Courseiva

F5-CTS-LTM BIG-IP Local Traffic Manager Practice Question

An administrator configures a standard Virtual Server with a destination IP of 10.10.10.20:443, using a SNAT Pool instead of Auto Map. During peak hours, connections begin to fail because the SNAT pool only contains a single IP address and port exhaustion occurs. Which architectural adjustment best resolves this issue while maintaining security?

⚠ Common exam trap

Candidates often suggest replacing SNAT with direct routing or disabling it entirely during port exhaustion, compromising security policies instead of expanding the translation pool.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Add additional IP addresses to the existing SNAT pool to increase the total number of available ephemeral translation ports.

Expanding the SNAT pool by adding multiple IP addresses provides a larger translation address space and multiplies the available ephemeral port capacity per destination. This prevents port exhaustion during traffic spikes without sacrificing the controlled source IP mapping required by downstream security policies.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Switch the source address translation setting from SNAT Pool to Auto Map to leverage all available self IP addresses.

    Why it's wrong here

    Using Auto Map utilizes every floating and non-floating self IP address on the egress VLAN, which dramatically increases the pool of available source ports. However, this approach can expose unpredictable source IP addresses to backend servers, complicating firewall rules and security auditing.

  • ✗

    Increase the connection timeout profile value to allow closed connections to linger and free up sockets more gradually.

    Why it's wrong here

    Extending the idle timeout settings causes TCP connection states to remain active in memory longer. This exacerbates port exhaustion by preventing recycled ephemeral ports from becoming available for new client sessions during high-volume traffic bursts.

  • ✓

    Add additional IP addresses to the existing SNAT pool to increase the total number of available ephemeral translation ports.

    Why this is correct

    Adding more IP addresses directly scales the total translation capacity, as each IP provides approximately 64,000 source ports. This targeted mitigation preserves the defined egress IP range while successfully eliminating port exhaustion on the BIG-IP system.

  • ✗

    Configure a OneConnect profile on the virtual server to enable HTTP connection multiplexing across backend servers.

    Why it's wrong here

    OneConnect multiplexes client HTTP requests over fewer persistent server-side TCP connections, reducing backend server resource consumption. While this helps server-side port utilization, it does not directly resolve client-to-BIG-IP SNAT port exhaustion caused by high concurrent TCP sessions.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 119 original F5-CTS-LTM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official F5 exam blueprint

This F5-CTS-LTM practice question is part of Courseiva's free F5 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the F5-CTS-LTM exam.