F5 · Free Practice Questions · Last reviewed May 2026
6real exam-style questions organised by domain, each with the correct answer highlighted and a plain-English explanation of why it's right — and why the others are wrong.
An LTM Specialist is troubleshooting a virtual server where health monitors are failing despite the backend servers responding to ICMP. The health monitor is configured for HTTPS. Which TWO items should the specialist verify to ensure the monitor accurately reflects service availability?
The cipher suite compatibility between the BIG-IP and the pool member.
The BIG-IP must support the TLS ciphers enabled on the backend server. If the monitor attempts to negotiate a protocol or cipher that the server does not support, the handshake fails immediately, causing the monitor to mark the pool member as down regardless of application status.
The ICMP timeout value on the internal VLAN interface.
The 'Receive String' configured in the HTTPS monitor.
The receive string is the expected content the BIG-IP looks for in the HTTP response body. If the application returns a custom error page instead of the expected data, the monitor will mark the server down, protecting users from being sent to a broken service instance.
The persistence profile assigned to the virtual server.
The SNAT pool associated with the virtual server.
Refer to the exhibit. The LTM Specialist discovers that the HTTPS monitor is failing. The server logs indicate that the requests are reaching the web server, but the server is returning a 400 Bad Request error. What is the most likely cause?
The BIG-IP is using the wrong SSL profile for the monitor.
The Host header in the send string does not match the server's expected virtual host.
When using HTTP/1.1, the Host header is mandatory. If the server expects a specific host header value but receives 'example.com', it will reject the request with a 400 status. The monitor must be updated to match the hostname configured on the backend web server.
The monitor is missing a 'Receive String' definition.
The monitor is using the wrong HTTP method.
Which BIG-IP feature allows an LTM Specialist to perform granular inspection and modification of HTTP traffic headers before they reach the backend server?
Local Traffic Policy
iRules
iRules provide the most flexibility for inspecting and modifying traffic headers. By attaching an iRule to a virtual server, you can trigger logic on HTTP_REQUEST events, allowing for complex manipulation of headers, cookies, or path data, which is crucial for modern, dynamic web application delivery.
Persistence Profile
FastL4 Profile
A client is experiencing intermittent connection resets when accessing a virtual server. The LTM Specialist observes that the backend servers are occasionally overwhelmed during traffic spikes. Which feature should be implemented to mitigate this impact on the backend servers?
Increase the idle timeout in the TCP profile.
Enable Connection Limits on the pool members.
Setting connection limits ensures that a pool member will not be selected by the load balancing algorithm once its maximum concurrent connection threshold is reached. This is the standard method for managing server capacity and preventing service outages during high-demand events or traffic spikes.
Configure a SNAT pool with more IP addresses.
Change the load balancing method to Least Connections.
An LTM Specialist needs to configure a virtual server to handle both HTTP and HTTPS traffic on the same IP address. Which THREE steps are required to implement this? (Select THREE)
Create two virtual servers using the same virtual IP address.
The BIG-IP allows multiple virtual servers to share the same IP address provided they listen on different ports. One for port 80 and one for port 443 is the standard configuration for hosting dual-protocol services on a single VIP address, simplifying client-side DNS management.
Assign a Client SSL profile to the HTTPS virtual server.
An HTTPS virtual server must have a Client SSL profile to terminate the TLS connection from the client. Without this profile, the BIG-IP cannot decrypt the inbound HTTPS traffic, and therefore cannot perform content inspection or load balancing based on HTTP headers.
Assign the same pool to both virtual servers.
Using the same pool for both virtual servers ensures that the backend servers receive the same traffic flow regardless of whether the client connected via HTTP or HTTPS. This creates a unified application backend and simplifies the management of server availability and health status.
Configure a single virtual server with a wildcard port.
Disable the HTTP profile on the HTTPS virtual server.
Refer to the exhibit. The virtual server is showing client-side traffic but no server-side traffic. What is the most likely reason?
The virtual server is configured with an incorrect destination IP address.
All pool members are currently marked down by health monitors.
If all pool members are down, the BIG-IP will refuse or reset connections because it has no destination to forward traffic to. The client-side stats increase because the VIP receives the packet, but no server-side connections are opened, which matches the exhibit showing zero server-side traffic.
The client is sending traffic that does not match the HTTP profile.
The BIG-IP is configured with an incorrect default gateway.
Want more BIG-IP Local Traffic Manager practice?
Practice this domainThe F5-CTS-LTM exam has 60–90 questions and must be completed in 120 minutes. The passing score is 700/1000.
Scenario-based questions covering exam objectives with detailed answer explanations.
The exam covers 1 domain: BIG-IP Local Traffic Manager. Questions are weighted by domain — higher-weight domains appear more on your actual exam.
No. These are original exam-style practice questions written against the official F5 F5-CTS-LTM exam objectives. They are not copied from the real exam. Courseiva focuses on genuine understanding, not memorisation of braindumps.
Courseiva tracks your accuracy per domain and routes you toward weak areas automatically. Free, no account required.