Pass the F5 BIG-IP ASM 303 Questions and answers with CertsForce

Viewing page 8 out of 11 pages
Viewing questions 106-120 out of questions
Questions # 106:

An LTM Specialist is troubleshooting a problem on an eCommerce website. The user browses the online store using port 80, adding items to the shopping cart. The user then clicks the "Checkout" button on the site, which redirects the user to port 443 for the checkout process. Suddenly, the user's shopping cart is shown as empty. The shopping cart data is stored in memory on the server, and the default source address persistence profile is used on both virtual servers.

How should the LTM Specialist resolve this issue?

Options:

A.

Add an HTTP profile to both virtual servers.


B.

Enable SNAT Automap on both virtual servers.


C.

Create a custom persistence profile and enable "Map Proxies."


D.

Create a custom persistence profile and enable "Match Across Services."


Expert Solution
Questions # 107:

Which two subsystems could the LTM Specialist utilize to access an LTM device with lost management interface connectivity? (Choose two.)

Options:

A.

AOM


B.

ILO


C.

SCCP


D.

ALOM


Expert Solution
Questions # 108:

A BIG-IP Administrator is configuring a pool with members who have differing capabilities. Connections

to pool members must be load balanced appropriately.

Which load balancing method should the BIG-IP Administrator use?

Options:

A.

Least Sessions


B.

Least Connections (member)


C.

Fastest (node)


D.

Weighted Least Connections (member)


Expert Solution
Questions # 109:

-- Exhibit –

Question # 109

-- Exhibit --

Refer to the exhibit.

An LTM Specialist is working on an LTM 11.0.0 installation and has identified a security vulnerability as shown in the exhibit. The LTM Specialist is tasked with applying the latest available hotfix to resolve the problem.

Which procedure resolves the problem?

Options:

A.

Browse to System > Software Management > Hotfix List.

Import TMOS 11.2.0 to the available hotfix images.

Select the imported hotfix image and installation location and click Install.


B.

Browse to System > Software Management > Hotfix List.

Import 11.1.0.HF3 to the available hotfix images.

Select the imported hotfix image and installation location and click Install.


C.

Browse to System > Software Management > Image List.

Import TMOS 11.2.0 to the available hotfix images.

Select the imported hotfix image and installation location and click Install.


D.

Browse to System > Software Management > Image List.

Import 11.1.0.HF3 to the available hotfix images.

Select the imported hotfix image and installation location and click Install.


Expert Solution
Questions # 110:

A web server administrator informs the BIG-IP Administrator that web servers are overloaded Starting next month, the BIG-IP device will terminate SSL to reduce web server load. The BIG-IP device is ready using client SSL client profile and Rules on HTTP level. What actions should the BIG-IP Administrators to achieve the desired configuration?

Options:

A.

Remove the server SSL profile and configure the Pool Members to use HTTP


B.

Remove the client SSL profile and configure the Pool Members to US HTTP


C.

Remove the chart SSL profile and change the Virtual Server to accept HTTP


D.

Remove the server SSL profile and change the Virtual Server to accept HTTP traffic


Expert Solution
Questions # 111:

AN LTM Specialist is setting up a new HTTPS virtual server to decrypt client traffic. SNAT the traffic and send the encrypted traffic to the poor member, the client's IP address must be included in the traffic

sent to the pool member.

What is a complete set of profiles that must be configured for the virtual server to meet these requirements?

Options:

A.

TCP, Client SSL, Server SSL


B.

TCP , Server SSL, HTTP


C.

TCP, Client SSL, HTTP


D.

TCP, Client SSL, Server SSL, HTTP


Expert Solution
Questions # 112:

A BIG-IP Administrator uses a device group to share the workload and needs to perform service on a BIG-IP device currently active for a traffic group. The administrator needs to enable the traffic group to run on another BIG-IP device in the device group. What should the administrator do to meet the requirement?

Options:

A.

Create a new Traffic Group and then fail to Standby Unit


B.

Select Traffic Group and then select Failover


C.

Select Traffic Group and then select Force to Standby


D.

Select Traffic Group on Primary Unit and then select Demote


Expert Solution
Questions # 113:

Refer to the exhibit.

Question # 113

An LTMSpecialist configures the two syslog destination Syslog destination #1 can receive messages but the syslog destination #2 can NOT receive messages.

Which command sill correct the issue?

Options:

A.

{/Common)(tmos) # modify /syssyslog remote-servers modify (syslog_dest2 {local-ip


B.

{/Common)(tmos) # modify Ays syslog remote servers modify {syslog_dest2 {local- ip 10.208.102 254)}


C.

{/Common) (tmos) # modify /sys syslog remote-servers modify {syslog_dest2 {host 10 208.102.254 }}


D.

{Common(tmos) # modify/syslog remote-servers modify {syslog_dest2 {lost.10.10.10.28 }}


Expert Solution
Questions # 114:

The interface 1.1 of the BIG-IP device has been connected to a link dedicated to traffic on VLAN 120. What should the BIG-IP Administrator do to receive traffic from the VLAN?

Options:

A.

Create a new VLAN object and set Customer Tag to 120


B.

Create a new VLAN object and assign the interface 1.1 untagged


C.

Create a new trunk object with interface 1.1 assigned


D.

Create a new trunk object and assign it to the VLAN


Expert Solution
Questions # 115:

-- Exhibit –

Question # 115

-- Exhibit --

Refer to the exhibit.

Which two items can be consolidated to simplify the LTM configuration? (Choose two.)

Options:

A.

/Common/vs1-https-redirect


B.

/Common/vs2-https-redirect


C.

/Common/vs3-https-redirect


D.

/Common/vs4-https-redirect


E.

/Common/vs5-https-redirect


Expert Solution
Questions # 116:

A BIG-IP Operator has made a grave error and deleted a few virtual servers on the active LTM device fronting the web browsing proxies. The BIG-IP Operator has NOT yet performed a configuration sync.

Which command should the LTM Specialist execute on the active LTM device to force a failover to the standby node and restore web browsing?

Options:

A.

tmsh /sys failover standby


B.

tmsh run /sys failover standby


C.

tmsh /sys failover status standby


D.

tmsh run /sys failover status standby


Expert Solution
Questions # 117:

An LTM Specialist needs to configure a virtual server with the requirements displayed below.

Application is currently an internal HTTPapplication

Encrypted external user access

Links are hard for siteA example.com and need to rewritten to siteB.Example.com

Which profiles must the LTM Specialist use to provide the proper functionality?

Options:

A.

Clientssll, Stream


B.

Serverless, Stream


C.

Clientssl, fastL4, Stream


D.

Serverless, fastL4, Stream


Expert Solution
Questions # 118:

Users in a branch office are reporting a website is always slow. No other users are experiencing the problem. The LTM Specialist tests the website from the external VLAN along with testing the servers directly. All tests indicate normal behavior. The environment is a single HTTP virtual server on the external VLAN with a single pool containing three HTTP pool members on the internal VLAN.

Which two locations are most appropriate to collect additional protocol analyzer data? (Choose two.)

Options:

A.

a user's machine


B.

the switch local to the user


C.

the LTM device's internal VLAN


D.

the LTM device's external VLAN


E.

a user's Active Directory authentication


Expert Solution
Questions # 119:

A BIG-IP Administrator plans to upgrade a BIG-IP device to the latest TMOS version.

Which two tools could the administrator leverage to verify known issues for the target versions?

(Choose two.)

Options:

A.

F5 University


B.

F5 Downloads


C.

F5 End User Diagnostics (EUD)


D.

FSiHealth


E.

F5 Bug Tracker


Expert Solution
Questions # 120:

Refer to the exhibit

The BIG-IP Administrator is unable to access the management console via Self-IP 10.10 1.33 and port 443.

What is the reason for this problem?

Options:

A.

Packet Filter needs to be configured to allow a source


B.

Self IP is configured to allow TCP All


C.

Self IP is configured to allow UDP 443


D.

Packet Filter is configured to allow port 443


Expert Solution
Viewing page 8 out of 11 pages
Viewing questions 106-120 out of questions