Courseiva

F5-CTS-LTM BIG-IP Local Traffic Manager Practice Question

An administrator needs to modify the HTTP response header to hide the server version for security reasons. Which tool is most appropriate?

⚠ Common exam trap

Candidates often select the wrong iRule event, such as 'HTTP_REQUEST' instead of 'HTTP_RESPONSE', which prevents the BIG-IP from intercepting the header before it is delivered to the client.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

An iRule in the 'HTTP_RESPONSE' event with 'HTTP::header remove Server'.

An iRule using the 'HTTP_RESPONSE' event is the most flexible way to modify headers. Using the 'HTTP::header remove' command, an administrator can strip sensitive version information from the 'Server' header before the response reaches the client. This is a common security hardening task that prevents potential attackers from fingerprinting the backend server version and identifying known vulnerabilities associated with that specific platform.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A Local Traffic Policy with a 'header' modify action.

    Why it's wrong here

    While policies can modify some header information, they are generally less flexible than iRules for complex header manipulation logic. For stripping specific version strings from a dynamic header, an iRule provides the granular, programmatic control necessary to ensure the security requirement is met precisely and reliably across all responses.

  • ✓

    An iRule in the 'HTTP_RESPONSE' event with 'HTTP::header remove Server'.

    Why this is correct

    This iRule is the industry-standard way to remove the 'Server' header. By acting in the 'HTTP_RESPONSE' event, the LTM processes the response as it returns from the backend, allowing the BIG-IP to strip the sensitive version information before the final response is delivered to the end-user client.

  • ✗

    A customized HTTP profile that blocks the 'Server' header.

    Why it's wrong here

    Standard HTTP profiles do not have a feature to 'block' specific headers by name. While they control many HTTP behaviors, header manipulation is not a native checkbox or field configuration within the standard profile settings, requiring more advanced logic provided by either policies or custom-coded iRules.

  • ✗

    A custom monitor with 'header-strip' enabled.

    Why it's wrong here

    Custom monitors are used for checking service health, not for modifying the traffic that passes through the BIG-IP. A monitor does not sit in the traffic flow and therefore cannot alter the headers of the application response sent back to the client, making this approach completely ineffective.

About these practice questions

Courseiva writes every F5-CTS-LTM question from scratch — 119 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official F5 exam blueprint

This F5-CTS-LTM practice question is part of Courseiva's free F5 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the F5-CTS-LTM exam.