F5-CTS-LTM BIG-IP Local Traffic Manager Practice Question
An administrator is configuring a new virtual server and needs to ensure that it only accepts traffic on a specific VLAN. How should this be configured?
⚠ Common exam trap
Many test-takers confuse virtual server VLAN restrictions with SNAT settings or self-IP configurations, incorrectly assuming that assigning a self-IP automatically restricts virtual server traffic to that specific VLAN.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
By modifying the 'Enabled VLANs and Tunnels' setting in the virtual server properties.
Configuring VLAN-specific access for a virtual server is done within the 'Resources' or 'Configuration' tab of the virtual server settings. By default, a virtual server listens on all enabled VLANs. Restricting this to a single VLAN enhances security by preventing unauthorized traffic from other network segments from reaching the virtual server and potentially exposing the application to unnecessary risk.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
By applying a packet filter to the virtual server object in the GUI.
Why it's wrong here
While packet filters can restrict traffic, they are not applied directly to the virtual server object itself. Packet filters are applied at the VLAN level or as a global security policy. Using the virtual server's built-in VLAN list is the intended and most direct method for managing ingress traffic per virtual server.
- ✓
By modifying the 'Enabled VLANs and Tunnels' setting in the virtual server properties.
Why this is correct
The BIG-IP virtual server configuration includes a specific setting to control which VLANs are allowed to access it. By selecting 'Enabled on all VLANs' or explicitly choosing the required VLANs, the administrator can effectively isolate traffic access, ensuring that the service is only exposed where it is intended to be reachable.
- ✗
By adding a static route in the routing table for that VLAN.
Why it's wrong here
Static routes dictate the path for outgoing traffic, not the ingress accessibility of a virtual server. Modifying the routing table will not restrict which traffic hits the virtual server; it only determines how the BIG-IP forwards packets to a destination network. This is not the correct configuration for ingress security.
- ✗
By creating a SNAT pool that only contains IPs from the specific VLAN.
Why it's wrong here
SNAT deals with source address translation for egress traffic from the BIG-IP to the backend servers. It has no bearing on which clients are allowed to connect to the virtual server in the first place, and therefore cannot be used to restrict ingress traffic access to a specific VLAN.
Visual reference
About these practice questions
This F5-CTS-LTM question is part of Courseiva's 119-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official F5 exam blueprint
This F5-CTS-LTM practice question is part of Courseiva's free F5 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the F5-CTS-LTM exam.