is used to change the user and group ownership of files. Using 'chown -R nginx:nginx' recursively changes the ownership to the nginx user and group, allowing the worker processes to read the files. Using chmod 777 is a severe security risk, and adding the nginx user to the root group violates least privilege.

  5. Question 5Advanced

    NGINX Management · Manage shared memory zones

    An administrator is configuring a rate-limiting zone using limit_req_zone. They expect to track up to 160,000 unique IP addresses simultaneously. Assuming a 64-bit platform where the state information per IP address consumes roughly 128 bytes, what is the MINIMUM recommended size they should allocate for the shared memory zone to prevent memory exhaustion?

    Show answer & explanation

    Correct answer: D

    In NGINX, a 1-megabyte zone can keep around 16,000 states on a 64-bit platform (or 8,000 depending on exact key size, but the standard rule of thumb is 16k). To track 160,000 unique IP addresses, you need approximately 160,000 / 16,000 = 10 megabytes. Therefore, '10m' is the correct minimum size.

  6. Question 6Intermediate

    NGINX Management · Manage shared memory zones

    To limit the number of concurrent connections per client IP address, an administrator must first define a shared memory zone. Which of the following is the correct syntax to define a 10-megabyte connection limiting zone named 'limitperip' based on the client's binary IP address?

    Show answer & explanation

    Correct answer: A

    This is the correct syntax. The 'limit_conn_zone' directive requires the key (in this case, '$binary_remote_addr' which is more memory-efficient than '$remote_addr') followed by the 'zone=' parameter defining the name ('limitperip') and the size ('10m').

Ready for the real thing?

The full F5CANR simulator has every exam-style question, timed mode, and instant scoring.

Go to the F5CANR simulator →