F5-CTS-LTM BIG-IP Local Traffic Manager Practice Question
An LTM Specialist is troubleshooting an issue where client browsers are receiving errors when connecting via HTTPS. The virtual server is working fine for plain HTTP. Which THREE of the following could be the cause? (Choose three)
⚠ Common exam trap
Candidates often overlook the certificate chain. They assume the server certificate is the only requirement, forgetting that browsers require a complete chain to trust the SSL connection to the BIG-IP.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The Client SSL profile is using an expired certificate.
HTTPS issues usually stem from certificate, profile, or protocol mismatch problems. An expired certificate, a missing intermediate certificate in the chain, or an incompatible SSL profile will break the TLS handshake. These issues are common in LTM deployments and must be systematically ruled out by checking the BIG-IP logs, certificate stores, and profile settings to ensure the handshake can complete successfully between the client and the BIG-IP.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The Client SSL profile is using an expired certificate.
Why this is correct
An expired certificate will cause the client's browser to reject the connection as untrusted. This is a common cause for HTTPS failures. The BIG-IP will successfully initiate the handshake, but the client will immediately terminate the connection upon validating the certificate, causing the user to see a security error.
- ✗
The virtual server is missing a Server SSL profile.
Why it's wrong here
A Server SSL profile is only required if the BIG-IP is re-encrypting traffic to the backend. It does not affect the handshake between the client and the BIG-IP. If the backend is using plain HTTP, this profile is not needed and its absence won't break the client's HTTPS connection.
- ✓
The certificate chain is incomplete on the BIG-IP.
Why this is correct
If the intermediate certificate is not provided, the client cannot verify the certificate's trust path. This results in the client browser displaying a 'Not Trusted' or 'Untrusted Issuer' error, effectively preventing the user from successfully accessing the secure site until the full chain is correctly installed on the LTM.
- ✓
The Client SSL profile is missing or misconfigured.
Why this is correct
Without a properly configured Client SSL profile, the BIG-IP cannot perform the SSL handshake. This would prevent the encrypted channel from being established at all, causing the connection to fail before any application data is transmitted, which is a common point of failure in secure application delivery configurations.
- ✗
The virtual server is listening on the wrong port.
Why it's wrong here
If the virtual server was on the wrong port, it would likely fail for both HTTP and HTTPS or behave consistently across both. HTTPS specifically requires a configured SSL profile and valid certificate. The issue described is unique to the HTTPS configuration, not a general virtual server port configuration error.
About these practice questions
This F5-CTS-LTM question is part of Courseiva's 119-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official F5 exam blueprint
This F5-CTS-LTM practice question is part of Courseiva's free F5 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the F5-CTS-LTM exam.