F5-CTS-LTM BIG-IP Local Traffic Manager Practice Question
An LTM administrator is configuring a new virtual server and needs to ensure that only specific source networks can access the application. Which TWO methods can be used to restrict access?
⚠ Common exam trap
Test-takers often look for traditional firewall rule options, forgetting that LTM features like iRules and Local Traffic Policies handle source address filtering directly.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure an iRule in the CLIENT_ACCEPTED event to drop connections from unauthorized IPs.
Restricting access is a fundamental security requirement for LTM deployments. Using either an iRule to drop unauthorized connections or a Local Traffic Policy is a standard security practice. These methods provide granular control, allowing administrators to filter traffic based on source IP, CIDR blocks, or other criteria before the request is processed by the pool, effectively mitigating unauthorized access at the network edge.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Configure an iRule in the CLIENT_ACCEPTED event to drop connections from unauthorized IPs.
Why this is correct
The 'CLIENT_ACCEPTED' event is the perfect place to enforce IP-based security. By checking 'IP::client_addr' and using the 'drop' command, the BIG-IP terminates unauthorized connections before any further resources are consumed, providing an efficient and secure way to implement access control lists directly within the traffic flow.
- ✗
Set the virtual server type to 'Forwarding (IP)'.
Why it's wrong here
A 'Forwarding (IP)' virtual server is used to route packets without load balancing or processing. It does not provide any mechanism to filter traffic based on source IPs and would simply pass all traffic, completely defeating the purpose of implementing security access controls for the application.
- ✓
Apply a Local Traffic Policy with a 'drop' action for disallowed source addresses.
Why this is correct
Local Traffic Policies offer a declarative, GUI-driven approach to traffic management. Defining a policy rule that matches specific source IP conditions and triggers a 'drop' action is a supported and efficient way to enforce network-level security without the complexity of managing custom scripts or iRule code.
- ✗
Assign a FastL4 profile to the virtual server to block unwanted traffic.
Why it's wrong here
A FastL4 profile is designed for high-performance transport layer switching. While it is efficient, it does not have built-in capabilities to filter traffic based on source IP address criteria in the way that iRules or policies do. It focuses on protocol acceleration, not security access control.
- ✗
Increase the 'Idle Timeout' value in the TCP profile.
Why it's wrong here
The TCP profile's 'Idle Timeout' setting dictates how long an inactive connection remains open. It has no role in access control or filtering traffic based on source addresses. Adjusting this setting will not prevent unauthorized connections, as it is strictly used for connection state management and cleanup.
Visual reference
About these practice questions
One of 119 original F5-CTS-LTM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official F5 exam blueprint
This F5-CTS-LTM practice question is part of Courseiva's free F5 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the F5-CTS-LTM exam.