F5-CTS-LTM BIG-IP Local Traffic Manager Practice Question
An LTM administrator needs to ensure that client SSL traffic is offloaded at the BIG-IP while maintaining end-to-end encryption to the backend servers. Which profile configuration is required to achieve this?
⚠ Common exam trap
Candidates frequently forget the Server SSL profile, assuming that client-side decryption is enough, which would leave the traffic unencrypted between the BIG-IP and the backend server.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Assign both a Client SSL profile and a Server SSL profile to the virtual server.
To achieve SSL offloading with backend encryption, the LTM must terminate the client-side SSL using a Client SSL profile and then initiate a new SSL connection to the server using a Server SSL profile. This architecture, known as SSL Bridging, is critical for organizations needing to perform deep packet inspection or Layer 7 load balancing while maintaining security compliance protocols between the load balancer and the internal server pool members.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Apply only a Client SSL profile to the virtual server.
Why it's wrong here
Applying only a Client SSL profile results in SSL termination at the BIG-IP, but the traffic from the BIG-IP to the backend server is sent in cleartext. This violates the requirement for end-to-end encryption and leaves the internal network segment vulnerable to packet sniffing and data interception.
- ✗
Configure a FastL4 profile with SSL persistence enabled.
Why it's wrong here
FastL4 profiles operate at Layer 4 and do not support SSL termination or inspection capabilities. Enabling SSL persistence on a FastL4 virtual server does not facilitate decryption or re-encryption, rendering it incapable of performing the requested SSL bridging task required for secure application delivery within the BIG-IP infrastructure.
- ✓
Assign both a Client SSL profile and a Server SSL profile to the virtual server.
Why this is correct
Assigning both profiles enables SSL Bridging. The Client SSL profile decrypts the incoming request, allowing the LTM to inspect or modify the payload. The Server SSL profile then encrypts the request before forwarding it to the backend server, ensuring security is maintained across the entire path of the transaction.
- ✗
Disable the Client SSL profile and enable a Server SSL profile only.
Why it's wrong here
Disabling the Client SSL profile forces the BIG-IP to treat the incoming traffic as opaque encrypted data. Without decryption, the BIG-IP cannot perform Layer 7 load balancing or iRules processing. Furthermore, only enabling a Server SSL profile would not permit the decryption of client-side traffic for inspection.
About these practice questions
Courseiva writes every F5-CTS-LTM question from scratch — 119 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official F5 exam blueprint
This F5-CTS-LTM practice question is part of Courseiva's free F5 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the F5-CTS-LTM exam.