Courseiva

CCNA BIG-IP Local Traffic Manager Questions

75 of 119 questions · Page 1/2 · BIG-IP Local Traffic Manager · Answers revealed

1
MCQmedium

Which action does an LTM perform when a health monitor fails for a pool member?

A.It automatically restarts the service on the backend server.
B.It removes the member from the pool and drops all active connections.
C.It marks the member as down and stops load balancing new requests to it.
D.It alerts the user with a 503 error page.
AnswerC

This is the core behavior of LTM load balancing. By marking the member down, the BIG-IP removes it from the selection pool, ensuring that subsequent client requests are routed only to healthy, operational servers, thereby maintaining the availability and integrity of the application service for all users.

Why this answer

When a health monitor fails, the LTM marks the member as 'down' and stops sending new traffic to it. This ensures that users do not experience errors or timeouts. Existing connections are typically handled according to the persistence and timeout settings, preventing sudden application failures for active users while protecting the service from faulty backend infrastructure.

Exam trap

Candidates often assume a failed health monitor immediately drops and terminates all active client connections currently linked to that pool member.

2
Multi-Selecthard

Which THREE conditions must be met for Connection Mirroring to function correctly between two BIG-IP devices in a high-availability pair?

Select 3 answers
A.The devices must be members of a Sync-Failover device group.
B.The virtual server must have mirroring enabled in its configuration.
C.A mirroring IP must be configured for the VLANs in use.
D.The virtual server must use a 'Fast L4' profile.
E.The pool members must be in the same subnet as the BIG-IP.
AnswersA, B, C

Connection mirroring requires the devices to be part of a synchronization and failover device group. This ensures that the secondary device is aware of the primary's configuration and can actively participate in the state synchronization process required to maintain persistent connections during a failover event.

Why this answer

Connection Mirroring requires specific synchronization prerequisites. The devices must be in a device group, a mirror IP address must be defined for the VLANs, and the virtual server must have mirroring explicitly enabled. This ensures that the state information of TCP and persistence sessions is replicated, allowing for hitless failover where clients do not have to re-establish their connections upon a standby-to-active transition.

Exam trap

Candidates often assume enabling connection mirroring globally is enough, forgetting that it must also be explicitly configured on individual virtual servers and VLANs.

3
MCQmedium

What is the primary function of a OneConnect profile on a BIG-IP Virtual Server?

A.It encrypts traffic between the BIG-IP and the server.
B.It enables TCP connection pooling to backend servers.
C.It forces clients to use a single persistent connection.
D.It compresses HTTP traffic before sending to the server.
AnswerB

OneConnect allows the BIG-IP to reuse existing TCP connections to backend servers for subsequent client requests. This reduces the number of TCP handshakes, lowers CPU utilization on both the BIG-IP and the backend servers, and significantly improves throughput and response times for web-based application traffic in high-load scenarios.

Why this answer

OneConnect enables TCP connection pooling between the BIG-IP and backend servers. By keeping connections open, it reduces the overhead of the three-way handshake for every request, which significantly improves performance, especially for HTTP/1.1 traffic. This is a critical configuration for high-traffic environments where connection setup latency can become a bottleneck, allowing the BIG-IP to maximize backend server resource utilization by reusing established connections for multiple client requests.

Exam trap

Candidates often confuse OneConnect with persistence. They incorrectly assume OneConnect maintains client session affinity, rather than its true purpose of managing TCP connection reuse to backend servers.

4
MCQmedium

Refer to the exhibit. Why would an administrator enable 'map-to-ipv6' in a source-address persistence profile?

A.It forces all traffic to be converted to IPv6 for backend server processing.
B.It creates a unified persistence table for both IPv4 and IPv6 clients.
C.It allows the LTM to translate IPv6 client requests to IPv4 backend servers.
D.It is required for performance optimization on the BIG-IP management plane.
AnswerB

By enabling 'map-to-ipv6', the BIG-IP maps the IPv4 address into the IPv6 address space within the persistence table. This normalization allows the system to manage persistence entries for both protocol types in a single table, ensuring consistent load balancing behavior regardless of the client's source protocol.

Why this answer

In dual-stack environments, both IPv4 and IPv6 clients might access the same application. The 'map-to-ipv6' feature ensures that IPv4 addresses are normalized into an IPv6-compatible format within the persistence table. This creates a unified persistence context, allowing the BIG-IP to correctly track and persist traffic from both address types to the same backend server, maintaining session consistency across different network protocols.

Exam trap

Candidates frequently assume this feature is for IP address translation or security, missing that its primary purpose is to normalize IPv4 addresses into an IPv6 format for unified persistence table management.

5
MCQmedium

An LTM administrator needs to allow a specific external IP address to access a restricted management interface via a virtual server, while blocking all others. What is the most efficient way to implement this?

A.Apply a packet filter to the VLAN that blocks all traffic except the specific IP.
B.Use an iRule or Local Traffic Policy on the virtual server to check the source IP.
C.Modify the pool member's firewall to allow only the BIG-IP's self IP address.
D.Assign a 'None' profile to the virtual server to force an error on unauthorized connections.
AnswerB

Using a Local Traffic Policy or an iRule allows for granular, virtual-server-specific control. By evaluating the 'client_addr' or 'IP::client_addr' value, the administrator can restrict access precisely, ensuring only the permitted IP addresses can reach the application while the configuration remains isolated from other services running on the same BIG-IP unit.

Why this answer

The most efficient way to control access at the BIG-IP level is using an LTM Local Traffic Policy or an iRule. While a packet filter or AFM can work, LTM-specific policies are integrated directly into the virtual server configuration. By checking the client IP address in the policy, the administrator can perform a 'drop' or 'reset' action for unauthorized traffic, ensuring high performance.

Exam trap

Candidates often select packet filters or external firewalls for access control, missing that LTM-specific policies and iRules provide direct, integrated management right at the virtual server level.

6
MCQmedium

An administrator wants to use an iRule to log the 'Host' header of every incoming HTTP request. Which iRule event is most appropriate for this task?

A.CLIENT_ACCEPTED
B.HTTP_REQUEST
C.HTTP_RESPONSE
D.LB_SELECTED
AnswerB

The 'HTTP_REQUEST' event is the correct place to handle HTTP header information. It occurs after the BIG-IP has parsed the request headers, allowing the iRule to safely access the 'Host' header and perform the logging operation before the request is forwarded to the backend pool member.

Why this answer

The 'HTTP_REQUEST' event triggers whenever a client sends an HTTP request, providing immediate access to the headers before the request is processed by the pool selection logic. This is the correct point in the request-response cycle to inspect and log headers. Using this event ensures that the logging logic executes for every single request, providing a full audit trail of host header usage.

Exam trap

Candidates often choose incorrect events like 'CLIENT_ACCEPTED', which happens before the HTTP request is parsed, meaning the HTTP headers are not yet available for the iRule to read.

7
MCQhard

Which component is responsible for executing iRules on the BIG-IP LTM system?

A.The Control Plane (MCPD).
B.The Data Plane (TMM).
C.The Linux Kernel.
D.The REST API daemon (restjavad).
AnswerB

The Traffic Management Microkernel (TMM) handles all packet flow through the system. By executing iRules within the TMM process, the BIG-IP ensures that traffic management logic is applied at wire speed, minimizing overhead and latency while maintaining full visibility into the traffic stream for complex decision-making and payload modifications.

Why this answer

The Traffic Management Microkernel (TMM) is the core engine of the BIG-IP system responsible for processing all traffic. iRules are executed directly within TMM as packets are processed, allowing for line-rate traffic manipulation. This architecture ensures that complex logic, such as header modification or persistence redirection, occurs in real-time with minimal latency, which is a major advantage of the LTM's purpose-built hardware acceleration and software design.

Exam trap

Candidates frequently confuse the Control Plane (management) with the Data Plane (TMM), mistakenly attributing traffic processing tasks to the management IP or the F5 Linux-based operating system itself.

8
MCQeasy

Which component of the BIG-IP LTM system is responsible for performing health checks on backend servers to determine if they are capable of accepting new connections?

A.The Persistence Profile
B.The Health Monitor
C.The SNAT Automap
D.The Virtual Server
AnswerB

Health monitors are specifically designed to poll backend resources. They verify availability by performing active checks. If a check fails, the resource is removed from the pool, ensuring traffic is only routed to responsive servers, which is the primary method for maintaining high availability in LTM.

Why this answer

Health monitors are the LTM component used to periodically verify the status of pool members. By sending specific requests—such as ICMP, TCP, or HTTP—the LTM determines if a server is healthy. If a monitor fails, the LTM marks the member as 'down' and stops sending traffic to it, which is essential for maintaining application availability and preventing users from hitting broken services.

Exam trap

Candidates frequently confuse 'Health Monitors' with 'Load Balancing Methods' or 'Persistence Profiles', incorrectly assuming that traffic distribution algorithms are responsible for verifying server health.

9
MCQmedium

Refer to the exhibit. What is the primary purpose of enabling 'insert-xforwarded-for' in the HTTP profile?

A.To hide the backend server's IP address from the client.
B.To allow the server to identify the original client's IP address.
C.To increase the throughput of HTTP requests.
D.To bypass the need for an SSL profile.
AnswerB

This header is a standard way for proxies to pass the client's original IP address to the web server. Without this header, the server would only see the BIG-IP's IP address, making it impossible to perform IP-based logging or access control at the application level.

Why this answer

When the BIG-IP acts as a proxy, the backend servers see the BIG-IP's IP address as the source of all traffic. By inserting the X-Forwarded-For header, the BIG-IP includes the original client's IP address in the HTTP request. This allows backend applications to log the true client IP for auditing, security analysis, and personalization, which would otherwise be lost due to the LTM's source IP translation.

Exam trap

Candidates assume the server automatically knows the client's IP. They overlook that the BIG-IP's SNAT or proxy behavior hides the true source IP, necessitating the X-Forwarded-For header for visibility.

10
MCQmedium

Which load balancing method is best suited for a pool where servers have significantly different processing capabilities and hardware specifications?

A.Round Robin
B.Least Connections
C.Ratio (member)
D.Observed
AnswerC

The Ratio (member) method allows administrators to define a specific weight for each pool member. This is the most appropriate choice for heterogeneous hardware, as it explicitly directs a higher proportion of traffic to servers with better CPU, RAM, and I/O capabilities, effectively balancing the actual load across the environment.

Why this answer

The 'Ratio' load balancing method allows administrators to assign weights to pool members, directing more traffic to more powerful servers. In heterogeneous environments, using a static method like Round Robin would overwhelm weaker servers while underutilizing stronger ones. Ratio-based load balancing provides the necessary control to optimize performance and server utilization based on the actual capacity of each individual backend node in the cluster.

Exam trap

Candidates often choose 'Least Connections' or 'Round Robin', failing to account for the fact that these methods do not consider the hardware performance disparity between the backend servers.

11
Multi-Selecthard

An LTM Specialist is troubleshooting an issue where client browsers are receiving errors when connecting via HTTPS. The virtual server is working fine for plain HTTP. Which THREE of the following could be the cause? (Choose three)

Select 3 answers
A.The Client SSL profile is using an expired certificate.
B.The virtual server is missing a Server SSL profile.
C.The certificate chain is incomplete on the BIG-IP.
D.The Client SSL profile is missing or misconfigured.
E.The virtual server is listening on the wrong port.
AnswersA, C, D

An expired certificate will cause the client's browser to reject the connection as untrusted. This is a common cause for HTTPS failures. The BIG-IP will successfully initiate the handshake, but the client will immediately terminate the connection upon validating the certificate, causing the user to see a security error.

Why this answer

HTTPS issues usually stem from certificate, profile, or protocol mismatch problems. An expired certificate, a missing intermediate certificate in the chain, or an incompatible SSL profile will break the TLS handshake. These issues are common in LTM deployments and must be systematically ruled out by checking the BIG-IP logs, certificate stores, and profile settings to ensure the handshake can complete successfully between the client and the BIG-IP.

Exam trap

Candidates often overlook the certificate chain. They assume the server certificate is the only requirement, forgetting that browsers require a complete chain to trust the SSL connection to the BIG-IP.

12
MCQmedium

Which BIG-IP feature allows an administrator to modify the HTTP header of a request before it reaches the backend server?

A.SNAT Pool
B.iRule
C.HTTP Profile
D.Virtual Server
AnswerB

iRules are the programmatic way to control traffic on the BIG-IP. They provide deep packet inspection and modification capabilities, including the ability to change, append, or remove HTTP headers before the request is forwarded to the backend pool member, satisfying the requirement for dynamic traffic manipulation.

Why this answer

An iRule is the primary mechanism for manipulating traffic at the application layer. By using events like HTTP_REQUEST, an administrator can insert, modify, or delete HTTP headers on the fly. This is essential for scenarios like adding X-Forwarded-For headers, removing security-sensitive headers, or injecting custom application-specific tokens to communicate information to the backend servers that the client did not initially provide.

Exam trap

Candidates often suggest using a 'Profile' to modify headers. While some profiles have limited header options, they fail to realize that dynamic, complex header manipulation requires the power of iRules.

13
MCQeasy

An administrator needs to monitor the health of a web service that uses an unconventional port and requires a specific string to be returned in the response. Which monitor type should be used?

A.A standard TCP monitor with the port defined in the monitor configuration.
B.An HTTP monitor with the 'Send String' and 'Receive String' configured.
C.An ICMP monitor added to the pool member's health monitor list.
D.An external monitor script that performs a shell command to check the service.
AnswerB

An HTTP monitor allows for custom sends (e.g., 'GET /health') and checks the response body against a 'Receive String'. This validates that the application layer is functioning correctly, which is the most reliable way to monitor the health of a web service beyond simple transport-layer connectivity tests.

Why this answer

The HTTP monitor is designed for checking web services. By specifying the port and the 'Receive String' field, the administrator can verify that the server is not only listening but also returning the expected content. This is essential for detecting 'grey failure' scenarios where a server responds to a TCP connection but serves an error page or an incomplete application response.

Exam trap

Candidates often try to use TCP monitors for web services, failing to realize that a TCP monitor only checks for an open port and cannot verify the application response.

14
MCQmedium

An administrator wants to ensure that a specific server in a pool receives more traffic than others due to its higher hardware capacity. Which load balancing method should be used?

A.Round Robin
B.Least Connections
C.Ratio
D.Fastest
AnswerC

Ratio load balancing assigns a configurable weight to each member. By setting a higher ratio for the higher-capacity server, the administrator directly controls the distribution of traffic. This matches the requirement to skew traffic toward the more capable hardware, effectively optimizing the overall performance of the pool.

Why this answer

The 'Ratio' load balancing method allows an administrator to assign a weight to each pool member. A server with a higher ratio will receive a proportionally larger number of connections compared to servers with lower ratios. This is the correct method for load balancing in heterogeneous environments where hardware performance varies, ensuring that more capable servers handle a larger share of the overall traffic load.

Exam trap

Test-takers often confuse the 'Ratio' method with 'Dynamic Ratio' or 'Least Connections', failing to realize that Ratio uses static weights assigned manually by the administrator.

15
MCQmedium

Which statement best describes the difference between a 'Node' and a 'Pool Member' in the BIG-IP LTM configuration?

A.Nodes are defined at the virtual server level, while pool members are defined globally.
B.Nodes represent the physical IP, whereas pool members represent the service port.
C.Nodes are only used for health monitoring, while pool members handle traffic.
D.Pool members are not required for load balancing traffic.
AnswerB

A node is an IP-level object representing the server itself. A pool member combines that node's IP with a specific service port. This allows the BIG-IP to direct traffic to different services (e.g., port 80 and 443) running on the same physical server identified by one node.

Why this answer

A Node is a device defined by its IP address, which exists independently of any pool. A Pool Member is an instance of a node assigned to a specific pool, often including port and monitor settings. This distinction is crucial because multiple pools can reference the same node, allowing administrators to manage health and load balancing for different services independently on the same physical backend server.

Exam trap

Candidates often confuse 'Nodes' with 'Pool Members', assuming they are interchangeable terms because both represent backend servers, forgetting that pool members specifically include a service port.

16
MCQhard

Refer to the exhibit. The virtual server is showing client-side traffic but no server-side traffic. What is the most likely reason?

A.The virtual server is configured with an incorrect destination IP address.
B.All pool members are currently marked down by health monitors.
C.The client is sending traffic that does not match the HTTP profile.
D.The BIG-IP is configured with an incorrect default gateway.
AnswerB

If all pool members are down, the BIG-IP will refuse or reset connections because it has no destination to forward traffic to. The client-side stats increase because the VIP receives the packet, but no server-side connections are opened, which matches the exhibit showing zero server-side traffic.

Why this answer

When a virtual server shows incoming client traffic but zero outgoing server traffic, it usually indicates that the BIG-IP cannot establish a connection to the pool members. This is often caused by a pool being empty, all members being marked down by health monitors, or a routing issue preventing the BIG-IP from reaching the backend servers. The lack of server-side connections confirms the BIG-IP is not successfully forwarding requests.

Exam trap

Candidates frequently suspect routing or client-side SSL issues when seeing no server-side traffic, missing the fundamental indicator that all pool members are down.

17
MCQhard

When configuring a custom monitor, what happens if the 'Time Until Up' is set to 0?

A.The monitor will never mark the node as up.
B.The monitor marks the node as up after the first success.
C.The monitor will fail to send any probes.
D.The monitor will use the default system timeout.
AnswerB

A value of zero for 'Time Until Up' instructs the BIG-IP to mark a pool member as available immediately after the first successful health check. This provides the fastest possible recovery time for a server returning to the pool, though it risks sending traffic to an un-warmed service.

Why this answer

Setting 'Time Until Up' to zero disables the 'slow start' or 'delayed up' feature of the health monitor. The member is marked 'Up' immediately upon the first successful probe. This is crucial for environments where rapid recovery is required, but it can lead to 'flapping' if the server is unstable.

Understanding monitor timing is vital for ensuring high availability without introducing unnecessary instability in the backend pool infrastructure.

Exam trap

Candidates often assume that setting this to 0 disables the monitor entirely, rather than understanding it simply removes the 'slow start' delay for marking a node as 'Up'.

18
MCQmedium

An administrator wants to use an iRule to change the pool for an incoming request based on the URI. Which event should be used in the iRule?

A.CLIENT_ACCEPTED
B.HTTP_REQUEST
C.HTTP_RESPONSE
D.LB_SELECTED
AnswerB

The HTTP_REQUEST event occurs after the client has sent the request headers. This is the ideal moment to inspect the URI, as the information is fully available in the request metadata, allowing the iRule to dynamically select the appropriate backend pool for that specific request.

Why this answer

The HTTP_REQUEST event is the correct choice for inspecting HTTP traffic. It triggers as soon as the BIG-IP has parsed the HTTP request headers, allowing the iRule to evaluate the URI, cookies, or other headers. This is the optimal point to perform content-based switching, as it happens before the request is forwarded to a pool member, ensuring the load balancing decision is based on application-layer information.

Exam trap

Candidates sometimes choose the wrong event, such as CLIENT_ACCEPTED. This event triggers before the HTTP headers are available, making it impossible to evaluate the URI or specific HTTP data.

19
MCQmedium

An administrator needs to modify the HTTP response header to hide the server version for security reasons. Which tool is most appropriate?

A.A Local Traffic Policy with a 'header' modify action.
B.An iRule in the 'HTTP_RESPONSE' event with 'HTTP::header remove Server'.
C.A customized HTTP profile that blocks the 'Server' header.
D.A custom monitor with 'header-strip' enabled.
AnswerB

This iRule is the industry-standard way to remove the 'Server' header. By acting in the 'HTTP_RESPONSE' event, the LTM processes the response as it returns from the backend, allowing the BIG-IP to strip the sensitive version information before the final response is delivered to the end-user client.

Why this answer

An iRule using the 'HTTP_RESPONSE' event is the most flexible way to modify headers. Using the 'HTTP::header remove' command, an administrator can strip sensitive version information from the 'Server' header before the response reaches the client. This is a common security hardening task that prevents potential attackers from fingerprinting the backend server version and identifying known vulnerabilities associated with that specific platform.

Exam trap

Candidates often select the wrong iRule event, such as 'HTTP_REQUEST' instead of 'HTTP_RESPONSE', which prevents the BIG-IP from intercepting the header before it is delivered to the client.

20
MCQmedium

Refer to the exhibit. The LTM Specialist discovers that the HTTPS monitor is failing. The server logs indicate that the requests are reaching the web server, but the server is returning a 400 Bad Request error. What is the most likely cause?

A.The BIG-IP is using the wrong SSL profile for the monitor.
B.The Host header in the send string does not match the server's expected virtual host.
C.The monitor is missing a 'Receive String' definition.
D.The monitor is using the wrong HTTP method.
AnswerB

When using HTTP/1.1, the Host header is mandatory. If the server expects a specific host header value but receives 'example.com', it will reject the request with a 400 status. The monitor must be updated to match the hostname configured on the backend web server.

Why this answer

The exhibit shows a manually defined send string that includes a Host header. A 400 Bad Request often indicates that the server does not recognize the Host header or the HTTP version specified in the request. In this configuration, the 'Host: example.com' header might be mismatched with the server's virtual host configuration, causing it to reject the request, which prevents the monitor from correctly identifying the server as healthy.

Exam trap

Candidates often assume the 400 Bad Request error is caused by a broken network link or general server downtime, missing that the custom HTTP send string explicitly requires a matching Host header.

21
MCQeasy

Which load balancing algorithm is best suited for a pool of servers where each server has different hardware specifications and processing capacities?

A.Round Robin
B.Ratio
C.Least Connections
D.Fastest
AnswerB

The Ratio algorithm permits the assignment of specific weights to each server. This is the ideal choice for heterogeneous server environments where processing power varies, as it ensures that traffic volume is aligned with each server's specific hardware capacity, preventing overload on smaller instances while fully utilizing high-spec resources.

Why this answer

The 'Ratio' load balancing method allows administrators to assign a weighting to each server based on its actual performance capability. In mixed-hardware environments, this prevents lower-spec servers from becoming overwhelmed while ensuring that more powerful servers handle a proportionately larger share of the traffic, thus maximizing the efficiency and reliability of the overall application delivery infrastructure.

Exam trap

Candidates often select Round Robin, assuming it is the default for all scenarios, failing to recognize that Ratio is specifically required to account for hardware performance disparities in mixed-server environments.

22
MCQhard

Refer to the exhibit. The web_pool is currently offline with zero active members. An LTM Specialist checks the backend servers and finds they are both responding to pings. What is the most likely reason for the pool being offline?

A.The virtual server is disabled.
B.The health monitor is misconfigured or the service is down.
C.The default route on the BIG-IP is missing.
D.The SNAT pool is exhausted.
AnswerB

Since servers respond to pings but are marked down by the pool, the health monitor is clearly failing. This means the specific application service the monitor is checking (like port 80/443) is not responding, or the monitor's parameters do not match the expected response from the backend server.

Why this answer

The pool status is 'offline' and 'children are down' despite servers being reachable via ping. This indicates the health monitor configured on the pool is failing, likely because the specific service (e.g., HTTP on port 80) is not responding or the monitor is misconfigured. Ping only tests network layer connectivity, whereas LTM monitors test application-layer availability, which is the standard for determining if a server can actually process traffic.

Exam trap

Candidates often assume that because a server responds to ICMP (ping), it is fully functional, failing to realize that the application service (HTTP/HTTPS) might be down.

23
MCQmedium

When using an iRule to select a pool, what happens if the iRule contains a logic error that results in no pool being selected?

A.The connection is immediately dropped.
B.The system selects the default pool defined on the VS.
C.The system routes traffic to the first pool in the list.
D.The iRule execution stops and returns an error to the client.
AnswerB

If the iRule executes without issuing a 'pool' command, the BIG-IP falls back to the default pool configured on the virtual server object. This design allows for graceful degradation or conditional routing where the iRule acts as an override rather than a mandatory requirement for every single connection request processed.

Why this answer

If an iRule does not issue a 'pool' command, the BIG-IP defaults to the pool defined on the Virtual Server itself. If no pool is defined on the VS, the connection is reset. Understanding this fallback behavior is vital for debugging complex iRule logic.

If an administrator fails to account for all conditions in an iRule, the traffic may behave unpredictably, falling back to default settings rather than failing outright.

Exam trap

Candidates often believe that an iRule logic error will cause the connection to drop immediately, forgetting that the BIG-IP will gracefully fall back to the Virtual Server's default pool.

24
MCQmedium

Which profile type is used to optimize the delivery of HTTP traffic, such as enabling GZIP compression or caching?

A.TCP profile
B.HTTP profile
C.Client SSL profile
D.OneConnect profile
AnswerB

The HTTP profile allows the LTM to inspect and modify HTTP traffic. It includes features for response compression (GZIP), caching static objects, and modifying headers, which are essential for optimizing web application performance and reducing the bandwidth required to serve content to end users.

Why this answer

The HTTP profile is the engine for Layer 7 application optimization. It allows administrators to manipulate headers, compress content for faster delivery, and cache static assets. Because LTM is a full-proxy architecture, it can perform these optimizations on the fly, reducing the load on backend servers and decreasing the time to first byte, which is crucial for modern web performance metrics.

Exam trap

Candidates often look for a specialized 'Optimization' or 'Caching' profile, missing that GZIP compression and caching are managed within the standard HTTP profile.

25
MCQmedium

What is the primary benefit of using SNAT (Source Network Address Translation) on a BIG-IP LTM system when communicating with backend pool members?

A.It improves the security of the backend servers by encrypting data.
B.It ensures return traffic from pool members passes back through the BIG-IP.
C.It increases the maximum number of concurrent client connections.
D.It eliminates the need for health monitoring of pool members.
AnswerB

By translating the client's source IP to the BIG-IP's address, the server responds directly to the BIG-IP. This prevents situations where the server sends traffic directly to the client via an alternate path, which would cause the BIG-IP to drop the connection due to asymmetric routing.

Why this answer

SNAT simplifies network topology by ensuring that traffic returned from pool members to the BIG-IP always traverses the same device, even if the pool members are on different subnets or lack a default gateway pointing to the BIG-IP. This prevents asymmetric routing and ensures that the BIG-IP can correctly correlate return traffic with the original client request for session persistence and tracking.

Exam trap

Candidates often confuse SNAT with packet encryption or load-balancing algorithms, missing its core network-layer purpose of forcing return traffic back through the BIG-IP.

26
MCQmedium

Which load balancing algorithm would be best suited for a pool of servers where the servers have significantly different hardware specifications and processing capabilities?

A.Round Robin
B.Ratio (member)
C.Least Connections
D.Fastest
AnswerB

Ratio (member) allows the administrator to define weights for each pool member. By assigning a higher weight to more powerful servers, the BIG-IP can distribute traffic based on the actual capacity of the backend hardware, ensuring that no single server becomes a performance bottleneck under load.

Why this answer

When servers in a pool are heterogeneous, using a simple round-robin approach causes faster servers to sit idle while slower servers become overloaded. The 'Ratio' algorithm allows administrators to assign a weight to each server, ensuring that higher-capacity servers receive a proportionally larger share of the traffic, which optimizes the overall system performance and prevents bottlenecking on the weaker backend hardware.

Exam trap

Candidates select 'Least Connections' assuming it automatically accounts for hardware differences, but it only tracks active sessions, not the actual processing power or hardware capability of the nodes.

27
MCQeasy

An administrator wants to ensure that all HTTP traffic is redirected to HTTPS. What is the most efficient way to perform this on a BIG-IP LTM?

A.Configure an HTTP profile on the virtual server to force SSL.
B.Create a virtual server on port 80 with an iRule that performs a 301 redirect.
C.Modify the backend server settings to reject HTTP connections.
D.Use a SNAT pool to force all port 80 traffic to port 443.
AnswerB

An iRule utilizing the 'HTTP::redirect' command on a port 80 virtual server is the most efficient and scalable way to enforce HTTPS. It handles the request at the entry point and returns a standard redirect, allowing the client to initiate a new connection to the secure virtual server.

Why this answer

Creating a separate virtual server for port 80 that uses an iRule to issue an HTTP 301/302 redirect is the standard, cleanest method. This offloads the redirection logic from the main secure virtual server, keeping the configuration modular. It ensures that any insecure traffic is immediately directed to the secure listener, maintaining security compliance and simplifying the management of HTTP vs.

HTTPS traffic.

Exam trap

Many candidates attempt to configure a single virtual server for both HTTP and HTTPS or use complex iRules on the HTTPS virtual server, which is less efficient and harder to manage than a redirect.

28
MCQmedium

Which component of the BIG-IP system is responsible for managing the connection table and performing packet-level forwarding decisions?

A.Configuration Utility (GUI)
B.Traffic Management Microkernel (TMM)
C.BigDB
D.MCPD
AnswerB

TMM is the core engine responsible for full-proxy traffic processing, including managing the connection table, performing load balancing decisions, and executing iRules. It operates at the kernel level to ensure high performance and low latency for all processed application traffic moving through the BIG-IP device platform.

Why this answer

The Traffic Management Microkernel (TMM) is the heart of the BIG-IP. It handles the data plane, including connection tracking, load balancing, and packet inspection. Understanding that TMM runs as a dedicated process separate from the management plane is essential for performance tuning and troubleshooting system-level issues, such as high CPU usage or packet loss during traffic spikes in high-throughput enterprise environments.

Exam trap

Candidates often confuse the TMM with the management plane (the Linux host). They fail to identify TMM as the core engine responsible for data plane packet processing and connection table management.

29
MCQmedium

An LTM Specialist needs to ensure that client traffic is distributed evenly across four backend servers, but some servers are more powerful than others. Which load balancing method should be chosen?

A.Round Robin
B.Ratio
C.Least Connections
D.Observed
AnswerB

Ratio load balancing allows the BIG-IP to distribute traffic based on a predefined weight for each server. This is specifically designed for environments where backend servers have different processing power, ensuring that traffic is weighted appropriately to match each server's specific capabilities and resources.

Why this answer

Ratio load balancing is the appropriate method when server capacities differ. By assigning a higher ratio weight to the more powerful servers, the BIG-IP will send a proportionally larger amount of traffic to them. This ensures that the load is balanced relative to the processing power of each backend node, maximizing the performance of the overall application cluster and preventing smaller servers from being overwhelmed.

Exam trap

Candidates frequently choose 'Least Connections' or 'Round Robin' regardless of server capacity, ignoring that 'Ratio' is the specific algorithm designed to handle servers with different hardware performance levels.

30
MCQmedium

What is the primary function of the LTM 'OneConnect' profile in an environment with high-volume short-lived connections?

A.It compresses HTTP traffic to reduce bandwidth usage.
B.It multiplexes client-side and server-side connections to reduce server CPU load.
C.It caches static content to prevent repetitive requests to backend servers.
D.It performs SSL decryption to offload cryptographic tasks.
AnswerB

OneConnect manages a pool of idle server-side TCP connections. When a new request arrives, it is mapped to an existing idle connection rather than creating a new one. This reduces the CPU overhead on backend servers by eliminating redundant TCP handshakes, improving overall throughput in high-volume environments.

Why this answer

OneConnect enables TCP connection multiplexing. It allows the BIG-IP to keep backend TCP connections open even after a client has closed its connection. By reusing these existing idle connections for new client requests, the LTM significantly reduces the overhead on backend servers associated with the TCP three-way handshake and slow-start process, which is essential for scaling performance in high-traffic web environments.

Exam trap

Candidates often mistake OneConnect for a simple caching mechanism or a security feature, failing to recognize its specific role in reducing TCP overhead by multiplexing connections between the BIG-IP and backend servers.

31
MCQeasy

Which BIG-IP feature allows an LTM Specialist to perform granular inspection and modification of HTTP traffic headers before they reach the backend server?

A.Local Traffic Policy
B.iRules
C.Persistence Profile
D.FastL4 Profile
AnswerB

iRules provide the most flexibility for inspecting and modifying traffic headers. By attaching an iRule to a virtual server, you can trigger logic on HTTP_REQUEST events, allowing for complex manipulation of headers, cookies, or path data, which is crucial for modern, dynamic web application delivery.

Why this answer

iRules are the primary tool for custom traffic manipulation on the BIG-IP. They provide an event-driven Tcl-based scripting environment that allows specialists to intercept, inspect, and modify any part of the packet, including HTTP headers. This is essential for advanced load balancing scenarios, such as header-based routing, security obfuscation, or dynamic application integration that standard profiles cannot handle natively.

Exam trap

Candidates often select standard HTTP profiles or Local Traffic Policies, forgetting that granular, custom inspection and modification of headers require the programmability of iRules.

32
MCQhard

Refer to the exhibit. Why is the 'http' profile required in this virtual server configuration?

A.To enable hardware acceleration for SSL processing.
B.To allow the LTM to inspect and modify HTTP headers.
C.To define the backend server pool members.
D.To enable port translation for the virtual server.
AnswerB

The HTTP profile provides the necessary protocol parsing for the BIG-IP to understand HTTP request and response structures. This is a prerequisite for any iRule that needs to inspect or modify headers, as well as for features like cookie persistence which rely on header analysis.

Why this answer

The 'http' profile is required because the BIG-IP LTM needs to parse the HTTP headers to perform application-level functions like persistence, compression, or header manipulation. Even if the Virtual Server simply forwards traffic, the presence of an HTTP profile enables the TMM to understand the protocol structure. This is critical for any LTM configuration that requires visibility into the payload for security or load-balancing logic.

Exam trap

Many candidates believe an HTTP profile is only needed for SSL termination or compression, forgetting it is mandatory for basic header inspection and cookie persistence.

33
Multi-Selectmedium

Which TWO of the following are valid methods to offload SSL processing from the backend servers to the BIG-IP system? (Choose two)

Select 2 answers
A.Configure Client-side SSL profile on the virtual server and leave the backend pool unencrypted.
B.Configure Server-side SSL profile on the virtual server and leave the client traffic unencrypted.
C.Configure both Client-side and Server-side SSL profiles on the virtual server.
D.Disable SSL on the virtual server and enable it on the pool.
E.Configure an iRule to forward unencrypted packets to the backend servers.
AnswersA, C

This is the classic SSL termination scenario. The BIG-IP handles the SSL handshake with the client and sends traffic to the pool members in cleartext. This is the most efficient method for offloading SSL because the backend servers handle no encryption at all for these incoming requests.

Why this answer

SSL Offloading is a primary function of LTM, allowing the BIG-IP to perform the resource-intensive cryptographic tasks. By terminating the SSL connection at the BIG-IP, the backend servers can focus on application logic. The two common architectures are SSL Termination (Client-side SSL) and SSL Bridging (Client-side and Server-side SSL), both of which effectively remove the encryption burden from the backend pool members.

Exam trap

Candidates often mistakenly select server-side SSL alone as an offloading method, forgetting that offloading requires terminating client-side encryption on the BIG-IP device.

34
MCQhard

Refer to the exhibit. What is the effect of the 'mask' setting in this source address persistence profile?

A.It hides the individual client's IP from the backend server.
B.It groups clients from the same class C network for persistence.
C.It limits the number of connections allowed from each subnet.
D.It causes the LTM to ignore the source IP entirely.
AnswerB

The 255.255.255.0 mask applies to the source IP, meaning only the first three octets of the client's IP are used to create the persistence record. Consequently, all users within that subnet will be directed to the same pool member, effectively sharing the same session persistence state.

Why this answer

The mask setting in a source address persistence profile allows the BIG-IP to group clients by subnet rather than individual IP address. By setting the mask to 255.255.255.0, the LTM treats all clients originating from the same /24 network as a single entity for persistence purposes. This is particularly useful in environments where many users share a gateway or proxy, preventing persistence table exhaustion.

Exam trap

Many examinees think the persistence mask applies to individual host routing rather than grouping entire subnets for session stickiness.

35
MCQhard

Refer to the exhibit. The virtual server 'vs_secure_site' is showing as 'offline'. What is the most immediate step to take to restore service?

A.Delete and recreate the virtual server.
B.Investigate the pool members and health monitor status.
C.Restart the BIG-IP TMM service.
D.Change the virtual server IP address.
AnswerB

The 'no available members' reason clearly points to the pool. By checking the pool status and health monitors, you can determine which server is failing and why. This is the correct troubleshooting path, as it addresses the source of the outage rather than guessing at configuration errors elsewhere.

Why this answer

When a virtual server status is 'offline' due to 'no available members', it indicates that all pool members associated with that virtual server have failed their health checks. The most immediate and logical step is to inspect the pool members and their monitors to identify why they are failing, as the virtual server cannot function without at least one healthy backend server.

Exam trap

Candidates often try to reset the virtual server or clear connections. They waste time on the frontend configuration instead of investigating the backend pool, which is the actual cause of the offline status.

36
MCQhard

Refer to the exhibit. The pool members are marked down. A manual test shows that 'curl -v -H "Host: www.example.com" http://<member_ip>/health.php' returns 'OK'. What is the most likely issue?

A.The monitor is missing the 'interval' and 'timeout' parameters.
B.The HTTP version in the send string is causing a protocol mismatch.
C.The 'receive' string does not account for the entire HTTP response body.
D.The connection should be set to 'Keep-Alive' instead of 'Close'.
AnswerC

The 'receive' field looks for the specified string anywhere in the returned payload. If the server returns additional characters, or if the 'OK' is buried in HTML that the BIG-IP does not see as a exact match, the monitor will fail. Exact string matching is required for health success.

Why this answer

The health monitor configuration requires exact string matching for the 'receive' field. If the server returns extra whitespace, headers, or different formatting than expected by the BIG-IP, the match will fail. The monitor configuration in the exhibit is correct in syntax, but the 'receive' string must match exactly the data found in the raw response body, which often differs from how a terminal-based curl output displays information.

Exam trap

Candidates often assume that if a curl command works in a terminal, the monitor will pass, failing to realize the monitor looks for an exact, case-sensitive string match in the raw response.

37
MCQmedium

An LTM Specialist needs to configure a virtual server to handle both HTTP and HTTPS traffic on the same IP address. Which THREE steps are required to implement this? (Select THREE)

A.Create two virtual servers using the same virtual IP address.
B.Assign a Client SSL profile to the HTTPS virtual server.
C.Assign the same pool to both virtual servers.
D.Configure a single virtual server with a wildcard port.
E.Disable the HTTP profile on the HTTPS virtual server.
AnswerA, B, C

The BIG-IP allows multiple virtual servers to share the same IP address provided they listen on different ports. One for port 80 and one for port 443 is the standard configuration for hosting dual-protocol services on a single VIP address, simplifying client-side DNS management.

Why this answer

To support both protocols, the BIG-IP needs a virtual server for each port (80 and 443). To handle them identically, they must share a pool. Additionally, the HTTPS virtual server requires an SSL profile to decrypt the traffic before it is load-balanced to the backend.

This architecture allows the BIG-IP to manage both cleartext and encrypted sessions efficiently while centralizing management of the backend pool.

Exam trap

Candidates often attempt to use a single virtual server for both HTTP and HTTPS, forgetting that SSL profiles cannot be applied to cleartext traffic and separate ports are required.

38
MCQhard

What is the result of setting the 'OneConnect Transformation' feature to 'Enabled' in an HTTP profile?

A.It forces the client to use HTTPS.
B.It rewrites HTTP headers to support connection reuse.
C.It compresses all outgoing HTTP payloads.
D.It disables all persistence profiles on the VS.
AnswerB

OneConnect transformation modifies the 'Connection' header in HTTP requests to match the state maintained by the BIG-IP. This ensures that the backend server acknowledges the BIG-IP's management of the connection, allowing it to remain open for future requests rather than prematurely closing it after a single transaction.

Why this answer

OneConnect Transformation allows the BIG-IP to safely rewrite Connection headers, converting 'keep-alive' to 'close' or vice-versa to facilitate connection reuse. This ensures that the backend servers properly interpret the connection state as managed by the BIG-IP's pooling mechanism. Without this, the server might close the connection prematurely, causing errors in applications that expect persistent connections, thereby negating the performance benefits provided by the OneConnect profile implementation.

Exam trap

Candidates often mistake this for a security feature or a compression setting, missing its critical role in rewriting HTTP headers to ensure backend servers support connection reuse via OneConnect.

39
MCQeasy

Which profile type is required to inspect and modify HTTP headers on a BIG-IP LTM virtual server?

A.TCP Profile
B.HTTP Profile
C.FastL4 Profile
D.Client SSL Profile
AnswerB

The HTTP profile provides the necessary functionality to inspect the HTTP request and response flow. It allows the LTM to interpret headers, modify content, and interact with iRules to manipulate traffic at the application layer, which is necessary for complex web application requirements and security header injections.

Why this answer

An HTTP profile is required to enable the LTM to parse, understand, and manipulate HTTP traffic. Without an HTTP profile, the BIG-IP processes traffic at the TCP layer, making it impossible to see or alter application-level headers. This is a foundational concept for implementing security policies, X-Forwarded-For injection, or traffic routing based on HTTP hostnames or path information.

Exam trap

Candidates often forget that an HTTP profile is a prerequisite for Layer 7 inspection, incorrectly thinking that LTM can automatically parse HTTP headers without explicit profile configuration on the virtual server.

40
MCQmedium

An LTM administrator needs to ensure that a pool member remains in the pool but stops receiving new connections while existing connections are allowed to finish. Which action should the administrator perform?

A.Set the pool member state to 'Offline'.
B.Force the pool member to 'Offline'.
C.Set the pool member state to 'Disabled'.
D.Delete the pool member from the pool.
AnswerC

Disabled status allows the BIG-IP to maintain existing connections while preventing the load balancer from assigning any new incoming requests to that member. This provides a controlled traffic draining mechanism, enabling administrators to perform maintenance tasks without impacting users who are currently in the middle of active application sessions or transactions.

Why this answer

Setting a pool member to 'Disabled' state is the standard operational procedure for graceful maintenance. It prevents new connections from being established via the load balancing algorithm while allowing established persistence records or active sessions to complete their lifecycle. This is critical for preventing service disruption during application updates or server-side patching cycles, ensuring a seamless user experience while managing backend resources effectively.

Exam trap

Test-takers frequently choose 'Offline' instead of 'Disabled', failing to realize that 'Offline' abruptly drops existing user connections rather than allowing them to complete gracefully.

41
MCQeasy

What is the result of applying a 'FastL4' profile to a virtual server?

A.It allows the BIG-IP to perform HTTP header insertion.
B.It provides high-performance L4 load balancing.
C.It enables SSL termination on the virtual server.
D.It creates a stateful firewall for all traffic.
AnswerB

FastL4 is optimized for raw performance by processing packets directly at the transport layer. It avoids the full overhead of a complete TCP stack and application-layer processing, making it the fastest way to route traffic through the BIG-IP for protocols that do not require application-layer inspection.

Why this answer

The FastL4 profile is designed for high-performance, transport-layer load balancing. It bypasses the full proxy capabilities of the BIG-IP, meaning it cannot perform L7 inspection, HTTP header manipulation, or SSL offloading. This is ideal for scenarios like UDP traffic, streaming, or simple TCP load balancing where maximizing throughput and minimizing latency are more important than application-level traffic modification or security features.

Exam trap

Candidates often assume FastL4 can still perform HTTP header manipulation or iRule logic. FastL4 is a hardware-accelerated profile that bypasses full proxy features, making it incapable of L7 inspection.

42
MCQhard

Refer to the exhibit. An LTM Specialist wants to ensure that persistence is maintained even if a client switches between different virtual services that share the same pool members. Based on the configuration, will this work?

A.Yes, because 'match-across-services' is enabled.
B.No, because the cookie name must be unique per virtual server.
C.No, because 'expiration 0' prevents persistence across services.
D.Yes, but only if the virtual servers share the same IP address.
AnswerA

The 'match-across-services' setting is specifically designed to allow persistence records to be shared across multiple virtual servers. By enabling this, the BIG-IP links the session to the pool member regardless of which virtual service the client hits, ensuring seamless session continuity across different parts of the application.

Why this answer

The persistence profile has 'match-across-services' enabled. This setting allows the BIG-IP to maintain the same persistence record across different virtual servers that share the same pool. This is crucial for complex applications where a user might initiate a session on one virtual service and be directed to another, as it ensures session affinity remains consistent throughout the user's entire journey across the application.

Exam trap

Candidates often assume persistence is strictly bound to a single virtual server, failing to notice the 'match-across-services' setting that allows sharing persistence records across multiple virtual servers.

43
MCQmedium

A client is experiencing intermittent connection resets when accessing a virtual server. The LTM Specialist observes that the backend servers are occasionally overwhelmed during traffic spikes. Which feature should be implemented to mitigate this impact on the backend servers?

A.Increase the idle timeout in the TCP profile.
B.Enable Connection Limits on the pool members.
C.Configure a SNAT pool with more IP addresses.
D.Change the load balancing method to Least Connections.
AnswerB

Setting connection limits ensures that a pool member will not be selected by the load balancing algorithm once its maximum concurrent connection threshold is reached. This is the standard method for managing server capacity and preventing service outages during high-demand events or traffic spikes.

Why this answer

Connection limits are the direct way to prevent backend servers from becoming overwhelmed. By setting a per-member connection limit, the BIG-IP will stop sending traffic to a server once it hits capacity, instead directing it to other available servers. This protects the backend from failure, ensuring the overall application remains available even when specific nodes are under extreme load conditions during traffic bursts.

Exam trap

Candidates often mistakenly suggest increasing the number of backend servers or modifying the load balancing algorithm, failing to realize that limiting connections is the direct mechanism to prevent server overload.

44
Multi-Selecthard

Which THREE features are provided by the BIG-IP LTM that assist in optimizing application performance?

Select 3 answers
A.TCP Express
B.HTTP Compression
C.RAM Cache
D.DNS Load Balancing
E.Firewall Rule Processing
AnswersA, B, C

TCP Express combines a set of advanced TCP optimizations to improve throughput and reliability over high-latency networks. It allows the BIG-IP to manage window sizes and retransmissions more effectively than the backend servers would, thereby significantly boosting the performance of web-based applications for remote users.

Why this answer

BIG-IP LTM offers a suite of optimization tools. TCP Express, HTTP compression, and Caching are central to reducing latency and server load. These features work together to reduce the data sent over the wire and optimize how that data is transported, significantly improving the end-user experience for slow network connections and reducing backend resource consumption.

Exam trap

Candidates frequently include security or high-availability features like ASM or connection mirroring when asked exclusively about performance optimization tools.

45
MCQmedium

Which TWO of the following are primary benefits of using an iApp Template for BIG-IP deployment?

A.Automatic translation of proprietary application logic into F5 proprietary TCL scripts.
B.Simplified management by grouping related LTM objects into a single logical entity.
C.Reduction of configuration errors through enforced deployment standardization.
D.Direct execution of remote SQL queries to backend database servers for load balancing.
E.Automatic hardware upgrades of the BIG-IP platform when capacity is reached.
AnswerB, C

One of the core design goals of iApps is to present a holistic view of an application deployment. By grouping virtual servers, pools, health monitors, and profiles together, administrators can manage the lifecycle of an entire application stack from a single unified control point within the GUI.

Why this answer

iApp templates provide a structured, simplified interface for deploying complex applications. By abstracting the creation of multiple objects (virtual servers, pools, profiles, iRules) into a single deployment unit, they reduce the risk of human error and configuration drift. These templates are essential for maintaining consistency across large environments and ensuring that best practices are followed during every configuration step.

Exam trap

Candidates often think iApps are primarily for performance optimization. In reality, their primary value is administrative governance, reducing configuration complexity, and preventing manual errors during deployment.

46
Multi-Selectmedium

An administrator wants to optimize the performance of an HTTPS-based application. Which THREE configurations should they consider to reduce load on the backend servers?

Select 3 answers
A.Enable SSL termination on the BIG-IP.
B.Configure the default 'Round Robin' load balancing method.
C.Implement HTTP compression on the BIG-IP.
D.Enable OneConnect on the virtual server.
E.Increase the maximum number of pool members.
AnswersA, C, D

SSL termination moves the CPU-intensive task of encrypting and decrypting HTTPS traffic from the backend server to the BIG-IP. Since the BIG-IP is hardware-accelerated for cryptographic operations, this dramatically reduces the load on the web servers and simplifies certificate management across the infrastructure.

Why this answer

Offloading resource-intensive tasks from the backend servers is a core function of the LTM. SSL offloading, HTTP compression, and connection pooling are key techniques. By performing decryption and compression on the BIG-IP, the backend servers are freed to focus on application logic, significantly improving response times and overall system scalability, while reducing the computational burden on the web server infrastructure.

Exam trap

Candidates often select 'Caching' or 'iRules' as primary performance optimizations, overlooking that OneConnect is specifically designed to reduce TCP handshake overhead on backend servers for HTTP traffic.

47
MCQmedium

An administrator is configuring a new virtual server and needs to ensure that it only accepts traffic on a specific VLAN. How should this be configured?

A.By applying a packet filter to the virtual server object in the GUI.
B.By modifying the 'Enabled VLANs and Tunnels' setting in the virtual server properties.
C.By adding a static route in the routing table for that VLAN.
D.By creating a SNAT pool that only contains IPs from the specific VLAN.
AnswerB

The BIG-IP virtual server configuration includes a specific setting to control which VLANs are allowed to access it. By selecting 'Enabled on all VLANs' or explicitly choosing the required VLANs, the administrator can effectively isolate traffic access, ensuring that the service is only exposed where it is intended to be reachable.

Why this answer

Configuring VLAN-specific access for a virtual server is done within the 'Resources' or 'Configuration' tab of the virtual server settings. By default, a virtual server listens on all enabled VLANs. Restricting this to a single VLAN enhances security by preventing unauthorized traffic from other network segments from reaching the virtual server and potentially exposing the application to unnecessary risk.

Exam trap

Many test-takers confuse virtual server VLAN restrictions with SNAT settings or self-IP configurations, incorrectly assuming that assigning a self-IP automatically restricts virtual server traffic to that specific VLAN.

48
MCQeasy

Which object acts as the primary configuration component that defines the destination IP address and service port for incoming client traffic?

A.Pool
B.Node
C.Virtual Server
D.Profile
AnswerC

The Virtual Server is the LTM object that defines the IP address and port upon which the BIG-IP listens for traffic. It serves as the front-end address that clients connect to, and it directs traffic to the appropriate backend pool based on the defined configuration and policies.

Why this answer

The Virtual Server is the fundamental LTM object that listens for client traffic. It acts as the gatekeeper, receiving packets on a defined IP and port, and then applying profiles, policies, and iRules before load balancing the traffic to a pool. Understanding the role of the Virtual Server is essential for all LTM operations, as it is the entry point for every application serviced by the BIG-IP device.

Exam trap

Candidates frequently mix up the roles of Pools, Nodes, and Virtual Servers, incorrectly selecting backend objects as the primary component that accepts incoming client traffic.

49
MCQeasy

Which profile type must be attached to a virtual server to allow the BIG-IP to perform Layer 7 application inspection and modification?

A.TCP Profile
B.HTTP Profile
C.Client SSL Profile
D.Persistence Profile
AnswerB

The HTTP profile enables the BIG-IP to interpret HTTP traffic. It is mandatory for any LTM functionality that requires understanding the HTTP protocol, such as inserting headers, rewriting URLs, or performing content-switching. It is the core requirement for enabling Layer 7 capabilities on any virtual server dealing with web traffic.

Why this answer

An HTTP profile is the foundation for Layer 7 processing on the BIG-IP. It allows the system to parse HTTP requests and responses, which is necessary for features like cookie persistence, header insertion, and iRule-based traffic manipulation. Without an HTTP profile, the LTM acts only at the TCP layer, limiting its ability to understand or modify application-level data, which is vital for modern web application delivery.

Exam trap

Candidates often mistake TCP profiles for Layer 7 profiles. They assume that since TCP is the transport, a TCP profile allows for application data inspection, which is false without an HTTP profile.

50
MCQmedium

What is the primary function of the 'FastL4' profile in a BIG-IP LTM configuration?

A.To enable advanced HTTP header inspection.
B.To provide high-throughput, hardware-accelerated packet switching.
C.To perform SSL offloading for encrypted traffic.
D.To manage persistence based on HTTP cookies.
AnswerB

FastL4 leverages the BIG-IP hardware's ability to offload packet processing directly to the FPGA (Field Programmable Gate Array). This enables rapid, wire-speed packet forwarding that is essential for scenarios requiring maximum throughput and low latency, without the overhead of full proxy processing at the application layer.

Why this answer

The FastL4 profile is designed for high-performance, layer 4 load balancing. It optimizes the processing of TCP or UDP traffic by bypassing the full proxy architecture for the majority of the connection's lifecycle. This allows the BIG-IP to handle a significantly higher volume of throughput and connections per second, making it ideal for large-scale deployments where deep application-layer inspection (layer 7) is not required for the specific traffic type.

Exam trap

Many students assume the FastL4 profile performs deep layer 7 inspection, confusing high-performance layer 4 switching with full proxy capabilities.

51
MCQeasy

Which monitoring method is most reliable for verifying that a web application is not just responding to TCP requests, but also returning correct application-layer data?

A.ICMP monitor
B.TCP monitor
C.HTTP monitor
D.SNMP monitor
AnswerC

The HTTP monitor sends a GET request to the target server and validates the response against a configured string. This provides high-fidelity monitoring by ensuring the web server is not only reachable and accepting connections but also actively serving correct application data, which is essential for maintaining service availability.

Why this answer

The HTTP monitor is specifically designed to perform application-layer verification by sending an actual HTTP request and waiting for a specific response string. This goes beyond simple TCP port checks, ensuring that the application server is fully functional, the web service is running, and the expected content is being served, which is vital for preventing 'false-up' states for failing web applications.

Exam trap

Candidates often select TCP monitors because they are 'easier' to configure, ignoring that a TCP monitor only checks if a port is open, not if the application is actually working.

52
MCQhard

Refer to the exhibit. A user connects to Virtual Server A, which uses the 'my_source_persistence' profile. The user is then redirected to Virtual Server B. Given the configuration, will the persistence record be honored?

A.Yes, because the timeout is set to 180 seconds.
B.No, because match-across-virtuals is disabled.
C.Yes, because source-addr persistence is global.
D.No, because the timeout must be set to indefinite.
AnswerB

With 'match-across-virtuals' explicitly disabled, the BIG-IP restricts the scope of the source address persistence record to only the specific virtual server that created it. Consequently, any requests arriving at a different virtual server will be treated as a new session, ignoring the persistence state established on the previous virtual server.

Why this answer

The persistence profile has 'match-across-virtuals' set to 'disabled'. Because this attribute is disabled, the BIG-IP will not share persistence information between Virtual Server A and Virtual Server B. When the user lands on Virtual Server B, the system will initiate a new load balancing decision instead of respecting the persistence session established on the first virtual server, which is crucial for managing multi-virtual server architectures.

Exam trap

Candidates often assume persistence is global by default, failing to check the 'match-across-virtuals' setting, which is disabled by default and prevents persistence sharing between different virtual servers.

53
MCQhard

An LTM Specialist is troubleshooting a virtual server where health monitors are failing despite the backend servers responding to ICMP. The health monitor is configured for HTTPS. Which TWO items should the specialist verify to ensure the monitor accurately reflects service availability?

A.The cipher suite compatibility between the BIG-IP and the pool member.
B.The ICMP timeout value on the internal VLAN interface.
C.The 'Receive String' configured in the HTTPS monitor.
D.The persistence profile assigned to the virtual server.
E.The SNAT pool associated with the virtual server.
AnswerA, C

The BIG-IP must support the TLS ciphers enabled on the backend server. If the monitor attempts to negotiate a protocol or cipher that the server does not support, the handshake fails immediately, causing the monitor to mark the pool member as down regardless of application status.

Why this answer

When HTTPS monitors fail despite successful ICMP responses, the issue usually involves TLS handshake failures or application-layer response mismatches. Checking the cipher compatibility ensures the BIG-IP and server can establish a secure connection. Verifying the receive string is vital because a 200 OK status code does not guarantee the application is actually functional; the BIG-IP must receive the expected content within the response body to confirm service health.

Exam trap

Candidates often rely solely on basic TCP or ICMP success, forgetting that HTTPS monitors require valid cipher matching and exact receive strings to validate application health.

54
MCQmedium

What is the primary benefit of using a 'OneConnect' profile in an HTTP virtual server?

A.It encrypts traffic to the backend.
B.It allows connection reuse to backend servers.
C.It compresses HTTP payload data.
D.It manages client persistence.
AnswerB

OneConnect allows the BIG-IP to keep backend TCP connections open after an HTTP request is completed. When a new client request arrives, the BIG-IP can reuse an existing idle connection to the pool member, eliminating the need to tear down and rebuild connections, which saves system resources and time.

Why this answer

OneConnect enables TCP connection reuse between the BIG-IP and the backend servers. By maintaining a pool of established connections, the BIG-IP avoids the overhead of repeated TCP three-way handshakes for each client request. This is particularly important for HTTP/1.1 traffic, where it significantly reduces latency and server CPU utilization, making it a critical optimization for high-traffic web applications.

Exam trap

Candidates often mistake OneConnect for a security or compression feature, failing to understand its primary role in optimizing TCP connection reuse between the BIG-IP and backend servers for HTTP/1.1.

55
MCQeasy

Which component of the BIG-IP LTM architecture is primarily responsible for the initial processing and decision-making regarding whether a packet should be forwarded to a pool member?

A.The Pool Member
B.The Virtual Server
C.The Health Monitor
D.The iControl API
AnswerB

The virtual server is the primary object that listens for client traffic. It applies the necessary LTM policies, profiles, and load balancing algorithms to determine if and where the traffic should be sent, serving as the entry point for all incoming application-layer requests and connections.

Why this answer

The Local Traffic Manager (LTM) module utilizes virtual servers to intercept incoming traffic. The virtual server acts as the central point of control, evaluating incoming packets against configured rules, policies, and profiles. This architecture allows the LTM to make intelligent load balancing decisions, ensuring traffic is directed to the most appropriate pool member based on system state, performance, and specific business logic requirements.

Exam trap

Candidates often confuse the Virtual Server with the Pool. They fail to realize that the Virtual Server is the entry point that evaluates traffic before any pool-based decisions are made.

56
MCQmedium

An LTM Specialist configures a virtual server with a destination of 10.10.10.10:80 and a default pool containing three members. A client connects to 10.10.10.10:80 and the connection is load balanced to a pool member. The Specialist then changes the virtual server's destination port from 80 to 8080. What happens to the existing client connection?

A.The existing connection is re-evaluated against the new virtual server and load balanced to a different pool member.
B.The existing connection is dropped because the virtual server no longer matches the original destination port.
C.The existing connection continues to be handled by the original virtual server and pool member until it closes.
D.The existing connection is reset immediately, and the client must reconnect to port 8080.
AnswerC

When a virtual server's destination is modified, existing connections that were already established remain associated with the original virtual server and continue to be processed by their assigned pool member. The BIG-IP maintains the connection table entry until the flow ends. New connections will use the updated virtual server configuration, but the existing session is not disrupted by the configuration change.

Why this answer

Existing connections are not affected by changes to a virtual server's destination address or port. The BIG-IP maintains the connection table entry and continues to process the flow using the original virtual server and pool member until the connection closes. New connections will use the updated configuration.

This behavior ensures that configuration changes do not disrupt active user sessions.

Exam trap

The trap here is assuming that modifying a virtual server's destination immediately affects all connections, including established ones, when in fact only new connections are impacted.

57
MCQhard

What happens when a health monitor fails for a pool member?

A.The BIG-IP sends an alert to the administrator and keeps the member active.
B.The BIG-IP marks the member as 'down' and stops sending new connections.
C.The BIG-IP automatically attempts to reboot the backend server.
D.The BIG-IP automatically removes the member from the pool configuration.
AnswerB

This is the primary function of the health monitor. By marking the member 'down', the BIG-IP effectively removes it from the pool, preventing new requests from being routed to a server that is not responding correctly. This provides automated, proactive failover and ensures high availability for the application.

Why this answer

When a health monitor fails, the BIG-IP marks the pool member as 'down' and immediately stops sending new traffic to it. Depending on the virtual server configuration, existing connections may be maintained or terminated. This automated process ensures that only healthy, verified backend servers receive traffic, which is critical for maintaining overall application availability and preventing user exposure to non-functional server components.

Exam trap

Test-takers frequently assume that a failed health monitor drops existing established connections immediately, ignoring the persistence and connection timeout settings.

58
MCQeasy

Which object in the BIG-IP LTM configuration is responsible for mapping a virtual server's incoming traffic to a specific group of backend servers?

A.Profile
B.Node
C.Pool
D.SNAT
AnswerC

A pool is a logical set of devices, such as web servers, grouped together to receive traffic. When a virtual server receives a request, it selects a pool based on its configuration, and the load balancing algorithm then picks a specific pool member to process that individual request.

Why this answer

A pool is the fundamental LTM object used to group backend servers together to handle traffic. The virtual server references a pool, and the load balancing algorithm determines which member within that pool receives the request. Understanding this relationship is critical for basic traffic management, as it is the primary mechanism for abstracting backend infrastructure and providing high availability services to clients.

Exam trap

Candidates sometimes confuse the 'Pool' with the 'Virtual Server' or 'Node', failing to recognize that the pool acts as the specific container for grouping backend servers for load balancing.

59
MCQmedium

An LTM is configured with a 'OneConnect' profile. What is the primary purpose of this feature?

A.To encrypt traffic between the BIG-IP and the backend servers.
B.To enable persistence for HTTP traffic.
C.To reuse backend TCP connections for multiple client requests.
D.To limit the number of concurrent connections per client.
AnswerC

OneConnect manages a pool of idle TCP connections to the backend servers. When a new request arrives, the LTM can reuse an existing established connection to a pool member rather than initiating a new three-way handshake, reducing latency and resource utilization on the backend servers.

Why this answer

OneConnect enables TCP connection pooling between the BIG-IP and the backend servers. By keeping backend connections open even after a client request finishes, the LTM avoids the overhead of repeated TCP handshakes. This is essential for high-performance web applications, as it significantly reduces latency and server CPU consumption, allowing the backend servers to handle a higher volume of concurrent user requests more efficiently than they could with per-request connection establishment.

Exam trap

Candidates often confuse OneConnect with HTTP Keep-Alive. While they are related, OneConnect manages the BIG-IP to server connection pooling, whereas Keep-Alive is strictly a client to BIG-IP communication mechanism.

60
MCQhard

An administrator implements a pool monitor using an HTTP GET request to verify application health. The application returns an HTTP 200 OK status, but the HTML body contains an error string indicating database connectivity failure. How should the administrator configure the monitor to mark the pool member down when this error appears?

A.Configure the monitor with a 'Receive' string that matches the database error message to validate failure.
B.Configure the monitor with a 'Receive Disable' string matching the database error message.
C.Change the monitor type to ICMP to detect underlying TCP socket failures automatically.
D.Enable reverse validation in the pool properties to invert HTTP status code return logic.
AnswerB

The 'Receive Disable' string inverts the monitor's logic: the health check passes on HTTP 200 but is forced down when the response body contains the specified database error text. This satisfies the requirement to detect application-layer failures that the status code alone cannot reveal.

Why this answer

Advanced monitors support 'Send' and 'Receive' string configurations. By specifying a 'Receive' string, the BIG-IP inspects the response body for expected content. Conversely, using a 'Receive Disable' string allows the administrator to specify a string that, if matched in the body, immediately marks the pool member down.

Exam trap

Candidates often confuse the 'Receive' string with the 'Receive Disable' string. They incorrectly assume that entering the error message in the 'Receive' field will mark the pool member down when it appears.

61
MCQmedium

Which health monitor should be used to verify that a web application is not just responding to TCP connections, but is actually serving the correct content?

A.TCP Monitor
B.ICMP Monitor
C.HTTP Monitor
D.External Monitor
AnswerC

An HTTP monitor sends a specific request to the server and checks the response against a predefined 'Receive String'. This validates that the web server is correctly processing HTTP requests and returning the expected application data, which is the only way to confirm full application availability at L7.

Why this answer

An HTTP or HTTPS monitor is required to verify the content of the response. Unlike a simple TCP monitor, which only checks for a successful three-way handshake, an HTTP monitor sends a GET request to a specific URI and checks the response for a 'Receive String'. This ensures the application layer is functioning and the web server is actually serving the expected site content.

Exam trap

Candidates frequently select TCP monitors because they are simpler to configure, forgetting that a TCP handshake only confirms the port is open and not that the application is actually functional.

62
MCQmedium

An administrator observes that the BIG-IP is not correctly load balancing traffic across all members of a pool. What is the most likely cause if the load balancing method is set to 'Least Connections'?

A.The pool members are in different subnets, preventing the load balancer from seeing all connections.
B.Persistence is enabled, causing the BIG-IP to bypass the load balancing algorithm for existing sessions.
C.The 'Ratio' load balancing method is implicitly overriding the 'Least Connections' setting.
D.The TCP profile is set to 'OneConnect', which prevents the tracking of individual connections.
AnswerB

When persistence is enabled, the BIG-IP binds a client to a specific backend server for the duration of the persistence timer. Consequently, subsequent requests from that client do not use the load balancing algorithm, resulting in traffic distribution that may not appear balanced, as persistence takes precedence over load balancing methods.

Why this answer

The 'Least Connections' method is highly dependent on the accuracy of the connection table. If persistence is configured, the BIG-IP will ignore the least connections algorithm for any request that is part of an existing session. This is a frequent point of confusion where administrators expect even distribution but see skewed results because users are 'stuck' to specific servers due to their persistence records.

Exam trap

Candidates often assume that load balancing algorithms are applied to every single request, forgetting that persistence records take precedence over the balancing algorithm for existing sessions.

63
MCQhard

An LTM is configured with a OneConnect profile. What is the primary purpose of this feature in the context of HTTP connections?

A.To increase the number of TCP connections allowed to the backend servers.
B.To enable persistent connections between the client and the BIG-IP.
C.To multiplex multiple client requests over a single server-side TCP connection.
D.To provide SSL offloading for non-HTTP traffic types.
AnswerC

OneConnect effectively decouples the client-side connection from the server-side connection. This allows the BIG-IP to keep server-side connections open and reuse them for subsequent requests from different clients, reducing the CPU and time overhead of constantly opening and closing new TCP connections for every single request.

Why this answer

OneConnect allows the BIG-IP to reuse existing connections between the BIG-IP and the backend servers. By multiplexing multiple client requests onto a smaller set of established TCP connections, it significantly reduces the overhead associated with the TCP three-way handshake and slow-start mechanism on the backend servers. This is particularly valuable for high-traffic environments where connection setup latency can become a major bottleneck for the application's response time.

Exam trap

Candidates often confuse OneConnect with load balancing algorithms, failing to recognize its specific role in multiplexing multiple client requests over a single persistent backend TCP connection.

64
MCQmedium

An administrator needs to ensure that a pool member remains part of the load balancing rotation only if it responds to specific HTTP GET requests on port 80, rather than just TCP SYN. Which action should the administrator perform?

A.Configure an ICMP monitor on the pool member.
B.Enable the 'Priority Group Activation' feature on the pool.
C.Create and assign an HTTP monitor with a specific 'Send' and 'Receive' string.
D.Change the pool's Load Balancing method to 'Least Connections'.
AnswerC

An HTTP monitor allows the BIG-IP to perform a layer 7 health check. By defining a specific 'Send' string and a 'Receive' string, the administrator ensures the web application is actively serving pages, which is critical for maintaining high availability for web-based services.

Why this answer

To validate application-level health rather than just network reachability, a custom monitor is required. By creating an HTTP or HTTPS monitor, the BIG-IP sends specific requests and verifies the content of the response. This ensures that the web service itself is functional, not just the underlying operating system or network stack, preventing the delivery of requests to unresponsive or malfunctioning application services.

Exam trap

Candidates often try to use a basic TCP monitor for application-level requirements. A TCP monitor only checks for a port, failing to verify if the application is actually providing content.

65
MCQmedium

Which component is responsible for monitoring the availability of pool members in a BIG-IP environment?

A.The iRule engine, which executes logic to check server response times.
B.The Local Traffic Manager (LTM) monitor, which performs periodic status checks.
C.The Virtual Server 'Status' setting, which acts as a heartbeat monitor.
D.The ConfigSync process, which replicates server status across the device group.
AnswerB

Health monitors are specialized processes that run at configurable intervals to verify the status of pool members. They provide the necessary intelligence to ensure that traffic is load-balanced only to functional servers, which is a core function of the LTM module's reliability and traffic management capabilities.

Why this answer

Health monitors are the entities that periodically verify the status of pool members. By sending specific probes (TCP, HTTP, ICMP, etc.), they determine if a resource is healthy. If a monitor fails, the BIG-IP marks the resource as 'down' and ceases sending traffic to it, ensuring that users are never routed to unresponsive or malfunctioning application nodes.

Exam trap

Candidates sometimes confuse the LTM monitor with the BIG-IP system's internal health check or the node's ICMP status, forgetting that LTM monitors specifically target the application service.

66
MCQhard

Refer to the exhibit. The BIG-IP LTM is configured with a simple TCP monitor. Users report that while the BIG-IP shows the pool members as 'Up', they receive a '503 Service Unavailable' error when accessing the application. What is the most likely reason for this?

A.The TCP monitor is configured with an incorrect port.
B.The pool members are not responding to the TCP SYN packets.
C.The application-level health check is missing or insufficient.
D.The load balancing algorithm is set to Round Robin.
AnswerC

The TCP monitor verifies network reachability but ignores the status of the web server software. An HTTP-based monitor is required to verify that the application returns a '200 OK' response, which would detect the 503 error being served by the underlying web application service.

Why this answer

A TCP monitor only confirms that the port is open and the operating system is accepting connections, not that the application service is operational. In this case, the web server process might have crashed or be misconfigured, leading to an HTTP 503 response. The LTM treats the server as 'Up' because the TCP handshake succeeds, failing to detect the application-level failure requiring an HTTP monitor.

Exam trap

Candidates frequently mistake a successful TCP handshake for a healthy application. They fail to realize that if the web server process is hung but the port is open, TCP monitors report success.

67
MCQhard

Which THREE actions are required to successfully implement SSL offloading on a BIG-IP virtual server?

A.Import the server certificate and private key into the BIG-IP's certificate store.
B.Create a Server SSL profile and assign it to the virtual server.
C.Configure a Client SSL profile and assign it to the virtual server.
D.Enable the 'Allow All' cipher suite in the SSL profile.
E.Configure the virtual server to listen on port 443.
AnswerA, C, E

For the BIG-IP to act as the endpoint for SSL/TLS, it must possess the server's identity. Importing the certificate and private key is essential to establish the cryptographic trust between the client and the BIG-IP, allowing the system to perform the decryption process effectively.

Why this answer

SSL offloading requires the BIG-IP to decrypt traffic before it reaches the backend. This involves importing the server's certificate and key, creating a Client SSL profile, and ensuring the virtual server is listening on the correct port (typically 443). By offloading SSL, the LTM can inspect traffic, perform security checks, and manage persistence, which is not possible if the traffic remains encrypted from the client to the backend server.

Exam trap

Candidates often forget that SSL offloading requires a Client SSL profile, mistakenly assuming that simply binding a server certificate enables decryption.

68
MCQhard

An administrator wants to reduce the load on the backend servers by caching static content. Which BIG-IP feature should be configured?

A.Enable the 'OneConnect' profile to pool backend connections.
B.Create an iRule to store request data in the BIG-IP session table.
C.Apply a Web Acceleration profile with an enabled cache object.
D.Configure the 'HTTP-Compress' profile to shrink the size of responses.
AnswerC

The Web Acceleration profile is the native, optimized way to implement HTTP caching on the BIG-IP. It allows administrators to define cache policies based on URI, file type, or HTTP response headers, ensuring that static content is served directly from the BIG-IP’s memory, which is much faster and reduces backend server utilization.

Why this answer

The Web Acceleration profile provides built-in HTTP caching capabilities. By enabling this on a virtual server, the BIG-IP can cache static assets like images, CSS, and JS files, serving them directly from memory and significantly reducing the number of requests that reach the backend web servers. This is a highly effective way to improve application performance and scalability without modifying the backend application code.

Exam trap

Candidates often look for a 'Caching' profile instead of the 'Web Acceleration' profile, which is the actual container for the caching functionality in modern BIG-IP versions.

69
MCQhard

Refer to the exhibit. Clients are reporting 'SSL Handshake Failure' errors. What is the most likely cause?

A.The certificate has expired.
B.The cipher string excludes TLS 1.0, which some clients require.
C.The virtual server is missing an HTTP profile.
D.The key and certificate do not match.
AnswerB

The exclusion '!TLSv1' removes support for TLS 1.0. If the connecting client only supports TLS 1.0, the handshake will fail immediately because there is no common protocol version that both the BIG-IP and the client can agree upon for the encrypted session.

Why this answer

The cipher string 'DEFAULT:!SSLv3:!TLSv1' explicitly disables TLS 1.0. Many legacy clients still require TLS 1.0 to establish a handshake. By excluding it, the BIG-IP is rejecting any connection attempt from clients that do not support TLS 1.1 or higher.

This is a common configuration error when trying to harden security without auditing the client base's compatibility first.

Exam trap

Candidates assume the cipher string is just about security strength, missing that '!TLSv1' explicitly disables compatibility for older clients, which is the most common cause of handshake failures in legacy environments.

70
MCQeasy

Which CLI command is used to view the real-time status of pool members and their current connection counts?

A.tmsh list ltm pool
B.tmsh show ltm pool
C.tmsh monitor ltm pool
D.tmsh status ltm pool
AnswerB

The 'tmsh show ltm pool' command provides a detailed view of the pool's current operational state, including health status (Available/Offline), total connections, and traffic throughput per member. This is the correct command for obtaining real-time performance metrics and availability data required for effective troubleshooting and system monitoring.

Why this answer

The 'tmsh show ltm pool' command is the primary tool for administrators to inspect the current state of load-balanced resources. It provides immediate visibility into member health, active connections, and traffic statistics. Being proficient with this command is essential for daily monitoring and rapid incident response, as it allows operators to quickly identify overloaded nodes or servers that have unexpectedly failed their health checks during production operations.

Exam trap

Candidates frequently confuse 'tmsh list' with 'tmsh show'. While 'list' displays the configuration settings, 'show' is required to retrieve the real-time operational statistics and connection counts.

71
MCQhard

Refer to the exhibit. If a client connects to the BIG-IP and the persistence profile is applied, what happens when the session expires?

A.The cookie remains on the client machine until manually deleted.
B.The cookie is removed when the browser session ends.
C.The BIG-IP forces the client to re-authenticate immediately.
D.The cookie remains valid for 3600 seconds as the default.
AnswerB

The 'expiration 0' parameter specifies that the cookie is a session-based cookie. According to browser standards, these cookies are deleted from memory as soon as the browser instance is terminated. This is the expected behavior for short-term session persistence where long-term tracking is not required.

Why this answer

The 'expiration 0' setting in the cookie persistence profile indicates that the persistence cookie is a session cookie, which persists as long as the browser remains open. Once the browser is closed, the cookie is deleted. Understanding how session versus persistent cookies function is vital for LTM administrators to manage user experience and ensure that session stickiness is maintained correctly across different browser behaviors and application requirements.

Exam trap

Candidates mistakenly believe a cookie with 'expiration 0' lasts forever. In reality, setting the expiration to zero makes it a session cookie, meaning it expires when the browser closes.

72
MCQmedium

Why would an LTM Specialist choose to implement a SNAT Automap instead of a SNAT pool?

A.To increase security by using multiple source IP addresses.
B.To reduce administrative overhead for simple configurations.
C.To prevent port exhaustion on the BIG-IP.
D.To allow backend servers to track unique client IP addresses.
AnswerB

SNAT Automap requires no manual IP management. It automatically selects the system's floating self-IP, making it the most efficient option for standard deployments. This simplifies configuration and reduces the risk of errors associated with manual IP pool maintenance, making it a preferred choice for straightforward translation requirements.

Why this answer

SNAT Automap is the simplest way to manage source translation because it automatically uses the BIG-IP's floating self-IP address. It is ideal for environments where a dedicated pool of IP addresses is not required. This reduces administrative complexity and configuration overhead, which is beneficial for smaller deployments or scenarios where the backend servers only need to see the BIG-IP as the source of traffic.

Exam trap

Candidates often believe SNAT Automap provides better performance than SNAT pools. In reality, the decision is purely about administrative simplicity and reducing configuration overhead rather than hardware throughput gains.

73
MCQmedium

Which load balancing method is most appropriate for a pool where servers have significantly different hardware specifications and processing capabilities?

A.Round Robin
B.Least Connections
C.Ratio
D.Observed
AnswerC

Ratio load balancing allows administrators to assign a weight to each server. Servers with higher hardware capacity can be assigned a higher ratio, meaning they will receive a larger portion of the total traffic load, which prevents weaker servers from becoming bottlenecks in a mixed-hardware environment.

Why this answer

When pool members have varying hardware specs, simple algorithms like Round Robin perform poorly because they send equal traffic to all servers regardless of their ability to handle it. 'Ratio' load balancing allows the administrator to assign a weight to each server, ensuring more powerful servers receive a higher proportion of traffic, which optimizes overall application performance and prevents the saturation of weaker servers.

Exam trap

Candidates often select 'Least Connections' for hardware-mismatched servers, assuming it accounts for processing power, when it actually only tracks the number of active connections regardless of server capacity.

74
MCQmedium

Which profile is essential to enable when you need to inspect or manipulate HTTP traffic, such as inserting X-Forwarded-For headers?

A.TCP Profile
B.HTTP Profile
C.Client SSL Profile
D.FastL4 Profile
AnswerB

The HTTP profile is the foundation for all Layer 7 functionality on the BIG-IP. It allows the system to understand the HTTP protocol, which is a prerequisite for any modification of HTTP headers, such as the X-Forwarded-For header, or for implementing cookie-based persistence mechanisms.

Why this answer

The HTTP profile is required for any Layer 7 processing. Without an HTTP profile, the BIG-IP treats traffic as raw TCP streams. By enabling the HTTP profile, the LTM gains the ability to parse HTTP requests and responses, allowing for features like header manipulation, cookie persistence, and content switching, which are standard requirements for modern web application delivery controllers.

Exam trap

Test-takers often confuse TCP profiles with HTTP profiles, assuming standard TCP handles application-layer modifications like header insertion natively without L7 parsing.

75
MCQeasy

What is the primary function of a BIG-IP LTM monitor?

A.To encrypt traffic between the client and the BIG-IP.
B.To balance traffic load across multiple pool members.
C.To determine the availability of a pool member.
D.To translate source IP addresses for outgoing traffic.
AnswerC

The primary role of a monitor is to perform health checks on pool members. If a check fails, the monitor marks the member as 'down' and removes it from the load balancing pool, ensuring that traffic is redirected only to healthy, operational servers in the infrastructure.

Why this answer

Monitors are used to verify the operational status and health of backend pool members. By periodically checking specific services, the BIG-IP ensures that traffic is only sent to functional servers. This prevents black-holing traffic and maintains high availability, as the BIG-IP will automatically stop sending requests to any member that fails its configured health check, providing seamless failover for users.

Exam trap

Candidates often confuse monitors with load balancing methods or persistence profiles, incorrectly assuming that monitors actively route traffic or maintain session state rather than simply checking for backend server health.

Page 1 of 2 · 119 questions totalNext →

Ready to test yourself?

Try a timed practice session using only BIG-IP Local Traffic Manager questions.