Summer Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70percent

F5 F5CAB3 BIG-IP Administration Data Plane Configuration (F5CAB3) exam Exam Practice Test

Demo: 24 questions
Total 82 questions

BIG-IP Administration Data Plane Configuration (F5CAB3) exam Questions and Answers

Question 1

For a given Virtual Server, the BIG-IP must perform SSL Offload and negotiate secure communication over TLSv1.2 only. What should the BIG-IP Administrator do to meet this requirement?

Options:

A.

Configure a custom SSL Profile (Client) with a custom TLSv1.2 cipher string

B.

Configure a custom SSL Profile (Server) and select no TLSv1 in the options list

C.

Configure a custom SSL Profile (Server) with a custom TLSv1.2 cipher string

D.

Configure a custom SSL Profile (Client) and select no TLSv1 in the options list

Question 2

A BIG-IP Administrator creates a new Virtual Server to load balance SSH traffic. Users are unable to log on to the servers.

What should the BIG-IP Administrator do to resolve the issue?

Options:

A.

Set Protocol to UDP

B.

Set HTTP Profile to None

C.

Set Source Address to 10.1.1.2

D.

Set Destination Address/Mask to 0.0.0.0/0

Question 3

DNS queries from internal DNS servers fail when sent through a BIG-IP Virtual Server.

Which Virtual Server property should be changed?

Options:

A.

Protocol Profile (Client) to DNS_OPTIMIZED

B.

Type to Performance (HTTP)

C.

Protocol to UDP

D.

Source Address to subnet

Question 4

To increase available bandwidth of an existing Trunk, the BIG-IP Administrator is adding additional interfaces. Which command should the BIG-IP Administrator run from within the bash shell?

Options:

A.

tmsh create /sys trunk trunk_A interfaces add {1.3 1.4}

B.

tmsh create /net trunk trunk_A interfaces add {1.3 1.4}

C.

tmsh modify /sys trunk trunk_A interfaces add {1.3 1.4}

D.

tmsh modify /net trunk trunk_A interfaces add {1.3 1.4}

Question 5

A BIG-IP Administrator adds new pool members into a highly utilized pool. Users report application failures.

Which pool-level setting should be checked?

Options:

A.

Availability Requirement

B.

Allow SNAT

C.

Action On Service Down

D.

Slow Ramp Time

Question 6

Refer to the exhibit.

A BIG-IP Administrator creates a new Virtual Server to load balance SSH traffic. Users are unable to log on to the servers.

What should the BIG-IP Administrator do to resolve the issue? (Choose one answer)

Options:

A.

Set Protocol to UDP

B.

Set Source Address to 10.1.1.2

C.

Set Destination Address/Mask to 0.0.0.0/0

D.

Set HTTP Profile to None

Question 7

Which type of Virtual Server requires the use of a FastL4 profile?

Options:

A.

Performance (Layer 4)

B.

Stateless

C.

Performance (HTTP)

D.

Standard

Question 8

A Standard Virtual Server reports poor network performance for Internet-based clients.

What configuration should be applied?

Options:

A.

Client TCP: f5-tcp-wan / Server TCP: f5-tcp-lan

B.

Client TCP: f5-tcp-lan

C.

Client TCP: f5-tcp-lan / Server TCP: f5-tcp-wan

D.

Client TCP: f5-tcp-optimized

Question 9

Users are unable to reach an application. The Virtual Server shows a red diamond status in the Configuration Utility.

What is the cause?

Options:

A.

All pool members are down

B.

HTTPS traffic sent to HTTP Virtual Server

C.

Virtual Server is disabled

D.

All pool members are disabled

Question 10

A BIG-IP Administrator configures a Virtual Server to load balance traffic between 50 webservers for an ecommerce website. Traffic is being load balanced using the Least Connections (node) method. The webserver administrators report that customers are losing the contents from their shopping carts and are unable to complete their orders. What should the BIG-IP Administrator do to resolve the issue?

Options:

A.

Change Default Persistence Profile setting to cookie

B.

Change Default Persistence Profile setting to sip_info

C.

Change Load Balancing method to Ratio (node)

D.

Change Load Balancing method to Ratio (member)

Question 11

A BIG-IP Administrator is creating a new Trunk on the BIG-IP device. What objects should be added to the new Trunk being created?

Options:

A.

IP addresses

B.

Network routes

C.

VLANs

D.

Interfaces

Question 12

Users report that traffic is negatively affected every time a BIG-IP device fails over. The traffic becomes stabilized after a few minutes. What should the BIG-IP Administrator do to reduce the impact of future failovers?

Options:

A.

Set up Failover Method to HA Order

B.

Enable Failover Multicast Configuration

C.

Configure MAC Masquerade

D.

Configure a global SNAT Listener

Question 13

A BIG-IP Administrator needs to modify a virtual server that will offload web traffic compression tasks from the target server. Which two profiles must the BIG-IP Administrator apply to a virtual server to enable compression? (Pick the 2 correct responses below)

Options:

A.

Persistence profile

B.

Compression profile

C.

Server SSL profile

D.

Stream profile

E.

HTTP profile

Question 14

A BIG-IP Administrator needs to configure health monitors for a pool containing HTTP, HTTPS, FTP, and SSH services.

Which configuration ensures accurate member status?

Options:

A.

All monitors with Availability Requirement = all

B.

All monitors with Availability Requirement = at least one

C.

ICMP + TCP with all

D.

HTTP and HTTPS only

Question 15

A web server administrator informs the BIG-IP Administrator that web servers currently load-balanced require encrypted traffic. Starting next month, the web server administrator will offload SSL. Starting next month, the BIG-IP device will terminate SSL to reduce web server load. The BIG-IP device is already using Client SSL, Client port, and iRules on HTTP traffic. What actions should the BIG-IP Administrator take to achieve the desired configuration? (Choose one answer)

Options:

A.

Remove the server SSL profile and configure the pool members to use HTTP

B.

Remove the client SSL profile and configure the pool members to use HTTP

C.

Remove the server SSL profile and change the Virtual Server to accept HTTP traffic

D.

Remove the client SSL profile and change the Virtual Server to accept HTTP traffic

Question 16

A virtual server is configured to offload SSL from a pool of backend servers. When users connect to the virtual server, they successfully establish an SSL connection but no content is displayed. A packet trace performed on the server shows that the server receives and responds to the request. What should a BIG-IP Administrator do to resolve the problem? (Choose one answer)

Options:

A.

enable Server SSL profile

B.

disable Server SSL profile

C.

disable SNAT

D.

enable SNAT

Question 17

A BIG-IP Administrator configures a node with a standard icmp Health Monitor. The Node shows as DOWN although the Backend Server is configured to answer ICMP requests. Which step should the administrator take next to find the root cause of this issue?

Options:

A.

Run a qkview

B.

Run a tcpdump

C.

Run an ssldump

D.

Run a curl

Question 18

The BIG-IP Administrator has to provide encrypted communication between the users and the virtual server they access. Multiple hostnames are configured in DNS with the same IP address. Which profile type and setting in the profile should be used?

Options:

A.

Client SSL, Client Name

B.

Server SSL, Client Name

C.

Server SSL, Server Name

D.

Client SSL, Server Name

Question 19

A BIG-IP Administrator is configuring an SSH Pool with five members. Which Health Monitor should be applied to ensure that available pool members are monitored accordingly?

Options:

A.

UDP

B.

HTTP

C.

HTTPS

D.

TCP

Question 20

A BIG-IP Administrator finds the following log entry after a report of user issues connecting to a virtual server:

01010201: Intercept exhaustion on 10.70.110.112 to 192.28.123.250:80 (proto 6)

How should the BIG-IP Administrator modify the SNAT pool that is associated with the virtual server? (Choose one answer)

Options:

A.

Increase the timeout of the SNAT addresses

B.

Remove the SNAT pool and apply SNAT Automap

C.

Remove an IP address from the SNAT pool

D.

Add an IP address to the SNAT pool

Question 21

All pool members are online and all other settings are default.

What might alter the load balancing behavior?

Options:

A.

Adding a OneConnect profile

B.

Enabling SNAT Automap

C.

Enabling an HTTP fallback host

D.

Adding a persistence profile

Question 22

The BIG-IP Administrator has to provide encrypted communication between the users and the virtual server they access. Multiple hostnames are configured in DNS with the same IP address. Which profile type and setting in the profile should be used? (Choose one answer)

Options:

A.

Client SSL, Client Name

B.

Server SSL, Server Name

C.

Client SSL, Server Name

D.

Server SSL, Client Name

Question 23

A node is a member of multiple pools hosting different web applications. If one application fails, only that pool member should be marked down.

What should be configured?

Options:

A.

UDP monitor

B.

ICMP + TCP monitor

C.

HTTP monitor with custom send/receive

D.

TCP monitor

Question 24

Which of the following has iApp configured objects?

Options:

A.

ltm virtual /Common/vmware_test.app/vmware_test_proxy_https {app-service /Common/vmware_test.app/vmware_testcreation-time 2024-04-12:08:49:12destination /Common/10.155.47.199:443ip-protocol tcplast-modified-time 2024-04-12:08:49:12mask 255.255.255.255profiles {/Common/ppp {}/Common/rba {}/Common/vdi {}/Common/vmware_test.app/vmware_test {}/Common/vmware_test.app/vmware_test_client_ssl {context clientside}/Common/vmware_test.app/vmware_test_

B.

ltm virtual /Common/app2_vs {creation-time 2020-02-07:09:48:01description https://app2.apmsupport.localdestination /Common/10.155.47.161:443ip-protocol tcplast- modified-time 2024-05-13:06:02:40mask 255.255.255.255pool /Common/https_lamp_poolprofiles {/Common/apm_support {context clientside}/Common/f5-tcp-progressive {}/Common/http {}/Common/multi_domain_ap {}/Common/rba {}/Common/serv

C.

ltm virtual /Common/test_vs {creation-time 2023-09-01:12:28:27destination /Common/10.176.21.11:443disabledip-protocol tcplast-modified-time 2023-09-01:12:29:40mask 255.255.255.255profiles {/Common/fastL4 {}}serverssl-use-sni disabledsource 0.0.0.0/0translate-address enabledtranslate-port enabled}

D.

ltm virtual /Common/app1_vs {creation-time 2020-02-07:09:47:12description https://app1.apmsupport.localdestination /Common/10.155.47.160:443ip-protocol tcplast-modified-time 2024-05-15:09:57:19mask 255.255.255.255pool /Common/https_lamp_poolprofiles {/Common/apm_support {context clientside}/Common/f5-tcp-progressive {}/Common/http {}/Common/multi_domain_ap {}/Common/oneconnect {}/Common

Demo: 24 questions
Total 82 questions