Free Practice Questions for Akamai App & API Protector
Exam-style questions and explanations by OpenExamPrep.
Loading practice questions...
Explore More Akamai Certifications
Continue into nearby exams from the same family. Each card keeps practice questions, study guides, flashcards, videos, and articles in one place.
Key Facts: Akamai App & API Protector Exam
~60
Exam Questions
Akamai
~70%
Passing Score
Akamai
90 min
Exam Duration
Akamai
~$300
Exam Fee
Akamai
2 years
Certification Validity
Akamai
100
Practice Questions
OpenExamPrep
Approximately 60 questions in 90 minutes, ~70% passing score, ~$300 fee. Key domains: WAF Rules & Policy Management (25-30%), Bot Management (20-25%), DDoS & Rate Controls (20-25%), API Security (15-20%), and Origin Protection (10-15%). Certification valid for 2 years. Available online proctored.
Sample Akamai App & API Protector Practice Questions
Try these sample questions to review concepts for the Akamai App & API Protector exam. Each question includes a detailed explanation. Start the interactive quiz above for the full 100+ question experience with AI tutoring.
1What is the primary function of Akamai App & API Protector's WAF component?
2In Akamai App & API Protector, what does 'evaluation mode' allow security teams to do?
3Which Akamai feature uses behavioral analysis to distinguish automated bot traffic from legitimate human users?
4A customer notices that a legitimate third-party monitoring tool is being blocked by App & API Protector. Which configuration option should they use to resolve this without disabling bot management globally?
5What is the purpose of Akamai's rate controls feature in App & API Protector?
6In the Akamai security model, what does 'Kona' refer to within App & API Protector?
7Which of the following best describes an Akamai 'custom rule' in App & API Protector?
8What is the role of Akamai's 'network list' feature in App & API Protector?
9How does Akamai App & API Protector protect against DDoS attacks at the application layer (Layer 7)?
10What does Akamai's EdgeScape service provide that is useful in security policies?
About the Akamai App & API Protector Exam
The Akamai Certified — App & API Protector exam validates expertise in Akamai's WAAP platform, covering WAF rule management, bot detection, Layer 7 DDoS protection, rate controls, API security, and origin protection. It is the successor to the Kona Site Defender certification.
Exam sponsor: Akamai Technologies. The requirements and fees below concern the certification or admission exam, separate from our free practice resources.
Questions
60 questions
Time Limit
90 minutes
Passing Score
~70%
Reported exam pass rate: ~65-75%. for well-prepared candidates (industry estimate) This describes exam candidates, not OpenExamPrep users or results from using our resources. Exam sponsor website
Fees, eligibility, and exam policies can change. Confirm them with the exam sponsor before applying or paying.
Our practice resources: topics covered
We aim to reflect publicly available exam outlines and topic information in our study resources. Coverage, format, and difficulty may differ from the actual exam, and we cannot guarantee that every detail is accurate or current. Confirm exam requirements, fees, and policies with the official exam sponsor.
WAF Rules and Policy Management
Kona Rule Set (KRS), custom rules, match conditions, attack group scoring, evaluation mode vs. deny mode, false positive tuning, managed threat intelligence updates, security configurations and policies
Bot Management
Akamai Bot Manager, known-bot classification and categories, behavioral analysis, JavaScript challenges, CAPTCHA, client reputation, bot exception lists, credential stuffing mitigation
DDoS Protection and Rate Controls
Layer 7 DDoS mitigation (HTTP floods, slow POST), rate control thresholds, time-window throttling, Prolexic comparison (L3/L4 vs. L7), volumetric and application-layer attack handling
API Security and Advanced Features
API discovery, shadow/zombie API identification, WAAP concepts, OWASP API Security Top 10, schema validation, Page Integrity Manager for Magecart protection, Adaptive Security Engine
Origin Protection and Monitoring
SiteShield origin IP protection, IP reputation feeds, network lists, EdgeScape geolocation, DataStream 2 SIEM export, Security Center analytics dashboard
Preparing for the Akamai App & API Protector Exam
What You Need to Know
- Passing score: ~70%
- Exam length: 60 questions
- Time limit: 90 minutes
- Exam / certification fees: ~$300 Official sources
Using Our Practice Resources
- Work through all 100 available questions
- Review every answer and explanation
- Track weak areas and revisit them
- Use our AI tutor for tough concepts
Akamai App & API Protector: Suggested Study Strategy
Frequently Asked Questions
What is Akamai App & API Protector?
App & API Protector is Akamai's unified Web Application and API Protection (WAAP) platform that evolved from Kona Site Defender. It provides WAF protection using the Kona Rule Set, bot management with behavioral analysis, Layer 7 DDoS mitigation, rate controls, API discovery and protection, and origin protection through SiteShield.
What is the Kona Rule Set (KRS)?
The Kona Rule Set is Akamai's managed WAF rule engine inherited from Kona Site Defender. It includes continuously updated attack definitions for OWASP Top 10 attacks (SQL injection, XSS, RFI, path traversal, RCE), organized into attack groups with configurable scoring thresholds. Akamai's threat intelligence team updates KRS automatically without customer action.
What is evaluation mode in App & API Protector?
Evaluation mode allows security teams to stage new rules or policy changes in shadow mode — requests are logged and scored but not blocked. This enables teams to assess false-positive impact before promoting rules to deny mode, preventing service disruption during policy tuning.
What is SiteShield?
SiteShield restricts access to the customer origin server to only Akamai's designated edge IP ranges. This prevents attackers who discover the origin IP from sending requests directly, bypassing the WAF. SiteShield is implemented by configuring origin server firewall rules to only accept connections from Akamai's SiteShield IP list.
How does Akamai Bot Manager classify bots?
Akamai Bot Manager uses behavioral signals, device fingerprinting, JavaScript challenge-response, and its global threat intelligence to classify traffic as human, known bot (categorized by type: search engine, monitoring, ad network), or unknown/suspicious bot. Per-category actions (allow, monitor, deny, challenge) are configured in security policies.
What is DataStream 2?
Akamai DataStream 2 delivers structured security event logs from App & API Protector to external destinations in near real-time — including Splunk, Sumo Logic, Amazon S3, Azure Blob Storage, and other SIEM/analytics platforms. It replaces older log delivery mechanisms with lower latency and richer structured data.