Courseiva

F5-CTS-LTM BIG-IP Local Traffic Manager Practice Question

An LTM administrator needs to allow a specific external IP address to access a restricted management interface via a virtual server, while blocking all others. What is the most efficient way to implement this?

⚠ Common exam trap

Candidates often select packet filters or external firewalls for access control, missing that LTM-specific policies and iRules provide direct, integrated management right at the virtual server level.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use an iRule or Local Traffic Policy on the virtual server to check the source IP.

The most efficient way to control access at the BIG-IP level is using an LTM Local Traffic Policy or an iRule. While a packet filter or AFM can work, LTM-specific policies are integrated directly into the virtual server configuration. By checking the client IP address in the policy, the administrator can perform a 'drop' or 'reset' action for unauthorized traffic, ensuring high performance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Apply a packet filter to the VLAN that blocks all traffic except the specific IP.

    Why it's wrong here

    Packet filters operate at the interface or VLAN level and are global. Applying them to a VLAN affects all virtual servers on that VLAN. While effective, it lacks the granularity required to restrict access to a single specific virtual server without inadvertently impacting other services residing on the same network.

  • ✓

    Use an iRule or Local Traffic Policy on the virtual server to check the source IP.

    Why this is correct

    Using a Local Traffic Policy or an iRule allows for granular, virtual-server-specific control. By evaluating the 'client_addr' or 'IP::client_addr' value, the administrator can restrict access precisely, ensuring only the permitted IP addresses can reach the application while the configuration remains isolated from other services running on the same BIG-IP unit.

  • ✗

    Modify the pool member's firewall to allow only the BIG-IP's self IP address.

    Why it's wrong here

    This approach secures the backend server but does not prevent the unauthorized client from reaching the BIG-IP virtual server. If the goal is to block the client at the edge of the network, the security enforcement must happen on the BIG-IP, not just on the backend servers themselves.

  • ✗

    Assign a 'None' profile to the virtual server to force an error on unauthorized connections.

    Why it's wrong here

    A 'None' profile is not a security feature. It is typically used to clear or remove specific functionality from a virtual server. It provides no mechanism for evaluating client IP addresses or enforcing access control, and it would likely result in the virtual server failing to process any traffic at all.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

Courseiva writes every F5-CTS-LTM question from scratch — 119 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official F5 exam blueprint

This F5-CTS-LTM practice question is part of Courseiva's free F5 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the F5-CTS-LTM exam.