Courseiva

F5-CTS-LTM BIG-IP Local Traffic Manager Practice Question

An administrator needs to ensure that client SSL traffic is terminated at the BIG-IP LTM while maintaining persistence based on a specific session cookie. Which profile combination correctly enables this functionality?

⚠ Common exam trap

Candidates often confuse Server SSL with Client SSL, or select generic fallback profiles like HTTP instead of explicitly combining the Client SSL profile with the Cookie Persistence profile required for application-layer stickiness.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Client SSL profile and Cookie Persistence profile

To terminate SSL, a Client SSL profile must be assigned to the Virtual Server. To persist based on a cookie, a Cookie Persistence profile must be enabled. This combination is standard for web applications requiring secure transport and session stickiness. Understanding this architecture is vital because the LTM must decrypt traffic to inspect and insert the persistence cookie, allowing the BIG-IP to make intelligent load-balancing decisions based on application-layer data.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Server SSL profile and Source Address Affinity profile

    Why it's wrong here

    Server SSL profiles encrypt traffic from the BIG-IP to the backend server, not the client. Source Address Affinity persists based on the client IP address rather than application-layer session cookies. This combination fails to provide the required decryption for cookie inspection and lacks the requested application-specific persistence mechanism.

  • ✗

    Client SSL profile and Source Address Affinity profile

    Why it's wrong here

    While the Client SSL profile correctly terminates the connection, Source Address Affinity uses the client IP address for persistence. This does not fulfill the requirement of using a session cookie, which is necessary when multiple users share the same public IP address or NAT device.

  • ✓

    Client SSL profile and Cookie Persistence profile

    Why this is correct

    The Client SSL profile decrypts the incoming traffic, allowing the LTM to read and insert session cookies. The Cookie Persistence profile enables the LTM to track the specific session identifier, ensuring the client remains connected to the same backend pool member throughout the session duration.

  • ✗

    Server SSL profile and Cookie Persistence profile

    Why it's wrong here

    A Server SSL profile does not decrypt incoming client traffic; it only manages the backend encryption. Without a Client SSL profile, the BIG-IP cannot decrypt the payload to read or insert the persistence cookie, rendering the Cookie Persistence profile ineffective for incoming traffic from the client.

About these practice questions

Courseiva writes every F5-CTS-LTM question from scratch — 119 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official F5 exam blueprint

This F5-CTS-LTM practice question is part of Courseiva's free F5 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the F5-CTS-LTM exam.