Labour Day Special - 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: c4sdisc65

Note: This exam is available on Demand only. You can Pre-Order this Exam and we will arrange this for you.

Pre-Order Your "303 - BIG-IP ASM Specialist" Exam

You can pre-order your "BIG-IP ASM Specialist" exam to us if you are in need this urgent. Crack4Sure.com Team will prepare your Exam Questions & Answers From Real Exam within next 2 to 3 Weeks Time only.

How to Make Pre-Order You Exams:

  1. 1. Click to "Add to Cart" Button.
  2. 2. Our Expert will arrange real Exam Questions within 2 to 3 weeks especially for you.
  3. 3. You will be notified within 2 to 3 Weeks' time once your Exam is ready with all Real Questions and Possible Answers with PDF + Testing Engine format.

Why to Choose Crack4Sure?

In the unlikely event if we can't make this exam available to you then you will issue a full refund! So there is no risk.

READY TO MAKE YOUR "303" PRE-ORDER?

$450

 Add To Cart

303 Practice Exam Questions with Answers BIG-IP ASM Specialist Certification

Question # 6

Some users who connect to a busy Virtual Server have connections reset by the BIG-IP system. Pool member resources are NOT a factor in this behavior. What is a possible cause for this behavior?

A.

The Connection Rate Limit is set too high

B.

The server SSL Profile has NOT been reconfigured.

C.

The Connection Limit is set too low.

D.

The Rewrite Profile has NOT been configured.

Full Access
Question # 7

-- Exhibit –

303 question answer

303 question answer

-- Exhibit --

Refer to the exhibits.

Which URL on which server is causing the highest latency for users?

A.

/slow1.php on 172.16.20.3

B.

/slow2.php on 172.16.20.1

C.

/reflector.php on 172.16.20.2

D.

/Compress.HTML on 172.16.20.1

Full Access
Question # 8

To increase available bandwidth of an existing Trunk, the BIG-IP Administrator is adding additional

interfaces.

Which command should the BIG-IP Administrator run from within bosh shell?

A.

tmsh create /net trunk trunk_A interfaces add {1.3.1.4}

B.

tmsh create/sys trunk trunk_A interfaces add {1.3.1.4}

C.

tmsh modify/sys trunk trunk^A interfaces add {1.3.1.4}

D.

tmsh modify /net trunk trunk_A interfaces add {1.3.1.4}

Full Access
Question # 9

A high-availability (HA) pair configuration uses only the hardwire serial cable connection to determine device state. A power outage occurs to the PDU powering the active unit. The standby unit takes over the active role as expected.

How is the peer unit able to determine the active unit is unavailable?

A.

voltage loss on serial cable

B.

no data stream received on serial port

C.

no response on management interface

D.

no heartbeat packets received on self IPs

Full Access
Question # 10

AnLTM specialist needs to create a new account with the admin role called "newadmin' and access to all partitions.

Which tmsh command should be executed?

A.

create /auth user newadmin partition-access add {all-partitions {role admin }} prompt for-password.

B.

create /users newadmin partition-access add {all-partitions {role admin JJ prompt for-password.

C.

create /user newadmin partition-access add (all-partitions {role admin }} prompt- for-password.

D.

create / sys user newadmin partition-access add (all-partitions {role admin )} prompt-for-password.

Full Access
Question # 11

-- Exhibit –

303 question answer

-- Exhibit --

Refer to the exhibit.

An LTM Specialist has uploaded a qkview to F5 iHealth.

Within the GUI, what is the correct procedure to comply with the recommendation shown in the exhibit?

A.

Obtain product version image from release.f5.com.

Overwrite existing image with new product version image.

Select product version image and click Install.

Select the available disk and volume set name.

B.

Obtain product version image from images.f5.com.

Overwrite existing image with new product version image.

Select product version image and click Install.

Select the available disk and volume set name.

C.

Obtain product version image from downloads.f5.com.

Import product version image.

Install image onto BIG-IP platform.

Select product version image and click Install.

Select the available disk and volume set name.

D.

Log a call requesting the product version image via websupport.f5.com

Import product version image.

Install image onto BIG-IP platform.

Select product version image and click Install.

Select the available disk and volume set name.

Full Access
Question # 12

A BIG-IP Administrator uses a device group to share the workload and needs to perform service on a BIG-IP device currently active for a traffic group. The administrator needs to enable the traffic group to run on another BIG-IP device in the device group. What should the administrator do to meet the requirement?

A.

Create a new Traffic Group and then fail to Standby Unit

B.

Select Traffic Group and then select Failover

C.

Select Traffic Group and then select Force to Standby

D.

Select Traffic Group on Primary Unit and then select Demote

Full Access
Question # 13

-- Exhibit –

303 question answer

303 question answer

303 question answer

-- Exhibit --

Refer to the exhibits.

Users are able to access the application when connecting to the virtual server but are unsuccessful when connecting directly to the application servers. The LTM Specialist wants to allow direct access to the application servers.

Why are users unable to connect directly to the application servers?

A.

The router does NOT have a route to the server subnet.

B.

The web server does NOT have a correct default gateway.

C.

The LTM device does NOT have a SNAT on the External VLAN.

D.

The LTM device does NOT have an IP Forwarding virtual server on the Internal VLAN.

E.

The LTM device does NOT have an IP Forwarding virtual server on the External VLAN.

Full Access
Question # 14

TWO BIG-IP appliances need to be configured to load balance multiple firewall in a firewall sandwich,

Which health monitor setting should be used to verify that the firewalls are able to forward traffic?

A.

Adaptive

B.

Reverse

C.

Transparent

D.

Up internal

Full Access
Question # 15

A set of servers is used for an FTP application as well as an HTTP website via separate BIG-IP Pools. The

server support team reports that some servers are receiving a lot more traffic than others.

Which Load Balancing Method should the BIG-IP Administrator apply to even out the connection count?

A.

Ratio (Member)

B.

Least Connections (Member)

C.

Least Connections (Node)

D.

Ratio (Node)

Full Access
Question # 16

AN LTM Specialist is using an external monitor evaluate the hard drive usage of a node. The monitor has marked the node down because it exceeded the specific threshold. The disk usage on the server has been corrected below the threshold, however, the node remains offline.

Which feature is causing this problem?

A.

The parameter Time Until UP has a value greater than 0

B.

The value of Manual Resume is set to No

C.

The value for UP interval is enable with a value greater than 0

D.

The value for Manual Resume is set to Yes

Full Access
Question # 17

Traffic to a pool of SFTP servers that share storage must be balanced by an LTM device.

What are therequired profile and persistence settings for a standard virtual server?

A.

tcp, ctientsst, ftp serverssl persistence

B.

tcp, clientssl, serverssl persistence

C.

tcp, ftp - Source address persistence

D.

tcp - no persistence profile will be used

Full Access
Question # 18

A custom TCP application using a single server is being migrated to the LTM device. A server is being added to the pool. The application is known to violate the TCP protocol RFC. Theapplication currently works without error from a user perspective.

Which virtual server type is appropriate in this situation?

A.

Stateless TCP protocol is not applicable

B.

Performance (Layer 4)-pure layer A forwarding

C.

forwarding (Layer 2) pure routingforwarding, pool cannot be specified

D.

Standard-tcp profile exists, RFC verification will be performed

Full Access
Question # 19

-- Exhibit –

303 question answer

-- Exhibit --

Refer to the exhibit.

A company uses a complex piece of client software that connects to one or more virtual servers (VS) hosted on an LTM device. The client software is experiencing issues. An LTM Specialist is tasked with finding the cause of the problem.

The LTM Specialist has the tcpdump extract and knows the client software has at least one connection to a VS on port 1990. However, when a tcpdump runs on the internal VLAN, there is no record of port 1990 in the tcpdump.

Why is there no record of port 1990 in the tcpdump?

A.

The LTM device drops the connection.

B.

Port 1990 is a well-known port, so its use is restricted.

C.

The LTM device performs a Port Address Translation (PAT).

D.

The LTM device performs a Network Address Translation (NAT).

Full Access
Question # 20

An LTM device receives a response string containing "error"

Which monitor type and parameter will mark the HTTP server as down?

A.

HTTP monitor, Receive String "error", and set the Reverse option to Yes

B.

HTTP monitor and Receive String "error'' ... flag is up

C.

HTTP monitor. Receive String "down", and set the Reverse option to Yes .... flag is

D.

HTTP monitor and Receive DisableString "error'' .... flag is disable

Full Access
Question # 21

An LTM Specialist upgrades the switchinginfrastructure and the backend servers on the LAN segments.

The LTM Specialist notices a 20% memory usage increase on the BIG-IP device while handling the same number of concurrent connections.

A comparison of statistics pre-upgrade and post-upgrade showsa significant reduction on the following:

-RTT between the BIG-IP device and the backend servers

-Packet drops in the switch

Time to First Byte (TTFB)

The LTM Specialist is concerned with the scalability of the number of concurrent connections with the newmemory usage.

Which setting should be changed to reduce the memory usage on the BIG-IP device?

A.

Reduce the proxy buffer high setting on the server-side TCP profile

B.

Increase the receive window of the client-side TCP profile

C.

Increase the proxy buffer high setting on the server-side TCP profile

D.

Reduce the idle of the client-side TCP profile

Full Access
Question # 22

A node is a member of various pools and hosts different web applications. If a web application is unavailable, the BIG-IP appliance needs to mark the pool member down for that application pool. What should a BIG-IP Administrator deploy at the pool level to accomplish this?

A.

A UDP monitor with a custom interval/timeout

B.

A combination of ICMP + TCP monitor

C.

An HTTP monitor with custom send/receive strings

D.

A TCP monitor with a custom interval/timeout

Full Access
Question # 23

An LTM Specialist has been asked to configure a virtual server to distribute connections between a pool of two application servers with addresses 172.16.20.1 and 172.16.20.2. The application servers are listening on TCP ports 80 and 443. The application administrators have asked that clients be directed to the same node for both HTTP and HTTPS requests within the same session.

Virtual servers vs_http and vs_https have been created, listening on 1.2.3.100:80 and 1.2.3.100:443, respectively.

Which configuration option will result in the desired behavior?

A.

Create pool app_pool with members 172.16.20.1:any and 172.16.20.2:any

Assign app_pool as the default pool for both vs_http and vs_https

Disable port translation for vs_http and vs_https

B.

Create pool http_pool with members 172.16.20.1:80 and 172.16.20.2:80

Assign pool http_pool as the default pool for both vs_https and vs_https

Disable port translation for vs_https

Create an SSL persistence profile with "match across virtual servers" enabled

Assign the persistence profile to vs_http.

C.

Create pool http_pool with members 172.16.20.1:80 and 172.16.20.2:80

Create pool https_pool with members 172.16.20.1:443 and 172.16.20.2:443

Assign http_pool as the default pool for vs_http

Assign https_pool as the default pool for vs_https

Create a source address persistence profile with "match across services" enabled

Assign the persistence profile to vs_http and vs_https

D.

Create pool http_pool with members 172.16.20.1:80 and 172.16.20.2:80

Create pool https_pool with members 172.16.20.1:443 and 172.16.20.2:443

Assign http_pool as the default pool for vs_http

Assign https_pool as the default pool for vs_https

Create an SSL persistence profile with "match across virtual servers" enabled

Assign the persistence profile to vs_http

Full Access
Question # 24

An LTM Specialistis configuring a new virtual server on an LTM device and assigning a SNAT pool that is already is use another virtual server. Both virtual servers use the same pool members to load balance traffic. A maximum of 35,000 users needs to be able to access each virtual server ta any time. The network architecture does NOT allow the backend servers to use the LTM device as a default gateway.

What is the minimum number of SNAT addresses required in the SNAT pool to meet the needs of the virtual servers?

A.

2

B.

3

C.

4

D.

1

Full Access
Question # 25

A BIG-IP Administrator must determine if a Virtual Address is configured to fail over to the standby member of a device group in which area of the Configuration Utility can this be confirmed?

A.

Device Management > Traffic Groups

B.

Device Management > Devices

C.

Local Traffic > Virtual Servers

D.

Device Management > Overview

Full Access
Question # 26

A BIG-IP Administrator defines a device Self IP . The Self IP is NOT reachable from the network. What should the BIG-IP Administrator verify first?

A.

The correct interface has been selected.

B.

The correct VLAN has been selected.

C.

Verify if auto last hop is disabled.

D.

The correct Trunk has been selected.

Full Access
Question # 27

An ITM Specialist has the configuration shown:

303 question answer

The LTM Specialist needs to create a new virtual server in part B.

Which virtual address(es) should be used for the new virtual server?

A.

10.100.0.1 and.10.120.0.1

B.

10.90.0.1 and 10.12.0.1

C.

10.120.0.1 only

D.

10.90.0.1 and 10.100.0.1

Full Access
Question # 28

-- Exhibit –

303 question answer

-- Exhibit --

Refer to the exhibit.

An LTM device is used to load balance web content over a secure channel.

The developers of the web content have done a trace using an HTTP profiler application. They believe that allowing the LTM device to compress traffic to the client will improve performance. The client can utilize GZIP or deflate compression algorithms.

An LTM Specialist must implement the compression.

The LTM Specialist has completed the following actions:

1. Create the relevant profile.

2. Apply the relevant profile to the virtual server (VS).

After applying the relevant profile, the LTM device is failing to compress the traffic. Instead, the traffic is being served with an error.

What is the problem?

A.

The incorrect compression algorithm is applied to the compression profile.

B.

The LTM device CANNOT SSL offload the traffic in order to read and compress it.

C.

The Protocol Profile (Client) option of "Allow Compression" needs to be enabled.

D.

The Protocol Profile (Server) option of "Allow Compression" needs to be enabled.

Full Access
Question # 29

A BIG-IP Administrator needs to determine which pool members in a pool have been manually forced offline and are NOT accepting any new traffic. Which status icon indicates this?

A)

303 question answer

B)

303 question answer

C)

303 question answer

D)

303 question answer

A.

Option

B.

Option

C.

Option

D.

Option

Full Access
Question # 30

An LTM Specialist troubleshooting an issue looks at the following /var/log/ltm entries:

Oct 2 04:52:42 slot1/tmm7 crit tmm7[21734]: 01010201:2: Inet port exhaustion on 10.143.109.5 to 10.143.147.150:53 (proto 17)

Oct 2 05:37:16 slot1/tmm7 crit tmm7[21734]: 01010201:2: Inet port exhaustion on 10.143.109.5 to 10.143.147.150:53 (proto 17)

Oct 2 05:57:32 slot1/tmm2 crit tmm2[21729]: 01010201:2: Inet port exhaustion on 10.143.109.5 to 10.143.147.150:53 (proto 17)

Oct 2 06:30:03 slot1/tmm7 crit tmm7[21734]: 01010201:2: Inet port exhaustion on 10.143.109.5 to 10.143.147.150:53 (proto 17)

Oct 2 06:37:44 slot1/tmm2 crit tmm2[21729]: 01010201:2: Inet port exhaustion on 10.143.109.5 to 10.143.147.150:53 (proto 17)

Oct 2 06:47:05 slot1/tmm5 crit tmm5[21732]: 01010201:2: Inet port exhaustion on 10.143.109.5 to 10.143.147.150:53 (proto 17)

Which configuration item should the LTM Specialist review to fix the issue?

A.

SNAT Pool

B.

Pool Member

C.

Port Lockdown

D.

Virtual Server Port Translation

Full Access
Question # 31

To improve application security, an LTM Specialist must configure a BIG application access. The BIG IPsystem to authenticate the client certificate before permitting application access. The BIG-IP system must also support the ability to red to redirect users to a certificate enrolment system without generating a browser error.

Within the Client SSL profile, which value should the LTM Specialist select for the Client Certificate option?

A.

Require

B.

Request

C.

Demand

D.

ignore

Full Access
Question # 32

A BIG-IP Administrator needs to restore an encrypted UCS archive from the command line using the

TMSH utility.

Which TMSH command should the BIG-IP Administrator use to accomplish this?

A.

load/sys ucs passphrase

B.

load/sys config file passphrase

C.

load/sys config file

D.

load/sys ucs no-license

Full Access
Question # 33

Refer to the exhibit.

303 question answer

A pool member fails the monitor checks for about 30 minutes and then starts passing the monitor

checks. New traffic is Not being sent to the pool member.

What is the likely reason for this problem?

A.

The pool member is disabled

B.

Monitor Type is TCP Half Open

C.

Manual resume is enabled

D.

Time Until Up is zero

Full Access
Question # 34

Which method is recommended for creating a new user from the CLI?

A.

Run f5adduser username' then 'f5passwd username' from bash or tmsh

B.

Run tmsh create auth user username prompt for password' from bash

C.

edit bigip.conf to add the new user and the user's clear-text password

D.

Run useradd username' then 'passwd username' from bash tmsh

Full Access
Question # 35

Which command should the LTM Specialist use to determine the current system time?

A.

date

B.

time

C.

uname -a

D.

ntpq -p

Full Access
Question # 36

Windows PC clients are connecting to a virtual server over a high-speed, low-latency network with no packet loss.

Which built-in client-side TCP profile provides the highest throughput for HTTP downloads?

A.

tcp

B.

tcp-legacy

C.

tcp-lan-optimized

D.

tcp-wan-optimized

Full Access
Question # 37

A BIG-IP Operator has made a grave error and deleted a few virtual servers on the active LTM device fronting the web browsing proxies. The BIG-IP Operator has NOT yet performed a configuration sync.

Which command should the LTM Specialist execute on the active LTM device to force a failover to the standby node and restore web browsing?

A.

tmsh /sys failover standby

B.

tmsh run /sys failover standby

C.

tmsh /sys failover status standby

D.

tmsh run /sys failover status standby

Full Access
Question # 38

-- Exhibit –

303 question answer

-- Exhibit --

Refer to the exhibit.

An LTM Specialist configures a virtual server that balances HTTP connections to a pool of three application servers. Approximately one out of every three connections to the virtual server fails.

Which two actions will resolve the problem? (Choose two.)

A.

Assign a custom HTTP monitor to the pool.

B.

Enable SNAT automap on the virtual server.

C.

Verify that port lockdown is set to allow port 80.

D.

Verify the default gateway on the application servers.

E.

Increase the TCP timeout value in the default TCP profile.

Full Access
Question # 39

-- Exhibit –

303 question answer

-- Exhibit --

Refer to the exhibit.

Based on the output of the tmsh interface show command, what is the issue?

A.

There is a duplex mismatch on the management interface.

B.

Interfaces 2.1 and 2.2 are defective and need replacement.

C.

Flow Control is NOT configured on the management interface.

D.

There are too many drops on inbound traffic on interface 1.1.

Full Access
Question # 40

-- Exhibit –

303 question answer

303 question answer

-- Exhibit --

Refer to the exhibits.

An LTM device has been configured for load balancing a number of different application servers. Configuration changes need to be made to the LTM device to allow administrative management of the servers in 172.16.10/24, 172.16.20/24, and 172.16.30/24 networks. The servers require outbound access to numerous destinations for operations.

Which solution has the simplest configuration changes while maintaining functionality and basic security?

A.

Remove 172.16.10.0:0/24, 172.16.20.0:0/24, and 172.16.30.0:0/24, and keep 0.0.0.0:0/0.0.0.0 enabled on all VLANs.

B.

Replace 172.16.10.0:0/24, 172.16.20.0:0/24, and 172.16.30.0:0/24, with 172.16.0.0:0/16, and keep 0.0.0.0:0/0.0.0.0.

C.

Enable 172.16.10.0:0/24, 172.16.20.0:0/24, and 172.16.30.0:0/24 on ingress VLAN(s), and enable 0.0.0.0:0/0.0.0.0 on egress VLAN(s).

D.

Enable 172.16.10.0:0/24, 172.16.20.0:0/24, and 172.16.30.0:0/24 on egress VLAN(s), and enable 0.0.0.0:0/0.0.0.0 on ingress VLAN(s).

Full Access
Question # 41

An LTM Specialist discovers an issue with the custom http monitor that returns in a false positive status.

The end users cannot get the right website, but thehttp monitor marks the pool member UP.

What is causing the false positive result?

303 question answer

A.

The end user should use another type of browser.

B.

The response is chunked.

C.

The response is compressed.

D.

The Content-Type has value "iso-8859-200".

Full Access
Question # 42

An application is being load balanced through the LTM device using the configuration displayed below.

The network has been re-engineered to NAT all client connection. As a result, allclient connections are hitting the same pool member.

303 question answer

303 question answer

Which changes should the LTM Specialist make in order to restore load balancing functionality wile maintaining session persistence?

A.

Change the virtual server type to Standard, add an httpprofile, and change the persistence profile to Destination Address

B.

Leave the virtual server type set Performance (Layer 4) and change the persistence type to hash

C.

Change the virtual serer type to Forwarding (Layer 4) and leave the persistence type tohash source Address

D.

Change the virtual server to Standard add an http profile, and change the persistence profile to Cookie persistence

Full Access
Question # 43

A local user account (Users) on the BIG-IP device is assigned the User Manager role. Userl attempts to

modify the properties of another account (User2), but the action fails. The BIG-IP Administrator can

successfully modify the User2 account.

Assuming the principle of least privilege, what is the correct way to allow User 1 to modify User2

properties?

A.

Move User2 to the same partition as User1

B.

Grant User1 administrative privileges

C.

Move User to the same partition as User2.

D.

Modify the partition access for User 1

Full Access
Question # 44

An LTM Specialist is customizing local traffic logging.

Which traffic management OS alert level provides the most detail?

A.

Alert

B.

Notice

C.

Critical

D.

Emergency

E.

Informational

Full Access
Question # 45

An LTM Specialist needs to upgrade all guests on a Viprion eight CMP guests.

What is the maximum number of guests that the LTM Specialist should upgrade at once?

A.

Eight

B.

One

C.

TWO

D.

Four

Full Access
Question # 46

Refer to the exhibit

The network team creates a new VLAN on the switches. The BIG-IP Administrator needs to create a

configuration on the BIG-IP device. The BIG-IP Administrator creates a new VLAN and Self IP, but the

servers on the new VLAN are NOT reachable from the BIG-IP device.

Which action should the BIG-IP Administrators to resolve this issue?

A.

Set Port Lockdown of Set IP to Allow All

B.

Change Auto Last Hop to enabled

C.

Assign a physical interface to the new VLAN

D.

Create a Floating Set IP Address

Full Access
Question # 47

An HTTP monitor is created and assigned to a pool with the following non-default configuration:

Interval: 7 seconds

Timeout: 22 seconds

Reverse: Yes

Send String: GET/status.htmlHTTP/1.1/r/nHost:test.example.com/r/nConnector:Close Receive String: Up

The HTTP server sends the following response:

303 question answer

What is the resulting pool status?

A.

Unavailable (Enabled)

Available (Enabled)

B.

Offline (Enabled)

C.

Unknown (Disabled)

Full Access
Question # 48

An LTM Specialist needs to add a pool that will load balanceMYSOL services. It has four members, each with differing hardware platforms. All pool members are already assigned to another pool for load balancing FTP traffic.

Which load balancing method is most effective when the LTM Specialist sets up the pool?

A.

Observed (node)

B.

Predictive member)

C.

Round Robin

D.

Least Connections (node)

Full Access
Question # 49

A BIG-IP Administrator needs to view the CPU utilization of a particular Virtual Server. Which section of the Configuration Utility should the administrator use for this purpose?

A.

Statistics > Module Statistics > Local Traffic > Virtual Addresses

B.

Statistics > Module Statistics > Traffic Summary

C.

Statistics > Analytics > Process CPU Utilization

D.

Statistics > Module Statistics > Local Traffic > Virtual Servers

Full Access
Question # 50

-- Exhibit –

303 question answer

-- Exhibit --

Refer to the exhibit.

An LTM Specialist creates a virtual server to load balance traffic to a pool of HTTPS servers. The servers use client certificates for user authentication. The virtual server has clientssl, serverssl, and http profiles enabled. Clients are unable to connect to the application through the virtual server, but they are able to connect to the application servers directly.

Which change to the LTM device configuration will resolve the problem?

A.

Install the server certificate/key and enable Proxy SSL.

B.

Use the serverssl-insecure-compatible serverssl profile.

C.

Configure the clientssl profile to require a client certificate.

D.

Install the client's issuing Certificate Authority certificate on the LTM device.

Full Access
Question # 51

An LTM Specialist needs to deploy a virtual server that will load balance traffic targeting https://register.example.com to a set of three web servers. Persistence needs to be ensured. No persistence mirroring is allowed SSL offloading is required.

A fourth web server with fewer resources will be used to handle requests from engine bots to https://register.example.comvrobots.txt by an iRule. The (Rule will use the HTTP_REQUEST event. .

What are the required profile and persistence settings to implement this

A.

tcp. dientssl, hup, source address persistence

B.

tcp, clientssl, http. cookie persistence

C.

tcp, clientssl, serverssl, ssl persistence

D.

tcp, clientssl, http, serverssl cookie persistence

Full Access
Question # 52

An LTM Specialist needs to configure a virtual server with the requirements displayed below.

Application is currently an internal HTTPapplication

Encrypted external user access

Links are hard for siteA example.com and need to rewritten to siteB.Example.com

Which profiles must the LTM Specialist use to provide the proper functionality?

A.

Clientssll, Stream

B.

Serverless, Stream

C.

Clientssl, fastL4, Stream

D.

Serverless, fastL4, Stream

Full Access
Question # 53

An LTM Specialist has just manually failed the active LTM device over to the standby LTM device. The LTM Specialist notices the newly active LTM device is NOT currently receiving traffic. The LTM Specialist verifies the newly active device is responding to ARP but still no traffic is hitting the virtual servers. The LTM Specialist also notices that the virtual servers eventually start responding.

What should be added to the configuration to resolve the problem?

A.

vlan failsafe

B.

floating self IP

C.

network failover

D.

MAC masquerading

E.

connection mirroring

Full Access
Question # 54

A BIG-IP Administrator opens a case with F5 Support. The support engineer requests the BIG-IP

appliance chassis serial number.

Which TMSH command will provide this information?

A.

. list /sys software

B.

show /sys version

C.

list/sys diags

D.

show /sys hardware

Full Access
Question # 55

The BIG-IP Administrator configures an HTTP monitor with a specific receive string. The status is marked

'down'.

Which tool should the administrator use to identify the problem?

A.

Ping

B.

Health

C.

tcpdump

D.

ifconfig

Full Access
Question # 56

Refer to the exhibit.

303 question answer

A BIG-IP Administrator needs to deploy an application on the BIG-IP system to perform SSL offload and

re-encrypt the traffic to pool members.

During testing, users are unable to connect to the application.

What must the BIG-IP Administrator do to resolve the issue?

A.

Remove the configured SSL Profile (Client)

B.

Configure Protocol Profile (Server) as splitsession-default-tcp

C.

Enable Forward Proxy in the SSL Profile (Client)

D.

Configure an SSL Profile (Server)

Full Access
Question # 57

Refer to the exhibit.

303 question answer

Why is the virtual server responsive to incoming connections?

A.

The pool member is disabled

B.

The pool member monitor failed

C.

The node is disabled.

D.

The node monitor failed

Full Access
Question # 58

Refer to the exhibit.

303 question answer

How many nodes are represented on the network map shown?

A.

Four

B.

Three

C.

One

D.

Two

Full Access
Question # 59

A web application requires knowledge of the client's true IP address for logging and analysis purposes. Instances of the application that can decode X-Forwarded-For HTTP headers reside in pool_a, while pool_b instances assume the source IP is the true address of the client.

Which iRule provides the proper functionality?

A.

when HTTP_DATA {

if {[HTTP::header exists X-Forwarded-For]}{

pool pool_a

} else {

pool pool_b

}

}

B.

when HTTP_RESPONSE {

if {[HTTP::header exists X-Forwarded-For]}{

pool pool_a

} else {

pool pool_b

}

}

C.

when HTTP_REQUEST {

if {[HTTP::header exists X-Forwarded-For]}{

pool pool_a

} else {

pool pool_b

}

}

D.

when HTTP_OPEN {

if {[HTTP::header exists X-Forwarded-For]}{

pool pool_a

} else {

pool pool_b

}

}

Full Access
Question # 60

-- Exhibit –

303 question answer

-- Exhibit --

Refer to the exhibit.

Which profile could be removed or changed on this virtual server to reduce CPU load on the LTM device without increasing server side bandwidth usage?

A.

tcp

B.

http

C.

httpcompression

D.

optimized-caching

Full Access
Question # 61

-- Exhibit --

303 question answer

-- Exhibit --

Refer to the exhibit.

A company uses a complex piece of client software that connects to one or more virtual servers (VS) hosted on an LTM device. The client software is experiencing issues. An LTM Specialist must determine the cause of the problem.

The LTM Specialist is seeing a client source IP of 168.210.232.5 in the tcpdump. However, the client source IP is actually 10.123.17.12.

Why does the IP address of 10.123.17.12 fail to appear in the tcpdump?

A.

The LTM device performed NAT on the individual's IP address.

B.

The Secure Network Address Translation (SNAT) pool on the virtual server is activated.

C.

Network Address Translation (NAT) has occurred in the path between the client and the LTM device.

D.

The individual's data stream is being routed to the LTM device by a means other than the default route.

Full Access
Question # 62

Refer to the exhibit.

303 question answer

The pool shown isconfigured with four pool members in a variety of states. The application is receiving a large number of request. The LTM Specialist needs to make changes to make sure that all members receive the same levels of traffic.

Which changes need to be made?

A.

Enable 10.80.1.40 disable priority group activation, enable ratio

B.

Enable 10.80.1.40 and 10.80.1.1.20 disable group activation, enable Round Robin

C.

Enable 10.80.1.20 disable priority group activation, enable Round Robin

D.

Enable 10.80.1.40 and 10.80.1.20 disable priority group activation, enable ratio.

Full Access
Question # 63

What is the status of a pool member when manual resume is enabled and a health check first fails and then passes?

A.

Offline (Disabled)

B.

Offline (Enabled)

C.

Available (Disabled)

D.

Available (Enabled)

Full Access
Question # 64

-- Exhibit –

303 question answer

-- Exhibit --

Refer to the exhibit.

Users report that a web application works incorrectly. Sometimes contextual data displayed on the web pages is accurate; other times it is inaccurate.

The LTM administrator looks at the connection table with a filter on one of the client IP addresses currently connected using the command "tmsh show sys connection cs-client-addr 10.0.20.1"

with the following results:

10.0.20.1:60048 10.0.20.88:80 10.0.20.1:60048 172.16.20.1:80 tcp 3 (tmm: 0)

10.0.20.1:60050 10.0.20.88:80 10.0.20.1:60050 172.16.20.3:80 tcp 3 (tmm: 0)

10.0.20.1:60047 10.0.20.88:80 10.0.20.1:60047 172.16.20.2:80 tcp 3 (tmm: 0)

10.0.20.1:60049 10.0.20.88:80 10.0.20.1:60049 172.16.20.1:80 tcp 3 (tmm: 0)

What is the solution to the problem?

A.

Synchronize the clock of the LTM device with NTP.

B.

Modify the load balancing method attached to the pool.

C.

Set up an HTTP cookie insert profile in the virtual server.

D.

Modify the setup of the monitor bound to the pool used by the application.

Full Access
Question # 65

An LTM Specialist reports that an application si no longer reachable after it has beenupgraded.

Nothing has been changed in the configuration on the LTM device.

The logs indicates that health monitors to all servers have failed as shown:

What should the LTM Specialist verify next?

A.

That the TCP hand shake with the servers is stall completed using tcpdump

B.

That the custom receive string for the HTTP monitor has changed with the upgrade

C.

That the can still ping the servers from te BIG_ IP device.

D.

That the firewall between the BIG-ip device and servers is still allowing HTTP

Full Access
Question # 66

-- Exhibit –

303 question answer

303 question answer

-- Exhibit --

Refer to the exhibits.

An LTM Specialist is troubleshooting an issue with one of the virtual servers on an LTM device, and all requests are receiving errors. Testing directly against the server generates no errors. The LTM Specialist has captured the request and response on both client and server sides of the LTM device.

What should the LTM Specialist do to fix this issue?

A.

Remove "header-erase Host" in http profile.

B.

Configure SNAT Automap on the virtual server.

C.

Assign OneConnect profile to the virtual server.

D.

Set "redirect-rewrite" to "selective" in http profile.

Full Access
Question # 67

An LTM Specialist needs to create a virtual server to pass TCP traffic to three pool members.

Which two virtual server types should be used to meet the requirements? (Choose two)

A.

Performance (Layer A)

B.

Standard

C.

Forwarding (IP)

D.

Stateless

E.

Forwarding (Layer 2)

Full Access
Question # 68

The active LTM device in a high-availability (HA) pair performs a failover at the same time the network team reports an outage of a switch on the network.

Which two items could have caused the failover event? (Choose two.)

A.

a VLAN fail-safe setting

B.

a monitor on a pool in an HA group

C.

the standby LTM that was rebooted

D.

an Auditor role that has access to the GUI

E.

the standby LTM that lost connectivity on the failover VLAN

Full Access
Question # 69

Users are unable to reach an application. The BIG-IP Administrator checks the Configuration Utility and observes that the Virtual Server has a red diamond in front of the status. What is causing this issue?

A.

All pool members are down.

B.

The Virtual Server is receiving HTTPS traffic over HTTP virtual.

C.

The Virtual Server is disabled.

D.

All pool members have been disabled.

Full Access
Question # 70

A BIG-IP Administrator runs the initial configuration wizard and learns that the NTP servers were invalid. In which area of the Configuration Utility should the BIG-IP Administrator update the list of configured NTP servers?

A.

System > Configuration

B.

System > Services

C.

System > Preferences

D.

System > Platform

Full Access
Question # 71

An LTM Specialist needs to modify the logging level for tcpdump execution events. Checking the BigDB Key, the following is currently configured:

sys db log.tcpdump.level {

value "Notice"

}

Which command should the LTM Specialist execute on the LTM device to change the logging level to informational?

A.

tmsh set /sys db log.tcpdump.level value informational

B.

tmsh set /sys db log.tcpdump.level status informational

C.

tmsh modify /sys db log.tcpdump.level value informational

D.

tmsh modify /sys db log.tcpdump.level status informational

Full Access
Question # 72

An LI M device is experiencing a high volume of traffic. The virtual server is struggling under the load. The problem appears to be on the server side connections. The virtual server isaccepting connections . The virtual server is accepting connections on https and is configured with an SSL profile and http pool.

What should be added to increase the performance of the device?

A.

an HTTP Compression profile

B.

a One Connect profile

C.

smaller key to the SSL profile

D.

a SPDY profile

Full Access
Question # 73

An application is sensitive to packet loss and unexpected session termination. A pair of LTM devices is configured in an Active/Standby high availability configuration. SNATS are NOT used and the virtual server contains a Universal Persistence profile.

which two actions must an LTM Specialist take to ensure the sessions are maintained between the client and server during an LTM device failover event while maintaining maximum uptime? (Choose two.)

A.

configure a serial failover cable for mirror traffic

B.

configure a OneConnect profile to mirror connections

C.

configure a VLAN and primary mirroring address for mirror traffic

D.

enable Mirroring for a virtual server and persistence profile

E.

enable Clone Pools for a virtual server and a persistence profile

Full Access
Question # 74

The pool members are serving up simple static web content.

The current virtual server configuration is given as follows:

tmsh list ltm virtual simple

ltm virtual simple {

destination 10.10.10.10:80

ip-protocol tcp

mask 255.255.255.255

profiles {

http { }

httpcompression { }

oneconnect { }

tcp { }

}

snat automap

vlans-disabled

}

tmsh list ltm pool simple_pool

ltm pool simple_pool {

members {

10.10.10.11:80 {

address 10.10.10.11 }

10.10.10.12:80 {

address 10.10.10.12 }

10.10.10.12:80 {

address 10.10.10.13 }

}

}

Which three objects in the virtual server configuration can be removed without disrupting functionality of the virtual server? (Choose three.)

A.

tcp

B.

http

C.

oneconnect

D.

snat automap

E.

httpcompression

Full Access
Question # 75

An LTM Specialist is troubleshooting an issue with a new virtual server. When connecting through the virtual server, clients receive the message "Unable to connect" in the browser, although connections directly to the pool member show the application is functioning correctly. The LTM configuration is:

ltm virtual /Common/vs_https {

destination /Common/10.10.1.110:443

ip-protocol udp

mask 255.255.255.255

pool /Common/pool_https

profiles {

/Common/udp { }

}

translate-address enabled

translate-port enabled

vlans-disabled

}

ltm pool /Common/pool_https {

members {

/Common/172.16.20.1:443 {

address 172.16.20.1

}

}

}

How should the LTM Specialist resolve this issue?

A.

Remove an HTTP monitor from the pool.

B.

Add an HTTP profile to the virtual server.

C.

Enable the pool member on the correct VLAN.

D.

Select the correct protocol for the virtual server.

Full Access
Question # 76

-- Exhibit –

303 question answer

-- Exhibit --

Refer to the exhibit.

Users receive an error when attempting to connect to the website https://website.com. The website has a DNS record of 195.56.67.90. The upstream ISP has confirmed that there is nothing wrong with the routing between the user and the LTM device.

The following tcpdump outputs have been captured:

External Vlan, filtered on IP 168.210.232.5

00:25:07.598519 IP 168.210.232.5.33159 > 195.56.67.90.https: S 1920647964:1920647964(0) win 8192

00:25:07.598537 IP 195.56.67.90.https > 168.210.232.5.33159: S 2690691360:2690691360(0) ack 1920647965 win 4350

00:25:07.598851 IP 168.210.232.5.33160 > 195.56.67.90.https: S 2763858764:2763858764(0) win 8192

00:25:07.598858 IP 195.56.67.90.https > 168.210.232.5.33160: S 1905576176:1905576176(0) ack 2763858765 win 4350

Internal Vlan, filtered on IP 168.210.232.5

00:31:46.171124 IP 168.210.232.5.33202 > 192.168.100.20.http: S 2389057240:2389057240(0) win 4380

What is the problem?

A.

The filters on the tcpdumps are incorrect.

B.

The DNS entry for website.com is incorrect.

C.

The virtual server 'WEBSERVICES1' is listening on the incorrect port.

D.

The firewall is dropping the connection coming from the pool members returned to the client.

E.

The subnet masks of the pool members of pool WebServices1 and the f5 'Internal' Vlan are incorrect.

Full Access
Question # 77

Refer to the exhibit.

303 question answer

The BIG-IP Administrator is investigating disk utilization on the BIG-IP device.

What should the BIG-IP Administrator check next?

A.

Large files on the / file system

B.

Results from the EUD test

C.

Results from the platform diagnostics test

D.

Large files on /usr file system

Full Access
Question # 78

Which iRule will reject any connection originating from a 10.0.0.0/8 network?

A.

when CLIENT_ACCEPTED {

set remote_ip [IP::addr [IP::remote_addr] mask 8]

switch $remote_ip {

"10.0.0.0" { reject }

"11.0.0.0" { pool pool_http1}

default { pool http_pool }

}

}

B.

when CLIENT_ACCEPTED {

set remote_ip [IP::addr [IP::local_addr] mask 8]

switch $remote_ip {

"10.0.0.0" { reject }

"11.0.0.0" { pool pool_http1}

default { pool http_pool }

}

}

C.

when CLIENT_ACCEPTED {

set remote_ip [IP::addr [IP::client_addr] mask 255.0.0.0]

switch $remote_ip {

"10.0.0.0" { reject }

"11.0.0.0" { pool pool_http1}

default { pool http_pool }

}

}

D.

when CLIENT_ACCEPTED {

set remote_ip [IP::addr [IP::local_addr] mask 255.0.0.0]

switch $remote_ip {

"10.0.0.0" { reject }

"11.0.0.0" { pool pool_http1}

default { pool http_pool }

}

}

Full Access