Key details for this exam, checked against the published exam outline
Each question shows the correct answer and an explanation of why it is right
Plaintext
warning tmm[
warning tmm[
What is happening when the BIG-IP Administrator sees the messages in the LTM log displayed above? (Pick the 2 correct responses below)
These log messages indicate that the BIG-IP system is under significant resource pressure and has activated its Adaptive Connection Management.
Global Eviction Policy: The message Aggressive mode ... activated (global memory) confirms that the system has reached a memory utilization threshold that triggers the eviction policy. This happens because TMM (the data plane) is running low on available memory pages.
Sweeper/Reaping: Once in 'Aggressive mode,' the BIG-IP 'sweeper' starts reaping (terminating) connections to free up memory. The log Connections killed confirms this is occurring.
Impact: The system does not drop all connections; it targets connections based on the eviction policy (e.g., oldest connections or those exceeding limits) to bring memory usage back to safe levels. Thus, some connections will be dropped (Option A), and the cause is TMM memory exhaustion (Option C).
A BIG-IP Administrator receives reports from users that SSL connections to the BIG-IP device are failing. Upon checking the log files, the administrator notices: SSL transaction (TPS) rate limit reached. stats show a maximum of 1200 client-side SSL TPS and 800 server-side SSL TPS. What is the minimum SSL license limit required to handle this peak?
Troubleshooting failed SSL handshakes involves interpreting the resource limits defined by the system's license8888. The log message SSL transaction (TPS) rate limit reached indicates the BIG-IP is dropping SSL connections because it has exceeded its licensed 'Transactions Per Second' capacity. When analyzing stats to determine the correct license level, the administrator must focus on 'Client-side' SSL TPS. This represents the initial encrypted handshakes between users and the BIG-IP virtual servers91. In this scenario, the peak client-side demand is 1200 TPS. While the 800 server-side transactions represent re-encryption toward the backend, F5's primary SSL TPS license limits typically apply to the client-facing side of the traffic flow. Therefore, to resolve the intermittent connectivity issues and ensure the virtual server works reliably during peaks, the license must be upgraded to at least 1200 TPS949596969696.9798Confirming this peak via statistics andcomparing it to the current license is a standard troubleshooting step for SSL performance issues.
Where should the BIG-IP Administrator go in the GUI to verify the status of pool members of a pool?
To verify the specific health and availability status of individual members within a specific pool, the administrator must navigate to the Members tab of that specific pool.
Navigation Path: The correct path is Local Traffic > Pools > Pool List, then clicking on the name of the
Why Option A is correct: While you can see a general status summary on the Pool List page (Option B), that page only shows the status of the pool as a whole. To troubleshoot why a pool is not working or to see which specific member is down, you must drill down into the Members tab.
Evaluation of Other Options:
Local Traffic ---> Pools (Option B): This leads to the Pool List. It shows the aggregate status of all pools but does not list individual member details or their specific monitor results without further clicking.
Local Traffic ---> Virtual Servers ---> Statistics (Option C): This path shows traffic statistics (bits in/out, connections) for virtual servers, not the health monitor status of individual pool members.
Local Traffic ---> Nodes (Option D): While this shows the health of the underlying IP address (Node), it does not show the status of the specific service (Port/Member) within a pool. A Node might be 'Up' (ICMP), while the Pool Member is 'Down' (HTTP failure).
A BIG-IP Administrator needs to determine why only one pool member is showing connections from the virtual server, resulting in uneven load balancing.
What two reasons would cause uneven load balancing? (Choose two answers)
Uneven load balancing on a BIG-IP system typically occurs when traffic is not distributed evenly across all available pool members. One common reason is thatmonitors have marked down multiple pool members (Option B). When health monitors fail for specific pool members, BIG-IP automatically removes those members from load-balancing decisions. As a result, traffic is sent only to the remaining healthy member, creating the appearance that load balancing is not functioning correctly. This behavior is expected and aligns with BIG-IP's design to ensure traffic is sent only to healthy resources.
Another frequent cause isthe presence of a persistence profile on the pool or virtual server (Option C). Persistence (such as source address or cookie persistence) forces subsequent client connections to be sent to the same pool member for session continuity. While persistence is critical for certain applications, it can override the load-balancing algorithm and cause most or all traffic to be directed to a single pool member, especially during low traffic volumes or testing scenarios.
The other options are incorrect because avirtual server marked down (Option A)would not pass traffic at all, andall pool members marked down (Option D)would result in no connections rather than uneven distribution. This analysis follows standard BIG-IP troubleshooting methodology using pool status, monitor results, and persistence configuration review.
A BIG-IP Administrator makes a configuration change to a Virtual Server on the Standby device of an HA pair. The HA pair is currently configured with Auto-Sync Enabled. What effect will the change have on the HA pair configuration?
Understanding High Availability (HA) synchronization behavior is critical for maintaining a stable environment. In a device group where 'Auto-Sync' is enabled, the BIG-IP system monitors the management plane for any configuration updates across all members. While best practices often suggest making changes on the 'Active' device, TMOS allows changes on any device within the group. When a change is made on the 'Standby' device, the system detects a configuration mismatch and, because Auto-Sync is enabled, it automatically pushes those changes to the other devices in the sync group, including the current Active member. To troubleshoot if this is working correctly, the administrator should review the 'Sync Status' stats in the Configuration Utility. If the changes do not propagate, it suggests9 a breakdown i10n the HA trust relationship or network connectivity issues on the failover VLAN. Proper interpretation of this scenario confirms that the HA functionality is operating correctly, ensuring that both devices have a consistent set of virtual servers and pools, which is vital f11or seamless failover.
A BIG-IP Administrator configured the following virtual server to pass traffic on all addresses and ports. After configuration is completed, the BIG-IP Administrator notices that the virtual server is unable to pass traffic.
Plaintext
ltm virtual forwarding_any_vs {
destination 0.0.0.0:any
ip-forward
mask 255.255.255.255
profiles {
fastL4 {}
}
serverssl-use-sni disabled
source 0.0.0.0/0
translate-address disabled
translate-port disabled
}
Which part of the configuration is the cause of the issue?
The failure of the Forwarding (IP) virtual server is caused by an incorrect Network Mask configuration for a wildcard destination.
Wildcard Destination: The administrator intends to create a 'Wildcard' Virtual Server that listens for any destination IP address (0.0.0.0).
The Mask Conflict: A mask of 255.255.255.255 (or /32) tells the BIG-IP to look for a specific, single host address. When combined with 0.0.0.0, the system is literally looking for traffic destined for the IP 0.0.0.0, which is not a valid routable destination for standard traffic.
Correct Configuration: To allow the virtual server to catch traffic for any IP address, the mask must be changed to 0.0.0.0 (or /0). This signifies that the system should ignore all bits of the destination address and match everything.
Forwarding Logic: The rest of the configuration---including ip-forward (Forwarding IP type), translate-address disabled, and translate-port disabled---is correct for a BIG-IP acting as a router/gateway.
Exam domains verified against: Official F5 Networks F5CAB5 exam guide, last checked September 2026.
Distinguish between control plane and data plane resources to understand where processing occurs. Identify CPU statistics per virtual server and interpret statistics for interfaces to spot performance bottlenecks.
Identify when a packet capture is needed to diagnose problems and interpret availability status of interfaces. Recognize when drops are occurring and distinguish between TCP profiles to optimize throughput.
Review persistence settings, priority group activation, and rate and connection limits that prevent balanced traffic distribution. Check for misconfigurations in health checks and action on service down settings.
Sample question from this domain above: Q4
Check the availability status of the virtual server and identify conflicting or misconfigured profiles that block requests. Verify the IP address and port are configured correctly for the intended traffic.
Sample question from this domain above: Q2
Determine why health monitors have marked pool members down and confirm they are in the active priority group. Review the current configured and availability status of the pool and its members.
Sample question from this domain above: Q3
Interpret traffic object statistics and network configuration statistics to verify the system is operating as designed. Use statistics to prove that virtual servers, pools, and profiles are configured and functioning correctly.
Explain how application client-server communication flows through BIG-IP and interpret traffic graphs showing SNMP results. Trace packets from client through the BIG-IP to the backend server to understand path and transformations.
Common questions about the exam itself