F5N3 Sample Questions

F5N3 Sample Questions & Answers

Five equally weighted tasks make up this one: managing NGINX connections and bandwidth, restricting access, setting up logging, configuring certificates, and turning on HTTPS along with related security settings.

Launch the full F5N3 simulator →

Showing 6 of 12 free samples.

  1. Question 1Intermediate

    Demonstrate how to manage connections and bandwidth · Limit connections to server and upstreams

    Company Alpha is running a file hosting service. They are experiencing issues where malicious users open hundreds of slow connections to tie up server resources, but each connection only downloads data at a very slow rate. The architect wants to limit the number of concurrent connections per IP address to 5.

    Which directive correctly establishes the shared memory zone required for this connection limiting?

    Show answer & explanation

    Correct answer: A

    The 'limit_conn_zone' directive is required to define the state storage for connection limiting. '$binary_remote_addr' is used as the key (which is more memory-efficient than '$remote_addr'), and 'zone=addr:10m' names the zone 'addr' and allocates 10 megabytes of shared memory.

  2. Question 2Beginner

    Demonstrate how to manage connections and bandwidth · Enable and optimize keep-alives

    True or False: The NGINX keepalive_timeout directive sets the maximum time a keep-alive client connection will stay open on the server side, and its default value is 0 (which disables keep-alives).

    Show answer & explanation

    Correct answer: B

    False. While a value of 0 does disable keep-alive client connections, the default value in NGINX OSS is 75 seconds, not 0. Keep-alives are enabled by default.

  3. Question 3Intermediate

    Demonstrate how to manage connections and bandwidth · Set a bandwidth limit

    An administrator needs to enforce a dynamic bandwidth limit. Clients authenticating as 'premium' users should have no bandwidth limit (0), while 'standard' users should be limited to 100k per second. The user type is extracted to a variable named $user_bandwidth_limit.

    Which directive correctly applies this dynamic limit in a location block?

    Show answer & explanation

    Correct answer: D

    The 'limit_rate' directive supports the use of variables (since version 1.17.0). By passing the variable '$user_bandwidth_limit' (which would evaluate to '0' for premium and '100k' for standard), NGINX dynamically throttles the bandwidth per request.

  4. Question 4Beginner

    Demonstrate how to manage connections and bandwidth · Rate limiting vs bandwidth throttling

    What is the primary difference between rate limiting (limit_req) and bandwidth throttling (limit_rate) in NGINX?

    Show answer & explanation

    Correct answer: B

    Rate limiting (limit_req) uses the leaky bucket algorithm to control the frequency of incoming requests (e.g., 5 requests per second). Bandwidth throttling (limit_rate) limits the byte transmission speed of the response to the client (e.g., 500 kilobytes per second).

  5. Question 5Intermediate

    Demonstrate how to manage connections and bandwidth · Limit connections to server and upstreams

    A high-traffic e-commerce site experiences a DDoS attack. The architect decides to implement connection limiting. They configure limit_conn_zone $binary_remote_addr zone=perip:10m; in the http block.

    In the server block, they apply limit_conn perip 10;.

    What happens to the 11th concurrent connection from the same IP address?

    Show answer & explanation

    Correct answer: B

    By default, when the limit set by 'limit_conn' is exceeded, NGINX rejects the request and returns a 503 Service Unavailable HTTP status code to the client. This can be customized using the 'limit_conn_status' directive.

  6. Question 6Beginner

    Demonstrate how to restrict access · Restrict by IP address

    An administrator configures the following access control list for an internal dashboard:

    location /admin {
    deny 192.168.1.50;
    allow 192.168.1.0/24;
    deny all;
    }

    A request arrives from IP address 192.168.1.50. How does NGINX handle this request?

    Show answer & explanation

    Correct answer: B

    NGINX evaluates 'allow' and 'deny' directives sequentially in the order they are written. As soon as a match is found, NGINX stops processing the list. Since 'deny 192.168.1.50' is first, it matches immediately and access is denied.

Ready for the real thing?

The full F5N3 simulator has every exam-style question, timed mode, and instant scoring.

Go to the F5N3 simulator →