F5-CTS-LTM BIG-IP Local Traffic Manager Practice Question
Which TWO of the following are valid methods to offload SSL processing from the backend servers to the BIG-IP system? (Choose two)
⚠ Common exam trap
Candidates often mistakenly select server-side SSL alone as an offloading method, forgetting that offloading requires terminating client-side encryption on the BIG-IP device.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure Client-side SSL profile on the virtual server and leave the backend pool unencrypted.
SSL Offloading is a primary function of LTM, allowing the BIG-IP to perform the resource-intensive cryptographic tasks. By terminating the SSL connection at the BIG-IP, the backend servers can focus on application logic. The two common architectures are SSL Termination (Client-side SSL) and SSL Bridging (Client-side and Server-side SSL), both of which effectively remove the encryption burden from the backend pool members.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Configure Client-side SSL profile on the virtual server and leave the backend pool unencrypted.
Why this is correct
This is the classic SSL termination scenario. The BIG-IP handles the SSL handshake with the client and sends traffic to the pool members in cleartext. This is the most efficient method for offloading SSL because the backend servers handle no encryption at all for these incoming requests.
- ✗
Configure Server-side SSL profile on the virtual server and leave the client traffic unencrypted.
Why it's wrong here
Configuring only Server-side SSL results in the client-to-BIG-IP traffic being unencrypted while the BIG-IP-to-server traffic is encrypted. This does not offload SSL from the backend servers; rather, it introduces encryption overhead on the BIG-IP while leaving the client traffic vulnerable on the public network.
- ✓
Configure both Client-side and Server-side SSL profiles on the virtual server.
Why this is correct
This is SSL Bridging (or SSL Re-encryption). While the backend servers still perform encryption, the BIG-IP acts as a secure proxy. In many compliance scenarios, this is required to maintain end-to-end encryption while allowing the BIG-IP to inspect and modify traffic for load balancing or security purposes.
- ✗
Disable SSL on the virtual server and enable it on the pool.
Why it's wrong here
Disabling SSL on the virtual server means the BIG-IP will not accept encrypted connections. The client would not be able to establish a secure session with the VIP, causing the application to fail for any users requiring HTTPS, which is standard for modern web application security.
- ✗
Configure an iRule to forward unencrypted packets to the backend servers.
Why it's wrong here
While an iRule can technically route packets, it cannot perform SSL offloading. SSL offloading requires the cryptographic engine of the BIG-IP to manage the handshake and decryption process. Manual packet manipulation via iRules would not handle the complex state of an SSL session correctly or securely.
About these practice questions
One of 119 original F5-CTS-LTM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official F5 exam blueprint
This F5-CTS-LTM practice question is part of Courseiva's free F5 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the F5-CTS-LTM exam.