F5-CTS-LTM BIG-IP Local Traffic Manager Practice Question
An LTM administrator needs to ensure that only encrypted traffic is accepted by a Virtual Server. Which profile should be configured?
⚠ Common exam trap
Candidates often confuse the Client SSL profile with the Server SSL profile. They forget that the Client SSL profile is what decrypts traffic coming from the client to the BIG-IP.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Client SSL profile
The Client SSL profile is required to handle incoming encrypted traffic. By assigning this profile, the BIG-IP acts as the SSL endpoint. This is a foundational concept in secure application delivery. Properly configuring SSL termination ensures that the BIG-IP can inspect the traffic for security threats and load-balance it effectively while offloading the computationally expensive decryption process from the backend application servers.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Server SSL profile
Why it's wrong here
The Server SSL profile is used for encryption between the BIG-IP and the backend server. It does not handle incoming client-side encryption. To accept encrypted client traffic, a Client SSL profile must be attached to the virtual server to terminate the SSL handshake from the client.
- ✓
Client SSL profile
Why this is correct
The Client SSL profile allows the BIG-IP to accept and decrypt incoming SSL/TLS traffic from clients. This is the mandatory configuration for any virtual server intended to serve secure content, as it establishes the secure tunnel between the client and the BIG-IP device.
- ✗
TCP profile
Why it's wrong here
A TCP profile manages transport layer settings, such as idle timeouts and congestion control. While it is necessary for all TCP-based virtual servers, it cannot handle SSL/TLS encryption or decryption. SSL functionality is exclusively managed by the specialized Client SSL and Server SSL profile types.
- ✗
HTTP profile
Why it's wrong here
The HTTP profile handles application layer settings like header manipulation and compression. It cannot decrypt or encrypt traffic. SSL/TLS is a transport-layer security feature that must be handled by an SSL profile before the traffic can be processed by the HTTP profile for application-layer inspection.
About these practice questions
One of 119 original F5-CTS-LTM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official F5 exam blueprint
This F5-CTS-LTM practice question is part of Courseiva's free F5 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the F5-CTS-LTM exam.