Courseiva

CCNA Big IP Local Traffic Manager Questions

44 of 119 questions · Page 2/2 · Big IP Local Traffic Manager topic · Answers revealed

76
MCQmedium

What is the primary function of the 'OneConnect' profile in a BIG-IP LTM configuration?

A.To perform SSL decryption for client-side traffic.
B.To allow for HTTP header insertion.
C.To enable TCP connection reuse to backend servers.
D.To enforce persistence based on client IP.
AnswerC

OneConnect allows the BIG-IP to maintain a pool of idle connections to the backend servers. When a new client request arrives, the BIG-IP can use an existing connection instead of initiating a new TCP handshake, which drastically reduces the load on the backend servers and improves application response times.

Why this answer

The OneConnect profile enables connection pooling between the BIG-IP and the backend servers. By keeping backend connections open even after a client request is fulfilled, the BIG-IP can reuse these existing connections for subsequent requests. This reduces the overhead associated with the TCP three-way handshake for every new request, significantly lowering the CPU utilization on backend servers and improving overall latency.

Exam trap

Candidates often confuse OneConnect with client-side connection pooling or HTTP compression, mistakenly believing it reduces client-side TCP handshakes rather than backend server-side TCP connection overhead.

77
MCQhard

A company requires that traffic be load balanced based on server response time. The LTM must dynamically select the server that is currently responding the fastest. Which load balancing algorithm should be used?

A.Round Robin
B.Least Connections
C.Fastest
D.Observed
AnswerC

The Fastest algorithm is specifically designed to route traffic to the pool member with the lowest observed response time. This ensures that users always receive responses from the most responsive server, optimizing the overall end-to-end application delivery performance in environments with variable server response times.

Why this answer

The 'Fastest' load balancing algorithm tracks the time it takes for a server to respond to a request. The BIG-IP uses this metric to dynamically direct new connections to the pool member that currently provides the lowest latency. This is highly effective in environments where server performance varies due to heterogeneous hardware or fluctuating application loads.

Exam trap

Candidates often confuse the 'Fastest' algorithm with 'Least Connections'. They fail to recognize that 'Fastest' specifically monitors response latency, which is the key requirement for dynamic performance-based load balancing.

78
MCQmedium

You have a requirement to distribute traffic to pool members based on the total number of active connections each server is currently handling. Which load balancing method should be selected?

A.Round Robin
B.Least Connections (member)
C.Ratio (member)
D.Observed (member)
AnswerB

This method counts the active connections on each member and routes new requests to the member with the lowest count. It is highly effective at maintaining an even distribution of work, ensuring that no single backend server becomes a bottleneck due to an accumulation of long-lived sessions.

Why this answer

The 'Least Connections' method is the correct choice for load balancing based on active session counts. This algorithm dynamically tracks the current load on each server and directs new requests to the member with the fewest active connections. It is essential for application environments where individual requests vary significantly in duration or resource consumption, preventing any single server from becoming overwhelmed.

Exam trap

Candidates often confuse 'Least Connections' with 'Least Sessions' or 'Fastest'. They fail to distinguish between connection tracking and session-based persistence, leading to incorrect load balancing algorithm selection on the exam.

79
MCQhard

An administrator implements Priority Group Activation on a pool containing four web servers. Two servers are assigned priority 10, and two servers are assigned priority 5. The minimum active members parameter is set to 2. One priority 10 member fails. What is the precise traffic distribution behavior of the BIG-IP system?

A.Traffic ceases entirely for all pool members until administrators manually intervene and adjust the priority group thresholds via TMOS.
B.Traffic is balanced exclusively between the single remaining priority 10 member and the two priority 5 members.
C.Traffic distribution shifts completely to the two priority 5 servers, and the remaining priority 10 server is taken offline immediately.
D.Traffic is distributed strictly among the two priority 5 servers while the remaining priority 10 server acts as a standby hot spare.
AnswerB

When active priority 10 members fall below the minimum active threshold of 2, the BIG-IP system activates the priority 5 group while continuing to utilize the surviving priority 10 member, combining active members from both groups according to the load balancing algorithm.

Why this answer

Priority Group Activation directs traffic to the highest available priority group until the number of active members in that group drops below the specified minimum active members threshold. When one priority 10 member fails, one remains active, which is below the minimum threshold of 2, triggering activation of the lower priority group while keeping the remaining priority 10 member active.

Exam trap

Candidates assume that lower-priority groups remain completely idle until all higher-priority members fail, ignoring the minimum active members threshold rule.

80
MCQhard

An administrator wants to redirect all incoming HTTP traffic on port 80 to HTTPS on port 443. What is the most effective approach?

A.Configure the existing HTTPS VS to also listen on port 80.
B.Use an iRule on a separate HTTP virtual server to send a redirect.
C.Enable 'Force HTTPS' in the pool configuration.
D.Use a SNAT pool to force traffic to port 443.
AnswerB

Creating a virtual server dedicated to HTTP traffic and applying a simple 'HTTP::respond 301 Location...' iRule is the industry-standard way to force HTTPS. It is performant, easy to audit, and allows for clean management of redirection rules without cluttering the main HTTPS virtual server configuration.

Why this answer

Creating a separate HTTP virtual server that uses an iRule to perform a 301 or 302 redirect is the most effective method. This keeps the logic clean and separates the handling of unencrypted traffic (redirecting it) from the encrypted virtual server that handles the actual application traffic, ensuring clear separation of concerns in the configuration while maintaining a secure user experience.

Exam trap

Many candidates attempt to handle HTTP-to-HTTPS redirection directly within a single HTTPS virtual server, causing infinite loops or unhandled plaintext requests.

81
MCQmedium

Which THREE criteria determine how a BIG-IP selects a pool member for a new client connection?

A.The configured load balancing method.
B.The physical location of the client's ISP.
C.Active persistence records.
D.The current health state of the pool members.
E.The CPU speed of the client's device.
AnswerA, C, D

The load balancing method is the primary algorithm used to choose a member when no persistence is found. It dictates the distribution strategy, such as distributing traffic equally, based on connection counts, or based on server capacity, ensuring the load is spread according to the administrator's design.

Why this answer

Load balancing decisions are multi-faceted. The BIG-IP considers the configured load balancing method (e.g., Round Robin, Least Connections), the status of the pool members (only active members are eligible), and any active persistence records that might override the load balancing method for returning clients. These three factors combine to ensure traffic is distributed intelligently and consistently across the available server pool.

Exam trap

Candidates often forget that persistence overrides the load balancing method. They assume the load balancing algorithm is the sole factor, ignoring that active sessions force traffic to specific members.

82
MCQmedium

An administrator wants to use a single Virtual Server to handle both HTTP and HTTPS traffic for the same domain. What is the recommended way to achieve this?

A.Use a single Virtual Server on port 80 with an iRule to handle SSL.
B.Use two Virtual Servers and an iRule to redirect port 80 to 443.
C.Use a single Virtual Server with 'Any' port enabled.
D.Create one Virtual Server on 443 and disable port 80.
AnswerB

This is the industry-standard approach. The port 80 VS simply performs a '301 Moved Permanently' or '302 Found' redirect to the HTTPS URL. The HTTPS VS then contains the SSL profile and the backend pool configuration, ensuring secure communication for all clients once they are redirected.

Why this answer

The most efficient way to manage both HTTP and HTTPS is to create two separate virtual servers: one on port 80 and one on port 443. The port 80 virtual server should then use an iRule to redirect users to the HTTPS virtual server. This ensures that all traffic is encrypted while providing a seamless user experience, as the user only needs to type the domain name to be redirected correctly.

Exam trap

Candidates often attempt to handle both HTTP and HTTPS using a single virtual server without realizing that separate ports require distinct virtual server definitions.

83
MCQmedium

An LTM administrator needs to ensure that client SSL traffic is offloaded at the BIG-IP while maintaining end-to-end encryption to the backend servers. Which profile configuration is required to achieve this?

A.Apply only a Client SSL profile to the virtual server.
B.Configure a FastL4 profile with SSL persistence enabled.
C.Assign both a Client SSL profile and a Server SSL profile to the virtual server.
D.Disable the Client SSL profile and enable a Server SSL profile only.
AnswerC

Assigning both profiles enables SSL Bridging. The Client SSL profile decrypts the incoming request, allowing the LTM to inspect or modify the payload. The Server SSL profile then encrypts the request before forwarding it to the backend server, ensuring security is maintained across the entire path of the transaction.

Why this answer

To achieve SSL offloading with backend encryption, the LTM must terminate the client-side SSL using a Client SSL profile and then initiate a new SSL connection to the server using a Server SSL profile. This architecture, known as SSL Bridging, is critical for organizations needing to perform deep packet inspection or Layer 7 load balancing while maintaining security compliance protocols between the load balancer and the internal server pool members.

Exam trap

Candidates frequently forget the Server SSL profile, assuming that client-side decryption is enough, which would leave the traffic unencrypted between the BIG-IP and the backend server.

84
MCQmedium

A virtual server is configured with a OneConnect profile. What is the primary benefit of enabling OneConnect in this scenario?

A.It enables hardware-based SSL offloading.
B.It reduces the number of TCP connections opened on backend servers.
C.It forces all traffic to be encrypted using the strongest ciphers.
D.It eliminates the need for Source Address persistence.
AnswerB

OneConnect enables TCP connection pooling. By multiplexing multiple incoming requests onto a single persistent backend connection, the BIG-IP avoids the need for the backend servers to constantly open and close new TCP sockets, which saves significant CPU and memory resources on the servers.

Why this answer

OneConnect allows the BIG-IP to reuse existing TCP connections between the BIG-IP and the backend pool members. By multiplexing many client-side requests over a smaller number of established server-side connections, it significantly reduces the overhead of TCP handshake (SYN/ACK) processes on the backend servers. This is particularly effective for high-traffic applications that use short-lived HTTP connections, leading to improved server resource utilization and overall application latency.

Exam trap

Candidates mistakenly believe OneConnect is for client-side performance, whereas its main benefit is actually reducing the number of TCP connections the backend servers must maintain and process.

85
MCQmedium

Which component of the BIG-IP architecture is responsible for performing the actual load balancing of traffic to pool members?

A.The Linux kernel
B.The TMM (Traffic Management Microkernel)
C.The Control Plane
D.The Configuration Utility (GUI)
AnswerB

TMM is the core processing component designed specifically for fast, efficient traffic manipulation and load balancing. It operates outside the standard Linux kernel to ensure that the BIG-IP can process millions of concurrent connections with extremely low latency, which is essential for performance-critical application delivery tasks.

Why this answer

The TMM (Traffic Management Microkernel) is the heart of the BIG-IP system. It is a specialized, high-performance kernel that handles all traffic processing, including load balancing, SSL termination, and iRule execution. Unlike the standard Linux kernel, which handles management tasks, the TMM is optimized for high-throughput packet processing, which is the core requirement for LTM services in modern network environments.

Exam trap

Candidates often confuse the TMM with the management interface or the Linux kernel. They fail to distinguish the high-performance traffic processing engine from standard system management tasks.

86
MCQmedium

When implementing SNAT Automap on a virtual server, what is the source IP address of the traffic as it arrives at the backend server?

A.The original client source IP address.
B.The Virtual Server IP address.
C.The BIG-IP egress Self-IP address.
D.The default gateway address of the LTM.
AnswerC

SNAT Automap automatically chooses the self-IP address of the interface that the BIG-IP uses to route traffic to the destination pool member. This ensures return traffic from the server reaches the BIG-IP, facilitating successful two-way communication when the backend server lacks a route back to the client network.

Why this answer

SNAT Automap causes the BIG-IP to translate the client's source IP address to the self-IP address of the egress interface used to communicate with the pool member. This is a key design pattern for ensuring that backend servers can reply directly to the BIG-IP without needing to update their default gateways, which is essential for deployments where the BIG-IP is not the default gateway for the backend servers.

Exam trap

Candidates frequently confuse the client's original source IP with the BIG-IP address, forgetting that SNAT Automap performs address translation to the egress Self-IP to ensure return traffic hits the BIG-IP.

87
MCQeasy

Which component should an administrator monitor to identify if the BIG-IP is hitting its licensed throughput limit?

A.The system's disk space usage.
B.The total system throughput statistics.
C.The number of configured virtual servers.
D.The total number of user accounts.
AnswerB

Throughput statistics, visible in the dashboard or via SNMP, allow administrators to track the current traffic volume against the licensed limit. Monitoring this ensures that the device operates within its licensed capacity, preventing unexpected traffic shaping or rate limiting that would negatively impact the performance of hosted applications.

Why this answer

Monitoring the performance statistics, specifically bits per second or total throughput, is essential for capacity planning. If the BIG-IP exceeds its licensed throughput, it may rate-limit traffic, leading to performance degradation or dropped packets. Proactive monitoring ensures that administrators can upgrade licenses or scale out their BIG-IP deployments before hitting these hard performance caps that impact the end-user experience for critical production applications.

Exam trap

Candidates often look for specific hardware fault logs or CPU usage metrics, failing to recognize that throughput licensing is tracked via total system throughput statistics, not just resource utilization.

88
MCQmedium

What is the primary function of a 'Clone Pool' in an LTM virtual server configuration?

A.To provide high availability for the backend pool members.
B.To mirror incoming traffic to an out-of-band monitoring device.
C.To distribute traffic across two different data centers simultaneously.
D.To act as a backup pool if the primary pool fails.
AnswerB

The primary use of a clone pool is to replicate incoming packets to a specific pool of monitoring devices. This is essential for security teams who need to analyze traffic patterns or detect threats using network-based intrusion detection systems without adding latency or complexity to the production application flow.

Why this answer

A Clone Pool is used for traffic replication. It allows the BIG-IP to send a copy of the traffic (packets) to a secondary destination, such as an IDS (Intrusion Detection System) or a packet capture device, without affecting the primary traffic flow to the actual application servers. This is a common requirement for security compliance and troubleshooting, as it allows deep packet inspection on traffic that is intended for the production backend.

Exam trap

Candidates confuse clone pools with standard load-balancing pools, thinking clone pools actively distribute production client requests among multiple primary servers.

89
MCQmedium

What happens to the BIG-IP system when the failover trigger occurs in a high-availability pair?

A.The configuration is wiped and reset to factory defaults.
B.The secondary unit becomes the active unit and assumes the floating IPs.
C.The traffic is dropped until an administrator reboots the system.
D.The BIG-IP enters a maintenance mode to run diagnostics.
AnswerB

In an HA pair, the standby unit is constantly monitoring the status of the active unit. Upon failure, it promotes itself to 'active' status and assumes ownership of all floating IP addresses, ensuring that traffic addressed to those IPs is seamlessly directed to the now-active unit instead.

Why this answer

During a failover, the standby unit assumes control by taking over the floating IP addresses and processing the traffic load. The former active unit transitions to standby mode. This process is orchestrated by the failover mechanism to ensure high availability, with the 'active' status moving to the secondary unit to prevent service disruption, provided that connection mirroring was configured for active sessions.

Exam trap

Candidates often think both units stay active or that traffic drops completely, failing to recognize that the standby unit assumes floating IPs and becomes active.

90
MCQhard

An application requires persistence based on a specific custom header named 'X-Session-ID'. The LTM Specialist has confirmed the header is always present in requests. Which persistence method is most appropriate?

A.Cookie Insert persistence
B.Universal persistence
C.Source Address persistence
D.Hash persistence
AnswerB

Universal persistence allows for custom persistence logic based on any data within the request, including headers. By using an iRule to extract the 'X-Session-ID' value and calling 'persist uie', the BIG-IP maintains a mapping table entry for that specific ID, ensuring consistent routing.

Why this answer

Universal persistence is the only method that allows the BIG-IP to persist traffic based on arbitrary data found within the request. By extracting the value of the 'X-Session-ID' header using an iRule and mapping it to a persistence record, the BIG-IP can ensure that all requests with the same session ID are consistently routed to the same backend server, regardless of the client's IP address.

Exam trap

Candidates often suggest Source Address persistence, incorrectly believing it will work for custom application headers. They fail to realize that Source Address only looks at the client's IP, not request content.

91
MCQmedium

What is the primary function of the 'OneConnect' profile in a BIG-IP LTM environment?

A.It enables SSL offloading for encrypted traffic.
B.It improves performance by reusing server-side TCP connections.
C.It provides a mechanism for persistence across multiple pools.
D.It forces traffic to use HTTP/2 instead of HTTP/1.1.
AnswerB

OneConnect enables TCP connection multiplexing. It holds open server-side connections and reuses them for new client requests, preventing the overhead of creating new TCP handshakes for every request. This is a critical performance optimization for web applications that generate large amounts of short-lived connections to backend servers.

Why this answer

OneConnect allows the BIG-IP to reuse server-side TCP connections for multiple client-side requests. This reduces the overhead of repeatedly opening and closing TCP connections to the backend servers, which is highly beneficial for high-traffic applications. By maintaining a pool of idle connections to the servers, the system significantly improves performance and reduces the CPU load associated with the TCP three-way handshake on the backend.

Exam trap

Candidates often confuse OneConnect with 'Persistence' or 'Caching', assuming it is meant to keep users on the same server rather than optimizing the TCP connection lifecycle.

92
Multi-Selecthard

An LTM administrator is configuring a new virtual server and needs to ensure that only specific source networks can access the application. Which TWO methods can be used to restrict access?

Select 2 answers
A.Configure an iRule in the CLIENT_ACCEPTED event to drop connections from unauthorized IPs.
B.Set the virtual server type to 'Forwarding (IP)'.
C.Apply a Local Traffic Policy with a 'drop' action for disallowed source addresses.
D.Assign a FastL4 profile to the virtual server to block unwanted traffic.
E.Increase the 'Idle Timeout' value in the TCP profile.
AnswersA, C

The 'CLIENT_ACCEPTED' event is the perfect place to enforce IP-based security. By checking 'IP::client_addr' and using the 'drop' command, the BIG-IP terminates unauthorized connections before any further resources are consumed, providing an efficient and secure way to implement access control lists directly within the traffic flow.

Why this answer

Restricting access is a fundamental security requirement for LTM deployments. Using either an iRule to drop unauthorized connections or a Local Traffic Policy is a standard security practice. These methods provide granular control, allowing administrators to filter traffic based on source IP, CIDR blocks, or other criteria before the request is processed by the pool, effectively mitigating unauthorized access at the network edge.

Exam trap

Test-takers often look for traditional firewall rule options, forgetting that LTM features like iRules and Local Traffic Policies handle source address filtering directly.

93
MCQhard

When deploying a BIG-IP LTM in a high-availability (HA) pair, what is the purpose of the 'Failover' cable or link?

A.To synchronize the configuration files across both units.
B.To detect the failure of the peer device via heartbeat signals.
C.To mirror active connection states for seamless failover.
D.To increase the total throughput capacity of the cluster.
AnswerB

The failover link is dedicated to monitoring the health of the peer BIG-IP. By exchanging heartbeats, the devices can instantly detect a hardware or software crash on the peer. This is the trigger mechanism for the failover process, ensuring that traffic is seamlessly moved to the standby unit.

Why this answer

The failover link, often implemented via dedicated network interfaces or shared backplanes, is used for the continuous exchange of heartbeat signals between the two BIG-IP devices. This ensures that each unit knows the operational status of its peer. If the heartbeat is lost, the standby unit assumes the active unit has failed and triggers a failover, promoting itself to active to maintain service continuity.

Exam trap

Candidates often confuse the failover link with the synchronization (configsync) cable. They believe the failover link is used to transfer configuration data, which is incorrect.

94
MCQmedium

Refer to the exhibit. The monitor is failing even though the page exists. What is the most likely cause?

A.The monitor timeout is too low.
B.The HTTP version is unsupported.
C.The receive string is too restrictive.
D.The send string is missing the User-Agent header.
AnswerC

The '200 OK' string is highly specific. Depending on the server's implementation, the raw HTTP response might include extra whitespace, different header ordering, or formatted body content that prevents an exact match. Using a more flexible regex or just checking for the status code is a best practice.

Why this answer

The 'recv' string is set to '200 OK', but the HTTP monitor often returns the full response, including headers. If the server response contains the status code without the exact string '200 OK', or if the casing differs, the monitor will fail. This scenario emphasizes the importance of precise regex or string matching in health monitors to avoid false negatives in service availability monitoring.

Exam trap

Candidates often assume a monitor is failing due to a server error, failing to realize that overly specific or incorrectly cased 'receive' strings will cause the monitor to fail.

95
MCQhard

A BIG-IP administrator creates a Standard Virtual Server with source address translation set to 'Automated Map'. During peak hours, clients behind a specific corporate NAT gateway experience intermittent connection drops. What is the mechanism and impact of 'Automated Map' in this scenario?

A.It translates client source IPs using a dedicated SNAT pool, causing IP address collisions with upstream gateways.
B.It maps client source ports to a fixed range, restricting concurrent connections from individual subnet prefixes.
C.It uses the system self IP addresses as translation addresses, which can lead to port exhaustion under high connection rates.
D.It disables connection tracking, forcing clients to establish direct routing paths that bypass the internal firewall.
AnswerC

Automated Map leverages internal self IP addresses to perform source address translation for incoming client sessions. When many clients share a single source IP through upstream NAT, port exhaustion occurs rapidly because each TCP socket requires a unique source port.

Why this answer

Automated Map creates a temporary SNAT translation using available self IP addresses on the BIG-IP system. If traffic volume exhausts available source ports for a given self IP, connection attempts fail. High client concurrency through a shared NAT gateway exacerbates port exhaustion on the SNAT address, leading to dropped connections.

Exam trap

Candidates frequently overlook the fact that 'Automated Map' consumes source ports from the self IP. They often assume it is a limitless translation method rather than one prone to port exhaustion.

96
MCQmedium

An administrator observes that the 'Least Connections' load balancing algorithm is not distributing traffic as evenly as expected. What is the most probable reason?

A.The pool members have different weight values configured.
B.Persistence profiles are overriding the load balancing algorithm.
C.The TCP profile is set to 'OneConnect' mode.
D.The health monitor is failing intermittently.
AnswerB

Persistence profiles force traffic to a specific pool member for the duration of the session. Because this decision happens before the load balancing algorithm is even consulted, the 'Least Connections' algorithm is bypassed for all persistent traffic, naturally resulting in an uneven distribution of active connections.

Why this answer

Least Connections distributes traffic based on the number of active connections to each pool member. If persistence is enabled, the BIG-IP will send subsequent requests from the same client to the same server, regardless of the load balancing algorithm. Consequently, persistence overrides the load balancing decision, leading to uneven distribution if certain sessions are longer or more active than others.

Exam trap

Candidates often blame the load balancing algorithm for uneven traffic distribution. They forget that persistence forces clients to specific members, effectively ignoring the algorithm's calculation for those persistent sessions.

97
MCQmedium

Which component of the BIG-IP LTM architecture is responsible for performing the actual load balancing decisions based on the configured algorithm?

A.Configuration Utility (GUI)
B.Traffic Management Microkernel (TMM)
C.Local Traffic Manager (LTM) daemon
D.iControl API
AnswerB

TMM is the purpose-built kernel responsible for processing all network traffic in the BIG-IP system. It executes the load-balancing algorithms, manages persistence, and handles protocol-specific logic, ensuring high-speed processing and deterministic performance for all traffic flows entering the BIG-IP environment.

Why this answer

The Traffic Management Microkernel (TMM) is the core engine of the BIG-IP. It handles all packet processing, protocol parsing, and load balancing decisions. Mastering TMM's role is essential for LTM certification, as it allows administrators to understand why the BIG-IP can perform high-speed Layer 7 inspection and why it is so much more efficient than software-based load balancers that rely on general-purpose operating system networking stacks.

Exam trap

Candidates often incorrectly attribute load balancing decisions to the Virtual Server or the Configuration Utility, failing to understand that the TMM is the actual engine executing the logic.

98
MCQhard

Refer to the exhibit. The web server logs show the source IP is the BIG-IP Self IP. Why is this happening despite the X-Forwarded-For configuration?

A.The HTTP profile is misconfigured and needs an iRule to function.
B.SNAT is enabled on the virtual server, causing source translation.
C.The virtual server is missing a Client SSL profile.
D.The pool members are in a different subnet than the virtual server.
AnswerB

SNAT overrides the original client source IP with the BIG-IP's address at the network layer. Even with an X-Forwarded-For header present, the network-level source IP seen by the web server will be the BIG-IP's IP unless SNAT is disabled or the backend server is configured for XFF.

Why this answer

The 'Insert X-Forwarded-For' setting only adds an HTTP header; it does not change the source IP address of the TCP packet. If the backend server sees the BIG-IP Self IP, it is because SNAT (Secure Network Address Translation) is active and is translating the client's source IP to the BIG-IP's address. The X-Forwarded-For header is present, but the server must be configured to read it.

Exam trap

Candidates often assume that 'Insert X-Forwarded-For' automatically hides the SNAT IP, failing to realize that the header and the source IP translation are two completely independent BIG-IP configuration settings.

99
MCQhard

Refer to the exhibit. An administrator wants to modify this configuration to support persistence for this application. Which command should be added to the virtual server configuration?

A.persist /Common/cookie
B.profile /Common/cookie
C.persistence-mode cookie
D.pool /Common/pool_http persist
AnswerA

Adding 'persist /Common/cookie' attaches the default cookie persistence profile to the virtual server. This ensures that the BIG-IP will insert a persistence cookie into the HTTP response, allowing subsequent requests from the same client to be consistently routed to the same backend pool member as required.

Why this answer

To enable persistence on a Virtual Server, you must attach a persistence profile to the 'persist' attribute of the virtual server object. Simply having the pool members defined is insufficient for maintaining session affinity. This is a core concept in BIG-IP configuration; without a persistence profile, the LTM defaults to the load balancing algorithm, which may bounce users between different servers, breaking application sessions.

Exam trap

Many candidates assume persistence is enabled automatically when a pool is attached, forgetting that persistence profiles must be explicitly assigned to the virtual server configuration.

100
MCQhard

Refer to the exhibit. The administrator wants to use cookie persistence, but it is not working. What is missing from the configuration?

A.The virtual server is missing a default persistence profile.
B.The cookie profile mode must be set to 'rewrite'.
C.The HTTP profile needs to be set to 'oneconnect'.
D.The virtual server requires an iRule to parse the cookie.
AnswerA

Even if the profile exists in the configuration, it must be assigned to the virtual server's persistence settings. Without this linkage, the BIG-IP will use the default load balancing algorithm for every request, completely ignoring the persistence profile, which is a common configuration oversight for new virtual servers.

Why this answer

The cookie persistence profile is defined but not actually attached to the virtual server. In BIG-IP LTM, simply creating a profile is not enough; it must be explicitly assigned to the virtual server under the 'persistence' section of the virtual server configuration. Without this assignment, the LTM does not know to inject the cookie into the response headers.

Exam trap

Candidates assume that creating a profile automatically applies it to the virtual server. They forget that the profile must be explicitly selected within the virtual server's resource configuration settings.

101
MCQeasy

An administrator needs to perform a graceful shutdown of a server in a load-balanced pool without interrupting existing user sessions. Which action should be taken?

A.Set the node status to 'Forced Offline'.
B.Delete the node from the pool configuration.
C.Set the node status to 'Disabled'.
D.Disable the health monitor associated with the node.
AnswerC

Setting a node to 'Disabled' is the correct procedure for graceful maintenance. It stops new connections from being routed to the member while allowing existing connections to finish naturally. This ensures zero impact on currently active user sessions while the node is being prepared for maintenance.

Why this answer

To gracefully remove a node, the administrator should set the node or pool member state to 'Disabled'. When a node is 'Disabled', the BIG-IP stops sending new connections to it but allows existing connections to persist until they complete or time out. This is critical for maintaining a positive user experience during maintenance windows, preventing the immediate termination of active sessions that would occur if the node were set to 'Forced Offline'.

Exam trap

Candidates confuse 'Disabled' with 'Forced Offline', leading to accidental immediate termination of active client connections during server maintenance windows.

102
MCQmedium

An administrator configures a standard Virtual Server with a destination IP of 10.10.10.20:443, using a SNAT Pool instead of Auto Map. During peak hours, connections begin to fail because the SNAT pool only contains a single IP address and port exhaustion occurs. Which architectural adjustment best resolves this issue while maintaining security?

A.Switch the source address translation setting from SNAT Pool to Auto Map to leverage all available self IP addresses.
B.Increase the connection timeout profile value to allow closed connections to linger and free up sockets more gradually.
C.Add additional IP addresses to the existing SNAT pool to increase the total number of available ephemeral translation ports.
D.Configure a OneConnect profile on the virtual server to enable HTTP connection multiplexing across backend servers.
AnswerC

Adding more IP addresses directly scales the total translation capacity, as each IP provides approximately 64,000 source ports. This targeted mitigation preserves the defined egress IP range while successfully eliminating port exhaustion on the BIG-IP system.

Why this answer

Expanding the SNAT pool by adding multiple IP addresses provides a larger translation address space and multiplies the available ephemeral port capacity per destination. This prevents port exhaustion during traffic spikes without sacrificing the controlled source IP mapping required by downstream security policies.

Exam trap

Candidates often suggest replacing SNAT with direct routing or disabling it entirely during port exhaustion, compromising security policies instead of expanding the translation pool.

103
MCQeasy

Which command is used to view the current status and statistics of a pool from the command line?

A.tmsh list ltm pool
B.tmsh show ltm pool
C.tmsh view ltm pool
D.tmsh display ltm pool
AnswerB

'tmsh show' is the command to view operational statistics and runtime data. Using it with 'ltm pool' displays the health status, active connection counts, and traffic metrics for each pool member, which is vital for monitoring the performance and availability of the backend infrastructure in production environments.

Why this answer

The 'tmsh show ltm pool' command is the standard method for viewing real-time pool status and traffic statistics. It provides a comprehensive view of member health, current connection counts, and traffic throughput. This is an essential skill for LTM administrators for performing quick health checks and verifying that traffic is being distributed as expected across the backend server farm without relying on the GUI.

Exam trap

Candidates often guess GUI-based commands or incorrect bash syntax, forgetting that 'tmsh' is the standard administrative shell for managing and monitoring all BIG-IP objects.

104
MCQhard

A client is experiencing intermittent connection failures. You suspect the BIG-IP is SNATing traffic. If the SNAT pool is exhausted, what behavior will the BIG-IP exhibit?

A.It will automatically increase the SNAT pool size.
B.It will drop new incoming connections from clients.
C.It will bypass the SNAT pool and use the Self-IP.
D.It will rotate the source IP to the next available virtual address.
AnswerB

When all available source ports in the SNAT pool are utilized, the LTM cannot translate the next incoming request. Consequently, the BIG-IP will drop the connection. Monitoring SNAT pool utilization is essential for ensuring that the number of concurrent connections does not exceed the platform's port capacity.

Why this answer

SNAT pool exhaustion occurs when the BIG-IP runs out of available source ports to translate client connections. When this happens, new requests from clients will be dropped or rejected because the LTM cannot map the connection to a valid source IP/port combination. Identifying this is crucial during performance troubleshooting, as it often masquerades as generic network connectivity issues or server-side application errors.

Exam trap

Candidates often misinterpret SNAT exhaustion as a backend server crash. They fail to realize that the BIG-IP is dropping traffic before it ever reaches the pool because it cannot perform the translation.

105
MCQeasy

An LTM administrator needs to ensure that only encrypted traffic is accepted by a Virtual Server. Which profile should be configured?

A.Server SSL profile
B.Client SSL profile
C.TCP profile
D.HTTP profile
AnswerB

The Client SSL profile allows the BIG-IP to accept and decrypt incoming SSL/TLS traffic from clients. This is the mandatory configuration for any virtual server intended to serve secure content, as it establishes the secure tunnel between the client and the BIG-IP device.

Why this answer

The Client SSL profile is required to handle incoming encrypted traffic. By assigning this profile, the BIG-IP acts as the SSL endpoint. This is a foundational concept in secure application delivery.

Properly configuring SSL termination ensures that the BIG-IP can inspect the traffic for security threats and load-balance it effectively while offloading the computationally expensive decryption process from the backend application servers.

Exam trap

Candidates often confuse the Client SSL profile with the Server SSL profile. They forget that the Client SSL profile is what decrypts traffic coming from the client to the BIG-IP.

106
MCQhard

Refer to the exhibit. An administrator notices that users connecting to both port 80 and port 443 are being persisted to the same backend server. Why is this occurring?

A.The persistence timeout is too high, causing records to overlap across services.
B.The persistence profile is applied to the virtual server without a mask.
C.The 'match-across-services' setting is enabled in the persistence profile.
D.The virtual server is using a shared pool, forcing persistence across services.
AnswerC

Enabling 'match-across-services' forces the BIG-IP to maintain persistence records that are independent of the destination port. This means that once a client is mapped to a server via one virtual server, subsequent requests from that source IP to any virtual server will be sent to the same member.

Why this answer

The persistence profile /Common/my_src_persist has 'match-across-services' enabled. This feature instructs the BIG-IP to ignore the destination port when calculating the persistence record. Consequently, when a client hits the virtual server on port 80, the persistence record is created based on the source IP.

When the same client subsequently hits a virtual server on port 443, the BIG-IP identifies the existing persistence entry and directs the traffic to the same pool member.

Exam trap

Candidates often confuse source persistence with destination port settings, assuming that traffic arriving on different ports must always be persisted to different pool members regardless of global profile settings.

107
MCQmedium

When troubleshooting a persistent connection issue, which LTM feature allows you to view active persistence entries?

A.Traffic Management Shell (tmsh) persistence table
B.Configuration Utility Dashboard
C.Virtual Server Statistics
D.Log files in /var/log/ltm
AnswerA

The command 'show ltm persistence persist-records' provides a detailed view of current entries in the persistence table. This allows administrators to verify which clients are currently pinned to which backend servers, which is essential for diagnosing issues where session stickiness is failing to perform as expected.

Why this answer

The persistence table contains a real-time mapping of client sessions to specific pool members. Viewing this table is the most effective way to determine if persistence is working correctly. It is a fundamental troubleshooting step for LTM specialists, as it confirms whether client traffic is being directed to the intended server or if a conflict in the persistence configuration is causing sessions to be misrouted.

Exam trap

Many test-takers confuse configuration viewing commands in tmsh with runtime operational troubleshooting commands, mistakenly checking pool status instead of querying the actual persistence table records.

108
MCQhard

What is the primary risk of using a wildcard (0.0.0.0/0) virtual server on a BIG-IP system?

A.It prevents the use of SSL profiles on the virtual server.
B.It significantly increases the attack surface by exposing all ports.
C.It causes high CPU utilization due to packet inspection overhead.
D.It disables the BIG-IP's ability to use persistence.
AnswerB

By listening on all ports and all addresses, a wildcard virtual server makes the BIG-IP a wide-open gateway. An attacker can probe all internal services behind the BIG-IP, potentially bypassing intended security perimeters. Proper firewalling and access control lists are mandatory if such a configuration is absolutely necessary.

Why this answer

A wildcard virtual server intercepts all traffic directed to the BIG-IP on any port for any destination IP address. If not carefully configured with specific iRules or policies, this can lead to security vulnerabilities, such as exposing management or internal interfaces to public traffic. It significantly increases the attack surface of the network and is generally discouraged unless strictly required for specific gateway or firewall-like functionalities.

Exam trap

Candidates often assume a wildcard virtual server is a standard convenience feature rather than a significant security risk, failing to realize it exposes all ports and services to potential unauthorized access.

109
MCQmedium

You are managing an LTM and notice that some traffic is not being load-balanced as expected. You see that an iRule is applied to the virtual server. What is the most likely reason the iRule is overriding the load-balancing method?

A.The iRule is only triggered when the pool is empty.
B.The iRule explicitly selects a pool or node.
C.The load-balancing method is incompatible with iRules.
D.The iRule is disabled by the current license.
AnswerB

If an iRule uses the 'pool' or 'node' command, the BIG-IP directs the request to that specific destination, ignoring the load-balancing method assigned to the pool. This allows for powerful traffic management, such as content switching or blue-green deployments, but it also overrides the default selection algorithm.

Why this answer

iRules are processed before standard load balancing in the BIG-IP pipeline. When an iRule contains commands like 'pool' or 'node', it can explicitly select a destination server, effectively bypassing the configured load-balancing algorithm. This is a common point of confusion for administrators, as the iRule logic can override the expected behavior of the pool's load-balancing method.

Exam trap

Test-takers often assume the virtual server's static load-balancing method always dictates pool selection, forgetting that procedural iRules execute first in the traffic flow.

110
MCQhard

Refer to the exhibit. What happens to the user session if the 'my_app_cookie' is not present in the initial client request?

A.The request is dropped by the LTM.
B.The BIG-IP inserts a cookie in the response.
C.The LTM forces a redirect to the login page.
D.Persistence is permanently disabled for that session.
AnswerB

The 'insert' method instructs the BIG-IP to generate and send a persistence cookie to the client in the HTTP response. This allows the LTM to handle session persistence transparently, ensuring that future requests from the same user are directed to the same server, thereby maintaining session continuity for the client.

Why this answer

With the 'insert' method, the BIG-IP will inject a persistence cookie into the HTTP response header sent to the client. The client browser will then store this cookie and include it in all subsequent requests. This allows the BIG-IP to correctly route the user back to the same backend server on future requests without the backend application needing to handle the session tracking logic itself.

Exam trap

Candidates often assume the backend server must generate the cookie, forgetting that the BIG-IP 'insert' method handles the injection of the persistence cookie into the HTTP response header automatically.

111
MCQeasy

Refer to the exhibit. An administrator checks the status of 'web_pool' and observes the output shown. What is the most likely cause for the pool being offline?

A.The Virtual Server associated with the pool is disabled.
B.The health monitors assigned to the pool members are failing.
C.The load balancing method is set to Round Robin.
D.The license for the LTM module has expired.
AnswerB

The 'Available Members: 0' status confirms that all associated monitors are failing. The BIG-IP marks pool members as down when they fail to respond to probes, causing the pool to report an offline status. This typically points to server-side issues, network connectivity problems, or incorrect monitor settings.

Why this answer

The output indicates that the pool is offline because all members are unavailable. In LTM, a pool's availability status is determined by the health of its members. When all monitors fail or the members are manually disabled, the pool enters an offline state.

This is a fundamental concept for troubleshooting service outages, as it immediately identifies that the issue lies with the backend servers rather than the VIP.

Exam trap

Candidates often blame the virtual server configuration itself when a pool is down. They fail to recognize that the pool status is an independent health indicator that dictates the VIP's availability.

112
MCQmedium

Which health monitor type should be used when you need to verify that a web server is not only responding to TCP connections but also returning the correct content for a specific page?

A.TCP Half-Open monitor.
B.ICMP monitor.
C.HTTP monitor with 'send' and 'receive' strings.
D.SNMP DCA monitor.
AnswerC

An HTTP monitor allows the LTM to send a specific HTTP request and wait for a specific response string. This verifies that the web server is correctly processing requests, handling the application logic, and returning the expected data, providing a much higher level of confidence than transport-layer monitors.

Why this answer

An HTTP or HTTPS monitor is required to validate application-layer content. Simple TCP monitors only verify that the port is open and listening; they cannot confirm if the web server is actually serving pages or returning errors. By configuring an HTTP monitor with a 'send' and 'receive' string, the BIG-IP can ensure the application is functioning correctly, not just the network stack.

Exam trap

Candidates often choose a TCP monitor because it is simpler, failing to realize that a TCP monitor only checks for an open port, not application-layer health.

113
MCQmedium

An administrator needs to ensure that client SSL traffic is terminated at the BIG-IP LTM while maintaining persistence based on a specific session cookie. Which profile combination correctly enables this functionality?

A.Server SSL profile and Source Address Affinity profile
B.Client SSL profile and Source Address Affinity profile
C.Client SSL profile and Cookie Persistence profile
D.Server SSL profile and Cookie Persistence profile
AnswerC

The Client SSL profile decrypts the incoming traffic, allowing the LTM to read and insert session cookies. The Cookie Persistence profile enables the LTM to track the specific session identifier, ensuring the client remains connected to the same backend pool member throughout the session duration.

Why this answer

To terminate SSL, a Client SSL profile must be assigned to the Virtual Server. To persist based on a cookie, a Cookie Persistence profile must be enabled. This combination is standard for web applications requiring secure transport and session stickiness.

Understanding this architecture is vital because the LTM must decrypt traffic to inspect and insert the persistence cookie, allowing the BIG-IP to make intelligent load-balancing decisions based on application-layer data.

Exam trap

Candidates often confuse Server SSL with Client SSL, or select generic fallback profiles like HTTP instead of explicitly combining the Client SSL profile with the Cookie Persistence profile required for application-layer stickiness.

114
MCQmedium

An LTM Specialist is asked to prevent users from accessing a specific subdirectory on a website, e.g., '/admin'. What is the most secure and efficient way to do this?

A.Create an iRule to log the request and drop the connection.
B.Use a Local Traffic Policy to reject requests for '/admin'.
C.Configure a custom health monitor to mark the server down.
D.Enable a Persistence profile to filter the URI.
AnswerB

Local Traffic Policies are designed for this exact type of request filtering. They are evaluated at the virtual server level, allowing the BIG-IP to drop the request early in the processing chain. This protects the backend infrastructure and is significantly more performant than using iRules.

Why this answer

Using a Local Traffic Policy is the most efficient and secure way to block access to specific URI paths. By creating a policy rule that matches the request path against '/admin' and setting the action to 'reject' or 'drop', the BIG-IP intercepts the malicious or unauthorized request before it ever reaches the backend servers. This provides a clear, configurable, and high-performance security boundary for the application.

Exam trap

Candidates often write complex iRules to block URIs, ignoring that Local Traffic Policies provide a more efficient, modern, and easily manageable declarative solution.

115
MCQmedium

A virtual server is configured with a 'Least Connections' load balancing method. Under what specific scenario would this method be more effective than 'Round Robin'?

A.When all backend servers are identical in hardware specifications.
B.When the application consists of simple, static web pages.
C.When backend servers process requests with varying execution times.
D.When the virtual server is configured with a high persistence timeout.
AnswerC

In applications where requests have different processing times, some servers may accumulate more active connections than others. Least Connections keeps track of these active sessions and directs new traffic to the server with the fewest connections, preventing overloaded servers from becoming overwhelmed while others remain idle.

Why this answer

Least Connections is ideal when backend servers handle requests of varying complexity or duration. Because it tracks active connections, it avoids sending new requests to a server that is already busy, whereas Round Robin blindly rotates through all servers. This ensures better distribution of load in environments where some requests take significantly longer to process, preventing any single server from becoming a bottleneck during traffic spikes.

Exam trap

Candidates often select 'Least Connections' for high-traffic environments regardless of request duration. They forget that this method is specifically meant to balance load based on processing time, not just connection count.

116
MCQhard

Refer to the exhibit. What is the impact of using the 'tcp-lan-optimized' profile on this virtual server?

A.It improves performance for clients connecting over long-distance WAN links.
B.It provides faster window scaling for high-latency connections.
C.It is inappropriate if the clients are connecting over the Internet.
D.It disables TCP keep-alives to save memory on the BIG-IP.
AnswerC

Internet traffic typically suffers from higher latency and packet loss. 'tcp-lan-optimized' settings are tuned for local networks where those conditions are rare. Using this profile for WAN traffic will lead to sub-optimal throughput because the TCP windowing and retransmission timers are too aggressive for unstable connections.

Why this answer

The 'tcp-lan-optimized' profile is designed for high-speed, low-latency environments like LANs. It modifies TCP settings to be less aggressive than 'tcp-wan-optimized'. Using it on a connection where the client is accessing over the internet (WAN) can result in poor performance, as the settings do not account for the high latency and packet loss typically encountered on public networks compared to local infrastructure.

Exam trap

Candidates select LAN-optimized profiles for internet-facing virtual servers because they want aggressive performance, ignoring the high-latency reality of WAN environments.

117
MCQeasy

When configuring a BIG-IP LTM, what is the significance of the 'Service Down Action' setting on a virtual server?

A.It defines how the BIG-IP handles traffic when no pool members are available.
B.It sets the timeout for health monitor probes.
C.It determines the number of concurrent connections allowed.
D.It enables compression for the virtual server.
AnswerA

This setting directly controls the system's reaction to a complete pool failure. By properly configuring this action, administrators can control whether users receive an immediate connection reset or a graceful error page, which helps prevent confusion and improves the overall resilience of the application delivery service.

Why this answer

The 'Service Down Action' determines the behavior of the BIG-IP when all pool members are marked as 'Down' by the health monitor. Options include rejecting the connection, dropping it, or sending it to a fallback host. This setting is crucial for user experience, as it allows the administrator to provide a clean error response instead of letting the connection hang or time out during a total service outage.

Exam trap

Candidates frequently confuse the 'Service Down Action' with standard health monitor intervals, missing its specific role in handling total pool outages.

118
MCQmedium

A client is experiencing intermittent connection resets when accessing an application via an LTM Virtual Server. The administrator notices that 'OneConnect' is enabled on the virtual server. What is the most likely cause for these resets?

A.The client browser is incompatible with HTTP/2.
B.The server-side application does not properly handle persistent connections.
C.The Virtual Server's timeout value is too high.
D.The load balancing method is set to 'Least Connections'.
AnswerB

OneConnect requires that both the BIG-IP and the backend server correctly manage connection reuse. If the backend application closes the connection before the BIG-IP is ready, the LTM sends data over a closed socket, causing the server to send a TCP Reset (RST) packet.

Why this answer

OneConnect enables connection pooling, which allows the BIG-IP to keep server-side connections open for reuse. However, if the server-side application or web server doesn't support persistent HTTP connections or lacks proper keep-alive handling, it may prematurely close the connection. This mismatch results in the BIG-IP attempting to use a stale connection, leading to resets when the server rejects the subsequent HTTP requests.

Exam trap

Candidates often blame the BIG-IP for the resets, failing to recognize that OneConnect exposes underlying issues with backend servers that do not correctly support persistent HTTP connection handling.

119
Multi-Selectmedium

Which TWO of the following are benefits of using SNAT (Source Network Address Translation) on a BIG-IP LTM?

Select 2 answers
A.Simplifies return routing for backend servers.
B.Increases the encryption speed of the SSL handshake.
C.Hides the internal IP addresses of backend servers.
D.Improves the load balancing algorithm's accuracy.
E.Enables the use of cookie-based persistence.
AnswersA, C

SNAT ensures that the return traffic from the backend server is sent back to the BIG-IP, which is the entity that initiated the request. This eliminates the need for backend servers to have a default gateway pointing to the BIG-IP, simplifying the underlying network routing configuration for the servers.

Why this answer

SNAT simplifies return routing by ensuring traffic returns to the BIG-IP rather than the client, and it hides the backend infrastructure from the public internet. By SNATing the traffic to the BIG-IP's self-IP, the backend server sees the request as coming from the BIG-IP. This prevents asymmetric routing issues and enhances security by abstracting the backend server IP addresses from the end-user environment.

Exam trap

Candidates often confuse SNAT with security features like WAF or SSL offloading, failing to realize its primary purpose is managing return routing and hiding internal network topologies.

← PreviousPage 2 of 2 · 119 questions total

Ready to test yourself?

Try a timed practice session using only Big IP Local Traffic Manager questions.