Black Friday Special 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: clap70

303 BIG-IP ASM Specialist Questions and Answers

Questions 4

An LI M device is experiencing a high volume of traffic. The virtual server is struggling under the load. The problem appears to be on the server side connections. The virtual server isaccepting connections . The virtual server is accepting connections on https and is configured with an SSL profile and http pool.

What should be added to increase the performance of the device?

Options:

A.

an HTTP Compression profile

B.

a One Connect profile

C.

smaller key to the SSL profile

D.

a SPDY profile

Buy Now
Questions 5

A BIG-IP Administrator needs to purchase new licenses for a BIG-IP appliance.

The administrator needs to know if a module is licensed and the memory requirement for that module.

Where should the administrator view this information in the System menu?

Options:

A.

Resource Provisioning

B.

Configuration > Device

C.

Software Management

D.

Configuration >OVSDB

Buy Now
Questions 6

An LTM Specialist is troubleshooting an issue with a new virtual server. When connecting through the virtual server, clients receive the message "Unable to connect" in the browser, although connections directly to the pool member show the application is functioning correctly. The LTM device configuration is:

ltm virtual /Common/vs_https {

destination /Common/10.10.1.110:443

ip-protocol udp

mask 255.255.255.255

pool /Common/pool_https

profiles {

/Common/udp { }

}

translate-address enabled

translate-port enabled

vlans-disabled

}

ltm pool /Common/pool_https {

members {

/Common/172.16.20.1:443 {

address 172.16.20.1

}

}

}

What issue is the LTM Specialist experiencing?

Options:

A.

The virtual server is disabled on all VLANs.

B.

The pool member is marked down by a monitor.

C.

The pool member is marked down administratively.

D.

The virtual server is configured for the incorrect protocol.

Buy Now
Questions 7

An LTM Specialist needs to provide access to a 8BG-IP to device for a company's support person access to the BIG IP device, but are NOT allowed to change any settings All support the support remote access to the BIG-IP device, but are NOTallowed to change ant settings. All support have accounts in the company's Active Directory

Which method is appropriate to provide access for the support personnel to the BIG-JP device?

Options:

A.

configure remote authentication for all users with a default userrole of Guest

B.

configure remote authentication and map support personnel users to the Guest user role

C.

configure remote authentication and map support personnel users to the Operator user role

D.

configure remote authentication for all users with adefault user role of Operator

Buy Now
Questions 8

A BIG-IP Administrator needs to apply a license to the BIG-IP system to increase the user count from the

base license.

Which steps should the BIG-IP Administrator?

Options:

A.

System License > Re-activate> Add-On Registration> Edit

B.

System > License > Re-activate > Base Registration> Edit

C.

Device Management > Devices > Select BIG-IP System > Update

D.

System > Configuration >Device > General

Buy Now
Questions 9

An LTM Specialist configures an HTTP monitor as follows:

ltm monitor http stats_http_monitor {

defaults-from http

destination *:*

interval 5

recv "Health check: OK"

send "GET /stats/stats.html HTTP/1.1\\r\\nHost: www.example.com\\r\\nAccept-EncodinG. gzip, deflate\\r\\nConnection: close\\r\\n\\r\\n"

time-until-up 0

timeout 16

}

The monitor is marking all nodes as down. A trace of the HTTP conversation shows the following:

GET /stats/stats.html HTTP/1.1

Host: www.example.com

Accept-EncodinG. gzip, deflate

Connection: close

HTTP/1.1 401 Authorization Required

DatE. Tue, 23 Oct 2012 19:38:56 GMT

Server: Apache/2.2.15 (Unix)

WWW-AuthenticatE. Basic realm="Please enter your credentials"

Content-LengtH. 480

Connection: close

Content-TypE. text/html; charset=iso-8859-1

Which action will resolve the problem?

Options:

A.

Add an NTLM profile to the virtual server.

B.

Add a valid username and password to the monitor.

C.

Use an HTTPS monitor with a valid certificate instead.

D.

Add a backslash before the colon in the receive string.

Buy Now
Questions 10

A BIG-IP Administrator must configure the BIG-IP device to send system log messages to a remote syslog server In addition, the log messages need to be sent over TCP for guaranteed delivery. What should the BIG-IP Administrator configure?

Options:

A.

syslog-ng

B.

Request Logging Profile

C.

HSL Logging

D.

Remote Logging

Buy Now
Questions 11

An HTTP 1.1 application utilizes chunking.

Which header should be used to notify the client's browser that there are additional HTTP headers at the end of the message?

Options:

A.

ETag

B.

From

C.

Trailer

D.

Expect

Buy Now
Questions 12

An LTM Specialist is setting up a monitor for an HTTP 1.1 server. The response to a GET / is:

HTTP/1.1 302 Moved Temporarily

Location: http://www.example.com/new/location.html

Which send string settings should the LTM Specialist use to force a proper response?

Options:

A.

GET / HTTP/1.0\r\nHost: host.domain.com\r\nConnection: Close\r\n\r\n

B.

GET /new/location.html HTTP/1.1\r\nHost: www.example.com\r\nConnection: Close\r\n\r\n

C.

GET / HTTP/1.1\r\nHost: www.example.com/new/location.html\r\nConnection: Close\r\n\r\n

D.

GET /new/location.html HTTP/1.1\r\nHost: host.domain.com/new/locations.html\r\nConnection: Close\r\n\r\n

Buy Now
Questions 13

A BIG-IP Administrator adds new Pool Members into an existing, highly utilized pool. Soon after, there are reports that the application is failing to load for some users. What pool level setting should the BIG-IP Administrator check?

Options:

A.

Availability Requirement

B.

Allow SNAT

C.

Action On Service Down

D.

Slow Ramp Time

Buy Now
Questions 14

An LTMSpecialist must reconfigure a BIG-IP LTM system that load balances traffic to web application servers. The application developer inform the LTM Specialist that TLS must be used to communicate

with the application servers.

Which additional profile isrequired as part of virtual server configuration?

Options:

A.

SPDV profile

B.

Server SSL

C.

Client SSL

D.

Rewrite profile

Buy Now
Questions 15

Which two alerting capabilities can be enabled from within an application visibility reporting (AVR) analytics profile? (Choose two.)

Options:

A.

sFlow

B.

SNMP

C.

e-mail

D.

LCD panel alert

E.

high speed logging (HSL)

Buy Now
Questions 16

The end users of a web application need to verify that their browsers received the complete message-body from the web server.

Which HTTP header will accomplish this?

Options:

A.

Range

B.

Expect

C.

Accept-Ranges

D.

Content-Length

Buy Now
Questions 17

-- Exhibit –

-- Exhibit --

Refer to the exhibit.

A web application is configured to allow sessions to continue even after a user computer is shut down for the night. A new LTM device is configured to load balance the web application to several servers. The application owner reports that application users are logged out of the web application whenever their browser is restarted or computer is rebooted.

What is the problem?

Options:

A.

The virtual server does NOT have persistence configured.

B.

The virtual server does NOT have persistence mirroring configured.

C.

The cookie set by the LTM device does NOT have an "Expires" value.

D.

The cookie set by the server is NOT being passed to client by the LTM device.

Buy Now
Questions 18

Refer to the exhibit.

How many nodes are represented on the network map shown?

Options:

A.

Four

B.

Three

C.

One

D.

Two

Buy Now
Questions 19

A BIG-IP Administrator remotely connects to the appliance via out-of-band management using https://mybigip mycompany net. The management portal has been working all week. When the administrator attempts to login today, the connection times out. Which two aspects should the administrator verify? (Choose two)

Options:

A.

DNS is property resolving the FQDN of the device.

B.

The device is NOT redirecting them to http.

C.

The administrator has the latest version of the web browser.

D.

Packet Filters on the device are blocking port 80.

E.

The administrator has TCP connectivity to the device.

Buy Now
Questions 20

An LTM Specialist needs to configure a virtual server with the requirements displayed below.

Application is currently an internal HTTPapplication

Encrypted external user access

Links are hard for siteA example.com and need to rewritten to siteB.Example.com

Which profiles must the LTM Specialist use to provide the proper functionality?

Options:

A.

Clientssll, Stream

B.

Serverless, Stream

C.

Clientssl, fastL4, Stream

D.

Serverless, fastL4, Stream

Buy Now
Questions 21

A Client makes the request displayed below to the application server.

Which virtual server type should an LTM Specialist use to load balance based on the URI?

.A. Forwarding (Layer 2)

B. Stateless

C.Standard

D. Performance (Layer 4)

Options:

Buy Now
Questions 22

An TLM Specialist needs to configure a virtual server to terminate SSL connection on the LTM device.

Cryptographic information must be re-authorized for SSL sessions that remain open for longer than 30 seconds.

Which settings should the LTM Specialist configure in the client SSL profile?

Options:

A.

set the Handshake Timeout to 30 seconds

B.

enable Require Peer SN1 Support

C.

set the Renegotiate Period to 30 seconds

D.

set the Renegotiate Max Record Delay to 30

Buy Now
Questions 23

An LTM device is deployed in a one-armed topology. The virtual server, clients, and web servers are connected on the LTM device internal VLAN. A client tries to connect to the virtual server and is unable to establish a connection. A packet capture from the LTM device internal VLAN shows that the HTTP request is being forwarded to the web server.

From which two additional locations should protocol analyzer data be collected? (Choose two.)

Options:

A.

network interface of web server

B.

network interface of client machine

C.

internal VLAN interface of LTM device

D.

external VLAN interface of LTM device

E.

any network interface of the Internet firewall

Buy Now
Questions 24

The BIG-IP Administrator needs to perform a BIG-IP device upgrade to the latest version of TMOS. Where can the administrator obtain F5 documentation on upgrade requirements?

Options:

A.

AskF5

B.

DevCentral

C.

Bug Tracker

D.

iHealth

Buy Now
Questions 25

An TLM Specialist has an Exchange that must use the LTM device to route traffic to the internet.

Which SNAT/NAT configure allows the Exchange server’s traffic access the internet through the LTM device?

Options:

A.

NAT

B.

SNAT Pool

C.

SNAT List

D.

SNAT Automap

Buy Now
Questions 26

A node is a member of various pools and hosts different web applications. If a web application is unavailable, the BIG-IP appliance needs to mark the pool member down for that application pool. What should a BIG-IP Administrator deploy at the pool level to accomplish this?

Options:

A.

A UDP monitor with a custom interval/timeout

B.

A combination of ICMP + TCP monitor

C.

An HTTP monitor with custom send/receive strings

D.

A TCP monitor with a custom interval/timeout

Buy Now
Questions 27

A OneConnect profile is applied to a virtual server. The LTM Specialist would like the client source IP addresses within the 10.10.10.0/25 range to reuse an existing server side connection.

Which OneConnect profile source mask should the LTM Specialist use?

Options:

A.

0.0.0.0

B.

255.255.255.0

C.

255.255.255.128

D.

255.255.255.224

E.

255.255.255.255

Buy Now
Questions 28

-- Exhibit –

-- Exhibit --

Refer to the exhibit.

An HTTP monitor always marks the nodes in the pool as down. The monitor's definition and the HTTP headers from the monitor request and response are provided.

What is the issue?

Options:

A.

The response is compressed.

B.

The send string is incorrect.

C.

The monitor timeout is too short.

D.

The monitor is NOT configured to follow the redirect.

Buy Now
Questions 29

An LTM Specialist notices the following error on the stdout console:

mcpd[2395]: 01070608:0: License is not operational(expired or digital signature does not match contents)

Which command should be executed to verify the LTM device license?

Options:

A.

bigpipe version

B.

tmsh show /sys license

C.

tmsh /util bigpipe version

D.

tmsh show /sys license status

Buy Now
Questions 30

An LTM Specialist plans to enable connection mirroring for a virtualserver in an HA environment.

What must the LTM Specialist consider before implementing the configuration change?

Options:

A.

Impact on system performance that might be noticeable

B.

The add-on license that is required for this feature to be available

C.

Creating the required separate interface for connection mirroring

D.

Decreased number of possible concurrent connections to that virtual server

Buy Now
Questions 31

-- Exhibit –

-- Exhibit --

Refer to the exhibits.

Every monitor has the same Send String, Recv String, and an Alias of *:*. The LTM Specialist simplifies the configuration to minimize the number of monitors.

How many unique monitors remain?

Options:

A.

1

B.

2

C.

3

D.

4

E.

5

Buy Now
Questions 32

An HTTP monitor is created and assigned to a pool with the following non-default configuration:

Interval: 7 seconds

Timeout: 22 seconds

Reverse: Yes

Send String: GET/status.htmlHTTP/1.1/r/nHost:test.example.com/r/nConnector:Close Receive String: Up

The HTTP server sends the following response:

What is the resulting pool status?

Options:

A.

Unavailable (Enabled)

Available (Enabled)

B.

Offline (Enabled)

C.

Unknown (Disabled)

Buy Now
Questions 33

What should the 816-IP Administrator provide when opening a new ticket with F5 Support?

Options:

A.

bigip.license file

B.

QKViewfile

C.

Device root password

D.

SSL private keys

Buy Now
Questions 34

-- Exhibit –

-- Exhibit --

Refer to the exhibit.

A user is unable to access an HTTP application via a virtual server.

What is the cause of the failure?

Options:

A.

The host header requires a host name.

B.

The virtual server is in the disabled state.

C.

The Connection: Keep-Alive header is set.

D.

There is no pool member available to service the request.

Buy Now
Questions 35

A BIG IP device delivers the online shopping website https://shop.example.com. Two pool members handle the traffic. An iRule directs requests with the hip parameter "environment=development" to a third pool member for a staging environment.

Which combination of profiles is needed at minimum?

Options:

A.

tcp, http, request logging

B.

tcp,http, clientssl

C.

tcp, clientssl, serverssl

D.

http, clientssl, persistence

Buy Now
Questions 36

A BIG-IP Administrator is receiving intermittent reports from users that SSL connections to the BIG-IP device are failing. Upon checking the log files, the BIG-IP Administrator notices the following error message:

ere tmm[]: 01260008:3: SSL transaction (TPS) rate limit reached

After reviewing statistics, the BIG-IP Administrator notices there are a maximum of 1200 client-side SSL

TPS and a maximum of 800 server-side SSL TPS.

What is the minimum SSL license limit capacity the BIG-IP Administrator should upgrade to handle this

peak?

Options:

A.

2000

B.

400

C.

800

D.

1200

Buy Now
Questions 37

A BIG-IP Administrator plans to upgrade a BIG-IP device to the latest TMOS version.

Which two tools could the administrator leverage to verify known issues for the target versions?

(Choose two.)

Options:

A.

F5 University

B.

F5 Downloads

C.

F5 End User Diagnostics (EUD)

D.

FSiHealth

E.

F5 Bug Tracker

Buy Now
Questions 38

These log entries can have different root causes:

Jun 28 05:01:21 LTM_A notice mcpd[27545]: 0107143a:5: CMI reconnect timer: enabled

Jun 28 05:01:21 LTM_A notice mcpd[27545]: 01071431:5: Attempting to connect to CMI peer 1.1.1.2 port 6699

Jun 28 05:01:21 LTM_A notice mcpd[27545]: 01071432:5: CMI peer connection established to 1.1.1.2 port 6699

Jun 28 05:01:26 LTM_A notice mcpd[27545]: 0107143a:5: CMI reconnect timer: disabled, all peers are connected

Which two commands should be used to obtain additional information on these entries? (Choose two.)

Options:

A.

tmsh show /sys mcpd

B.

bigstart status mcpd

C.

tmsh modify /sys db log.mcpd.level value debug

D.

tmsh modify /sys db log.cmi.level value debug

Buy Now
Questions 39

-- Exhibit –

-- Exhibit --

Refer to the exhibit.

An LTM Specialist is troubleshooting an issue with SSL and is receiving the error shown when connecting to the virtual server. When connecting directly to the pool member, clients do NOT receive this message, and the application functions correctly. The LTM Specialist exports the appropriate certificate and key from the pool member and imports them into the LTM device. The LTM Specialist then creates the Client SSL profile and associates it with the virtual server.

What is the issue?

Options:

A.

The SSL certificate and key have expired.

B.

The SSL certificate and key do NOT match.

C.

The client CANNOT verify the certification path.

D.

The common name on the SSL certificate does NOT match the hostname of the site.

Buy Now
Questions 40

An LTM Specialist needs to deploy a virtual server that will load balance traffic targeting https://register.example.com to a set of three web servers. Persistence needs to be ensured. No persistence mirroring is allowed SSL offloading is required.

A fourth web server with fewer resources will be used to handle requests from engine bots to https://register.example.comvrobots.txt by an iRule. The (Rule will use the HTTP_REQUEST event. .

What are the required profile and persistence settings to implement this

Options:

A.

tcp. dientssl, hup, source address persistence

B.

tcp, clientssl, http. cookie persistence

C.

tcp, clientssl, serverssl, ssl persistence

D.

tcp, clientssl, http, serverssl cookie persistence

Buy Now
Questions 41

A BIG-IP Administrator creates an HTTP Virtual Server using an iApp template. After the Virtual Server is

created, the user requests to change the destination IP addresses. The BIG-IP Administrator tries to

change the destination IP address from 10.1.1.1 to 10.2.1.1 in Virtual Server settings, but receives the

following error:

The application service must be updated using an application management interface

What is causing this error?

Options:

A.

The Application Service was NOT deleted before making the IP address change.

B.

The IP addresses are already in use.

C.

The Application Services have Strict Updates enabled.

D.

The IP addresses used are NOT from the same subnet as the Self IP.

Buy Now
Questions 42

-- Exhibit –

-- Exhibit --

Refer to the exhibit.

A pair of LTM devices are configured for HA. The LTM Specialist observes from a capture that there is a successful connection from a client directly to a web server and an unsuccessful connection from a client via the LTM device to the same web server.

Which two solutions will solve the configuration problem? (Choose two.)

Options:

A.

Configure SNAT on the pool.

B.

Configure SNAT on the virtual server.

C.

Change server default gateway to point at LTM internal self IP.

D.

Change server default gateway to point at LTM internal floating IP.

Buy Now
Questions 43

An LTM device needs an additional traffic group.

Which configuration item is required?

Options:

A.

Default device

B.

Group name

C.

MAC Masquerade Address

D.

Auto Fallback Timeout

Buy Now
Questions 44

-- Exhibit –

-- Exhibit --

Refer to the exhibit.

An LTM Specialist is troubleshooting a new HTTP monitor on a pool. The pool member is functioning correctly when accessed directly through a browser. However, the monitor is marking the member as down. The LTM Specialist captures the monitor traffic via tcpdump.

What is the issue?

Options:

A.

The server is marking the connection as closed.

B.

The pool member is rejecting the monitor request.

C.

The monitor request is NOT returning the page body.

D.

The 'time-until-up' setting on the monitor is incorrect.

Buy Now
Questions 45

A virtual server for a set of web services is constructed on an LTM device. The LTM Specialist has created an iRule and applied this iRule to the virtual server:

when HTTP_REQUEST {

switch [HTTP::uri] {

"/ws1/ws.jsp" {

log local0. "[HTTP::uri]-Redirected to JSP Pool"

pool JSP

}

default { log local0. "[HTTP::uri]-Redirected to Non-JSP Pool"

pool NonJSP

}

}

}

However, the iRule is NOT behaving as expected. Below is a snapshot of the log:

/WS1/ws.jsp-Redirected to JSP Pool

/WS1/ws.jsp-Redirected to JSP Pool

/WS1/ws.jsp-Redirected to JSP Pool

/WS1/WS.jsp-Redirected to Non-JSP Pool

/ws1/WS.jsp-Redirected to Non-JSP Pool

/WS1/ws.jsp-Redirected to JSP Pool

/ws1/ws.jsp-Redirected to Non-JSP Pool

What should the LTM Specialist do to resolve this?

Options:

A.

Use the followinG. switch -lc [HTTP::uri]

B.

Use the followinG. switch [string tolower [HTTP::uri]]

C.

Set the "Case Sensitivity" option of each member to "None".

D.

Select the "Process Case-Insensitivity" option for the virtual server.

Buy Now
Questions 46

TWO LTM devices are in the same Device Group and configured for Ac live/Standby Failover. The LTM Specialist observes that the HA Active and Standby device constantly changes state. All network links use the default route domain A dedicated fiber ink is used for the HA connection with a latency of 250 ms but no packet loss.

What is causing the change in failover state to occur?

Options:

A.

The HA network is using the default routing domain.

B.

The HA network is using multicast IP.

C.

The HA network is not configured for mirroring.

D.

The HA network latency is too high.

Buy Now
Questions 47

Which two subsystems could the LTM Specialist utilize to access an LTM device with lost management interface connectivity? (Choose two.)

Options:

A.

AOM

B.

ILO

C.

SCCP

D.

ALOM

Buy Now
Questions 48

An LTM Specialistis configuring a new virtual server on an LTM device and assigning a SNAT pool that is already is use another virtual server. Both virtual servers use the same pool members to load balance traffic. A maximum of 35,000 users needs to be able to access each virtual server ta any time. The network architecture does NOT allow the backend servers to use the LTM device as a default gateway.

What is the minimum number of SNAT addresses required in the SNAT pool to meet the needs of the virtual servers?

Options:

A.

2

B.

3

C.

4

D.

1

Buy Now
Questions 49

Refer to the exhibit.

Which two pool members are eligible to receive new connections? (Choose two)

Options:

A.

10.21.0.102.80

B.

10.21.0.104.80

C.

10.21.0.105.80

D.

10.21.0.101.80

E.

10.21.0.103.80

Buy Now
Questions 50

The 8IG-IP Administrator generates a qkview using "qkview -SO" and needs to transfer the output file via

SCP.

Which directory contains the output file?

Options:

A.

/var/log

B.

/var/tmp

C.

/var/local

D.

/var/config

Buy Now
Questions 51

An LTM HTTP pool has an associated monitor that sends a string equal to 'GET /test.html'.

Which two configurations could an LTM Specialist implement to allow server administrators to disable their pool member servers without logging into the LTM device? (Choose two.)

Options:

A.

Set monitor to transparent and ask the server team to set string ‘TRANSPARENT’ in test.html.

B.

Set ‘receive string’ equal to 'SERVER UP and ask the server team to set string ‘SERVER DOWN’ in test.html.

C.

Set ‘alias’ equal to 'SERVER DOWN’ and ask the server team to set string ‘SERVER DOWN’ in test.html.

D.

Set ‘receive disable string’ equal to 'SERVER DOWN’ and ask the server team to set string ‘SERVER DOWN’ in test.html.

E.

Set ‘disable pool member’ equal to 'SERVER UP’ and ask the server team to set string ‘SERVER DOWN’ in test.html.

Buy Now
Questions 52

Refer to the exhibit.

The http monitor is applied to a pool. All members are enabled. One server responds as follows.

What is the resulting status of this poo! member?

Options:

A.

Offline (Disabled)

B.

Offline (Enabled)

C.

Unavailable (Disabled)

D.

Available (Enabled)

Buy Now
Questions 53

An LTM Specialist is experiencing issues in a failover event. Certain long-lasting FTP event. Certain long-lasting FTP connections using a single node pool are forced to reconnect. The bigip.conf extract isshown:

What does the LTM Specialist need to change in the configuration to avoid this issue?

Options:

A.

snatpool

B.

persistence mirroring

C.

connection mirroring

D.

ftp profile

Buy Now
Questions 54

-- Exhibit –

-- Exhibit --

Refer to the exhibit.

An LTM Specialist is troubleshooting an HTTP monitor that is marking a pool member as down. Connecting to the pool member directly through a browser shows the application is up and functioning correctly.

ltm monitor http http_mon {

defaults-from http

destination *:*

interval 5

recv "200 OK"

send "GET /\\r\\n"

time-until-up 0

timeout 16

}

What is the issue?

Options:

A.

The HTTP headers are compressed.

B.

The pool member is responding with a 404.

C.

The pool member is responding without HTTP headers.

D.

The request is NOT being received by the pool member.

Buy Now
Questions 55

A BIG-IP Administrator is unable to connect to the management interface via HTTPS. What is a possible reason for this issue?

Options:

A.

The port lockdown setting is configured to Allow None.

B.

An incorrect management route is specified.

C.

The IP address of the device used to access the management interface is NOT included in the "P Allow" list in the Configuration Utility.

D.

The IP address of the device used to access the management interface is NOT included in the "httpd Allow" list in the CLI.

Buy Now
Questions 56

-- Exhibit –

-- Exhibit --

Refer to the exhibits.

An LTM Specialist has configured a virtual server to distribute connections to a pool of application servers and to offload SSL processing. The application fails to work as expected when connecting to the virtual server. It does work when clients connect directly to the application. Two packet captures were taken at the application server.

What is the root cause of the problem?

Options:

A.

The application servers are NOT listening on port 80.

B.

The LTM device is sending non-SSL traffic to an SSL port.

C.

The virtual server does NOT have a clientSSL profile assigned.

D.

The SSL handshake between the LTM device and the server is failing.

Buy Now
Questions 57

What should the LT'M Specialist add to the virtual server?

Options:

A.

one Stream profile and an iRule with the command of STREAM expression (@http:// @https:// @@internalapp@publicapp@)

B.

two Stream profiles and an iRule with the command of STREAM expression (@http:// @https:// @@internalapp@publicapp@)

C.

one Stream profile with the expression of @http:// @https:// @

D.

Two Stream profiles, one profile for each rewrite requirement

Buy Now
Questions 58

During a maintenance window, an EUD test was executed and the output displayed on the screen. The BIG-IP Administrator did NOT save the screen output. The BIG-IP device is currently handling business critical traffic. The BIG-IP Administrator needs to minimize impact. What should the BIG-IP Administrator do to provide the EUD results to F5 Support?

Options:

A.

Boot the device into EUD then collect output from console

B.

Execute EUD from tmsh and collect output from console

C.

Collect file /var/log/messages

D.

Collect file /shared/log/eud.log

Buy Now
Questions 59

A user is having issues with connectivity to an HTTPS virtual server. The virtual server is on the LTM device's external vlan, and the pools associated with the virtual server are on the internal vlan. An LTM Specialist does a tcpdump on the external interface and notices that the host header is incomplete.

In which location should the LTM Specialist put a traffic analyzer to gather the most pertinent data?

Options:

A.

server

B.

external VLAN

C.

internal VLAN

D.

client machine

Buy Now
Questions 60

-- Exhibit –

-- Exhibit --

Refer to the exhibit.

An LTM Specialist is reviewing the virtual server configuration on an LTM device.

Which two actions should the LTM Specialist perform to minimize the virtual server configuration? (Choose two.)

Options:

A.

Remove 'snat automap' from the virtual server.

B.

Remove the 'http' profile from the virtual server.

C.

Remove the 'default_class' from the virtual server.

D.

Combine 'acct_class' and 'marketing_class' into one class and update associations on the virtual server.

E.

Combine 'marketing_class' and 'default_class' into one class and update associations on the virtual server.

Buy Now
Questions 61

An LTM device is monitoring three pool members. One pool member is being marked down.

What should the LTM Specialist enable to prevent the server from being flooded with connections once its monitor determines it is up?

Options:

A.

manual resume

B.

packet shaping

C.

hold down timer

D.

slow ramp timer

E.

fastest load balance algorithm

Buy Now
Questions 62

A BIG-IP Administrator wants to add a new Self IP to the BIG-IP device. Which item should be assigned to the new Self IP being configured?

Options:

A.

Interface

B.

Route

C.

VLAN

D.

Trunk

Buy Now
Questions 63

Refer to the exhibit.

An LTM Specialist has multiple SNAT and virtual server objects configured as in the bigip.conf shown.

The LTMSpecialist tests a connection from a client with. IP 172.163.31.11 to 192.168.0.100:80.

Which two objects will show an increase in Local Traffic statistics connections?

Options:

A.

VS_A&SNAT_B

B.

VS_B&SNAT_B

C.

VS_ B & SNAT A

D.

VS_A & SNAT A

Buy Now
Questions 64

Where does a LTM Specialist view all of the objects that are part of a deployed iApp?

Options:

A.

iAPP> Application Policy > Objects

B.

Local Traffic . Virtual Servers > Applications

C.

IAP > Application Service > Components

D.

Local Traffic > Network Map > View Map

Buy Now
Questions 65

The network team introduces a new subnet 10.10.22.0/24 to the network. The route needs to be configured on the F5 device to access this network via the 30.30.30.158 gateway.

How should the LTM Specialist configure thisroute?

Options:

A.

Tmsh modify net route 10.10.22/24 gw 30.30.30.158

B.

Tmsh create net route 10.10.22/24 gw 30.30.30.158

C.

Tmsh changey net route 10.10.22/24 gw 30.30.30.158

D.

Tmsh add net route 10.10.22/24 gw 30.30.30.158

Buy Now
Questions 66

An LTM Specialist is removing some of the load off an existing cluster by adding a adding a third BIG-IP

device to the device group. The new device candeliver twice the performance of the other two devices.

The LTM Specialist needs to make sure that the BIG-IP device with the highest available capacity is

always selected to take over a traffic group in the event of a failover.

Which failover method is most appropriate?

Options:

A.

Ordered List

B.

Load Aware

C.

HA Group

D.

HA Capacity

Buy Now
Questions 67

Which command should the LTM Specialist use to determine the current system time?

Options:

A.

date

B.

time

C.

uname -a

D.

ntpq -p

Buy Now
Questions 68

DNS queries from two internal DNS servers are being load balanced to external DNS Servers via a Virtual

Server on a BIG-P device. The DNS queries originate from 192.168.101.100 and 192.168.101.200 and

target 192.168.21.50

All DNS queries destined for the external DNS Servers fail

Which property change should the BIG-IP Administrator make in the Virtual Server to resolve this issue?

Options:

A.

Protocol Profile (Client) to DNS-OPTIMZED

B.

Type to Performance (HTTP)

C.

Protocol to UDP

D.

Source Address to 192.168.101.0/24

Buy Now
Questions 69

-- Exhibit --

-- Exhibit --

Refer to the exhibit.

A company uses a complex piece of client software that connects to one or more virtual servers (VS) hosted on an LTM device. The client software is experiencing issues. An LTM Specialist must determine the cause of the problem. The LTM Specialist has the tcpdump extract. The client loses connection with the LTM device.

Where is the reset originating?

Options:

A.

the local switch

B.

the application server

C.

the device initiating the connection

D.

the destination device of the initial connection

Buy Now
Questions 70

An LTM Specialist must perform a hot fix installation from the command line.

What is the correct procedure to ensure that the installation is successful?

Options:

A.

import the hot fix to the /var/shared/images directory

check the integrity of the file with an md5 checksum

tmsh apply sys software hotfix volume .iso

B.

import the hot fix to the /var/shared/images directory

check the integrity of the file with an md5 checksum

tmsh install sys software hotfix .iso volume

C.

import the hot fix to the /shared/images directory

check the integrity of the file with an md5 checksum

tmsh apply sys software hotfix volume .iso

D.

import the hot fix to the /shared/images directory

check the integrity of the file with an md5 checksum

tmsh install sys software hotfix .iso volume

Buy Now
Questions 71

A VLAN has the following objects configured:

Self-IP 10.10.10.100 with port lockdown set to Allow default

Virtual server 10.10.10.100:443 with UDP profile enabled

Virtual server 10.10.10.0/24 port forwarding virtual server

Global destination NAT forwarding 10.10.10.100 to internal server 172.168.10.100

Which object will process this request when https://10.10.10.100 is entered into a browser?

Options:

A.

self-IP 10.10.10.100 with port lockdown set to Allow default

B.

virtual server 10.10.100/24 port o forwarding virtual server

C.

global destination NAT forwarding 10.10.10.100 to internal server 172.168.10.100

D.

virtual server 10.10.10.100.443 with UDP profile enabled

Buy Now
Questions 72

An LTM Specialist has just manually failed the active LTM device over to the standby LTM device. The LTM Specialist notices the newly active LTM device is NOT currently receiving traffic. The LTM Specialist verifies the newly active device is responding to ARP but still no traffic is hitting the virtual servers. The LTM Specialist also notices that the virtual servers eventually start responding.

What should be added to the configuration to resolve the problem?

Options:

A.

vlan failsafe

B.

floating self IP

C.

network failover

D.

MAC masquerading

E.

connection mirroring

Buy Now
Questions 73

While investigating the cause of a device failover, an LTM Specialist discovers the following events in /var/log/ltm:

01010029:5: Clock advanced by 518 ticks

01010029:5: Clock advanced by 505 ticks

01010029:5: Clock advanced by 590 ticks

01010029:5: Clock advanced by 568 ticks

01010029:5: Clock advanced by 1681 ticks

01010029:5: Clock advanced by 6584 ticks

01140029:5: HA daemon_heartbeat tmm fails action is failover and restart.

010c0026:5: Failover condition, active attempting to go standby.

Which issue caused the failover?

Options:

A.

NTP being out of sync

B.

TMM being descheduled

C.

VLAN Fail-safe heartbeats

D.

HA missing heartbeat packets

Buy Now
Questions 74

-- Exhibit –

-- Exhibit --

Refer to the exhibit.

An LTM Specialist is upgrading the LTM devices.

Which device should be upgraded first?

Options:

A.

Device A

B.

Device B

C.

Device C

D.

Device D

Buy Now
Questions 75

An LTM Specialist needs to use a set of addresses to access an Internet website in an outbound configuration.

Whichfeature should the LTM Specialist configure?

Options:

A.

NAT pool

B.

NAT address

C.

SNAT pool

D.

SNAT address

Buy Now
Questions 76

-- Exhibit –

-- Exhibit --

Refer to the exhibit.

An LTM Specialist configures a virtual server that balances HTTP connections to a pool of three application servers. Approximately one out of every three connections to the virtual server fails.

Which two actions will resolve the problem? (Choose two.)

Options:

A.

Assign a custom HTTP monitor to the pool.

B.

Enable SNAT automap on the virtual server.

C.

Verify that port lockdown is set to allow port 80.

D.

Verify the default gateway on the application servers.

E.

Increase the TCP timeout value in the default TCP profile.

Buy Now
Questions 77

When importing a PEM formatted SSL certificate, which text needs to appear first in the file?

Options:

A.

--START CERTIFICATE....

B.

...BEGIN CERTIFICATE....

C.

...SECURITY CERTIFICATE....

D.

...SSL CERTIFICATE....

Buy Now
Questions 78

The owner of a web application asks the 8IG-IP Administrator to change the port that the BIG-IP device sends traffic to. This change must be made for each member in the server pool named app_pool for their Virtual Server named app_vs. In which area of the BIG-IP Configuration Utility should the BIG-P Administrator make this change?

Options:

A.

Local Traffic > Pools

B.

Local Traffic > Nodes

C.

Network > Interfaces

D.

Local Traffic > Virtual Servers

Buy Now
Exam Code: 303
Exam Name: BIG-IP ASM Specialist
Last Update: Nov 24, 2024
Questions: 0
303 pdf

303 PDF

$25.5  $84.99
303 Engine

303 Testing Engine

$30  $99.99
303 PDF + Engine

303 PDF + Testing Engine

$135  $450