F5-CTS-LTM BIG-IP Local Traffic Manager Practice Question
An LTM Specialist is troubleshooting a virtual server where health monitors are failing despite the backend servers responding to ICMP. The health monitor is configured for HTTPS. Which TWO items should the specialist verify to ensure the monitor accurately reflects service availability?
⚠ Common exam trap
Candidates often rely solely on basic TCP or ICMP success, forgetting that HTTPS monitors require valid cipher matching and exact receive strings to validate application health.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The cipher suite compatibility between the BIG-IP and the pool member.
When HTTPS monitors fail despite successful ICMP responses, the issue usually involves TLS handshake failures or application-layer response mismatches. Checking the cipher compatibility ensures the BIG-IP and server can establish a secure connection. Verifying the receive string is vital because a 200 OK status code does not guarantee the application is actually functional; the BIG-IP must receive the expected content within the response body to confirm service health.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The cipher suite compatibility between the BIG-IP and the pool member.
Why this is correct
The BIG-IP must support the TLS ciphers enabled on the backend server. If the monitor attempts to negotiate a protocol or cipher that the server does not support, the handshake fails immediately, causing the monitor to mark the pool member as down regardless of application status.
- ✗
The ICMP timeout value on the internal VLAN interface.
Why it's wrong here
ICMP is a layer 3 protocol used for reachability testing. Adjusting ICMP timeouts does not impact HTTPS monitor behavior, which operates at layer 7. If the server responds to pings, the network path is likely fine, but the service itself might be misconfigured or blocked.
- ✓
The 'Receive String' configured in the HTTPS monitor.
Why this is correct
The receive string is the expected content the BIG-IP looks for in the HTTP response body. If the application returns a custom error page instead of the expected data, the monitor will mark the server down, protecting users from being sent to a broken service instance.
- ✗
The persistence profile assigned to the virtual server.
Why it's wrong here
Persistence profiles control how client sessions are mapped to backend servers after the initial connection. They have no impact on the health monitor's ability to check the status of pool members, as monitors operate independently of the client-side load balancing and session affinity logic.
- ✗
The SNAT pool associated with the virtual server.
Why it's wrong here
SNAT is used for return traffic routing from the pool member back through the BIG-IP. While essential for traffic flow, the health monitor initiates its own connection; if it cannot reach the server, it is usually due to authentication, SSL, or response content mismatches.
About these practice questions
This F5-CTS-LTM question is part of Courseiva's 119-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official F5 exam blueprint
This F5-CTS-LTM practice question is part of Courseiva's free F5 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the F5-CTS-LTM exam.