Latest [Jan 11, 2024] 301a Exam Questions – Valid 301a Dumps Pdf [Q89-Q111]

Share

Latest [Jan 11, 2024] 301a Exam Questions – Valid 301a Dumps Pdf

301a Practice Test Questions Answers Updated 150 Questions


F5 301a exam is a comprehensive test that covers various topics related to BIG-IP LTM solutions, including network components, traffic management, load balancing, virtual servers, and iRules. 301a exam consists of 80 multiple-choice questions that must be answered in 90 minutes. 301a exam is available in English and Japanese and can be taken online or at a Pearson VUE testing center.

 

NEW QUESTION # 89
An LTM Specialist has detected that a brute force login attack is occurring against the SSH service via a BIG-IP management interface. Login attempts are occurring from many IPs within the internal company network. BIG-IP SSH access restrictions are in place as follows:

The LTM Specialist has determined that SSH access should only occur from the 192.168.1.0/24 and 172.16.254.0/23 networks.
Which tmsh command should the LTM Specialist use to permit access from the desired networks only?

  • A. modify /sys sshd login disable (''10.0.00/8'', ''172 16.0 0/12'', ''192. 168.0.0/16'')
  • B. modify.sys sshd allow add {''192.168. 10/24 , '' ''172. 16 2540/23'')
  • C. modify/sys sshd login enable {''192.166.10/24'''' ''172.16 254 0/23
  • D. modify/sys allow replace-all-with {''192.168.1.00/24'', ''192.16.254.0/23''}

Answer: D

Explanation:
Select C to overwrite the existing network's allow configuration over the specified network segment.


NEW QUESTION # 90
Where does a LTM Specialist view all of the objects that are part of a deployed iApp?

  • A. Local Traffic . Virtual Servers > Applications
  • B. Local Traffic > Network Map > View Map
  • C. iAPP> Application Policy > Objects
  • D. IAP > Application Service > Components

Answer: D


NEW QUESTION # 91
An LTM Specialist is configuring a client profile to offload processing a new application Company policy requires that clients can resume session for up to 30 minutes, but must renegotiate a new session after that.
Which setting should the LTM Specialist change to satisfy this requirement?

  • A. Renegotiate Max Record Delay
  • B. Cache timeout
  • C. Cache size
  • D. Renegotiation period

Answer: B

Explanation:
Question stem requires that you can resume SSL session within 30 minutes, then you need to define the ssl cache time in 30 minutes


NEW QUESTION # 92
An TLM Specialist needs to configure a virtual server to terminate SSL connection on the LTM device.
Cryptographic information must be re-authorized for SSL sessions that remain open for longer than 30 seconds.
Which settings should the LTM Specialist configure in the client SSL profile?

  • A. enable Require Peer SN1 Support
  • B. set the Renegotiate Max Record Delay to 30
  • C. set the Renegotiate Period to 30 seconds
  • D. set the Handshake Timeout to 30 seconds

Answer: C


NEW QUESTION # 93
Exhibit.

The LTM devices LTM1 and LTM2 are configured in a Device Group (Sync Failover) with Network Failover configured on both the management and HA and Internal VLANS. and ConfigSync is confined in a Device Group (Sync Failover) with Network Failover and internal are tagged on a single trunk with subnets Connection Mirroring is configured on both the HA interlace directly connected between LTM1 and LTM2, and the management interlace is connected to a management switch. The LTM devices have four Traffic Groups defined, and both LTM devices are healthy and capable of passing traffic for any of the Traffic Groups.
An LTM Specialist disconnects the cable for the HA network in an effort to test failover.
Which HA functionality works in this case?

  • A. ConfigSync does NOT work; Connection Mirroring works
  • B. ConfigSync does NOT work. Connection Mirroring floes NOT work.
  • C. ConfigSync works. Connection Mirroring docs NOT work
  • D. ConfigSync works Connection Mirroring works

Answer: A


NEW QUESTION # 94
An LTM Specialist has trouble with SNMP traps in the management network The ITM Specialist takes the network capture shown to troubleshoot:

What should the UM Specialist change to capture packets related to this workflow?

  • A. the interface
  • B. the port
  • C. the verbose level
  • D. the tcpdump filter expression

Answer: A


NEW QUESTION # 95
An LTM device provides load balancing to a web application? The LTM device has two dual-core processors and a licensed SSL Transactions Per Second (TPS) limit of 500 CMP is enabled.
TLS connections are used between client systems and virtual servers on the LTM device, as well as from the LTM device to servers used as part of LTM pool.
TLS enabled virtual servers utilize certificates based on 2048-bit keys During a peak period. 2560 new TLS transactions per second are attempted to the web application via the LTM device.
What will happen in this scenario?

  • A. 560 new TLS transactions will be silently discarded due to the SSL TPS license limit
  • B. Nothing: TLS transactions per second are NOT affected by an SSL TPS license limit
  • C. 2060 new TLS transactions will be silently discarded due to the SSL TPS license limit
  • D. Nothing: 2560 TLS transactions per second is within the SSI TPS license limit.

Answer: A


NEW QUESTION # 96
The network team has recently added a new syslog server with IP address 10.1.1.1.
Which command adds the new syslog entry on the F5 LTM device?
A)

B)

C)

D)

  • A. Option B
  • B. Option C
  • C. Option D
  • D. Option A

Answer: B


NEW QUESTION # 97
Two LTM devices must be manually configured to restrict in the same Device Group.
What is the correct order of steps to meet this requirement?

  • A. Configure Self-IPs, Configure VLAN, Configure Config-Sync IP. Configure Failover type, Establish Device Trust, Sync Device Trust, Create Device Group
  • B. Configure VLAN, Configure Config-Sync IP. Configure Self-IPs. Configure Failover type. Establish Device Trust, Create Device Group
  • C. Configure VLAN, Configure Self-IPs, Configure Config-Sync IP. Configure Failover type, Establish Device Trust, Sync Device Trust, Create Device Group.
  • D. Configure VLAN, Configure-Sync IP, Configure Failover type, Establish Device Trust, Sync Device Trust, Create type, Establish Device Sync Device Trust, Create Device Group.

Answer: C


NEW QUESTION # 98
Remote users who access the LTM device are authenticated via Radius. The default remote user role is Guest Some users need LTM device with the Administrator role. The F5 Radius attributes are configure on the Radius server.
Which configuration item needs to be created?

  • A. Admin account
  • B. User account
  • C. Remote User role
  • D. User role

Answer: C


NEW QUESTION # 99
AN LTM Specialist needs to determine the delay between an LTM device and the internal web server for a specific client.
Which two AVR reporting options should the LTM Specialist enable to measure the delay? (Choose two.)

  • A. Methods
  • B. Response codes
  • C. Client IP
    The problem is to specify the server delay of the client
  • D. User agents
  • E. Server latency

Answer: C,E


NEW QUESTION # 100
An LTM Specialist has recently taken over administration or an LTM device that has experienced resource availability issues. The LTM device will need to be solely used for load balancing and SSL offload. Previously, the LTM device was also used to provide statistical analysis of application traffic. However, that functionality has been moved to a third party solution.
Based on the output below, which configuration change should be made to ensure the LTM module receives the most amount of resources?

  • A. Provision LTM to Dedicated, Provision AVR to Dedicated
  • B. Provision AVR to Minimum, Provision LTM to Dedicated
  • C. Provision AVR to none. Provision LTM to Dedicated
  • D. Provision AVR to Minimum. Provision LTM at Maximum

Answer: C


NEW QUESTION # 101
Refer to the exhibit.

An LTM Specialist has multiple SNAT and virtual server objects configured as in the bigip.conf shown.
The LTM Specialist tests a connection from a client with. IP 172.163.31.11 to 192.168.0.100:80.
Which two objects will show an increase in Local Traffic statistics connections?

  • A. VS_A & SNAT A
  • B. VS_A&SNAT_B
  • C. VS_B&SNAT_B
  • D. VS_ B & SNAT A

Answer: B


NEW QUESTION # 102
A new HITP server has been deployed on an LTM device. The application running on the server must be monitored by the LIM device. The following is required:
A new HITP server has been deployed on an LTM device. The application running on the server must be monitored by the LIM device. The following is required:
When the server is unavailable, it will send an HTTP status code of 200 in response to a request for the status html page.
When the server is available. I will send and HTTP status code of 201 in response to a request for the status html page.
When the 200 status code is received, the pool member should receive No new connections.
Which configuration change should be made to meet these requirements?

  • A. set the Send String to GET/ status html and the Receive String to 200 and Receive Disable String to 201.
  • B. set the Send String to Get /status html and the Receive Disable String to 200 and Receive String to 201.
  • C. set the Send String to GET Arian and the Receive Disable String to 200 and Receive String to 201.
  • D. set the Send String to GET Arian and the Receive String to 200 and Receive Disable String to 201.

Answer: B


NEW QUESTION # 103
An LTM Specialist needs to deploy a virtual server that will load balance traffic targeting https://register.example.com to a set of three web servers. Persistence needs to be ensured. No persistence mirroring is allowed SSL offloading is required.
A fourth web server with fewer resources will be used to handle requests from engine bots to https://register.example.comvrobots.txt by an iRule. The (Rule will use the HTTP_REQUEST event. .
What are the required profile and persistence settings to implement this

  • A. tcp, clientssl, http. cookie persistence
  • B. tcp. dientssl, hup, source address persistence
  • C. tcp, clientssl, http, serverssl cookie persistence
  • D. tcp, clientssl, serverssl, ssl persistence

Answer: A

Explanation:
The option is wrong, it should be clientssl and serverssl. If the title requires ssl offload instead of encryption, you need clientssl instead of serverssl. irule needs HTTP profile to enable HTTP_REQUEST. If the session cannot be mirrored, the cookie session remains to meet the demand.


NEW QUESTION # 104
An LTM Specialist needs to configure a virtual server with the requirements displayed below.
Application is currently an internal HTTP application
Encrypted external user access
Links are hard for siteA example.com and need to rewritten to siteB.Example.com Which profiles must the LTM Specialist use to provide the proper functionality?

  • A. Serverless, Stream
  • B. Serverless, fastL4, Stream
  • C. Clientssl, fastL4, Stream
  • D. Clientssll, Stream

Answer: D

Explanation:
For http application and external encryption, clientssl is required, and if the message content needs to be modified, the steam profile is required. FastL4 profile cannot coexist with clientssl and stream.


NEW QUESTION # 105
set payload {CACHE :: payload}
}
Which two profiles should be used on the virtual server? (Choose two.)

  • A. http-transparent
  • B. http compression
  • C. webacceleration
  • D. http
  • E. stream

Answer: C,D


NEW QUESTION # 106
An LTM Specialist is configuring a new virtual server on an LTM device and assigning a SNAT pool that is already is use another virtual server. Both virtual servers use the same pool members to load balance traffic. A maximum of 35,000 users needs to be able to access each virtual server ta any time. The network architecture does NOT allow the backend servers to use the LTM device as a default gateway.
What is the minimum number of SNAT addresses required in the SNAT pool to meet the needs of the virtual servers?

  • A. 0
  • B. 1
  • C. 2
  • D. 3

Answer: B

Explanation:
Both vs share the same snat pool, and both use the same pool member. Then the concurrent number of snatpool will be added. For each VS, there is a maximum of 35,000 users, and those two VSs have a maximum of 70,000 users. The stem did not mention how many connections each user would have concurrently. Calculated with a minimum of 1 connection, then 70,000 connections would be concurrent. One IP can support 65,535 connection. Therefore, at least 2 or more snaptips are required


NEW QUESTION # 107
An LTM device configured with a management IP address and route and a series of self-IPs and TMM routes. Both management and TMM have a routing entry for 101 10/24 Application traffic is being load balanced and sent to pool member 10.1.1.123 with SNAT Automap and configured.
Which route will the LTM device use?

  • A. both routes, which will duplicate traffic on both management and TMM interface
  • B. equal cost multipath load balancing via both routes
  • C. TMM route regardless of the management port status
  • D. management route regardless of the management port status
  • E. management route when TMM interface is down or TMM is offline

Answer: C


NEW QUESTION # 108
An application is sensitive to packet loss and unexpected session termination. A pair of LTM devices is configured in an Active/Standby high availability configuration. SNATS are NOT used and the virtual server contains a Universal Persistence profile.
which two actions must an LTM Specialist take to ensure the sessions are maintained between the client and server during an LTM device failover event while maintaining maximum uptime? (Choose two.)

  • A. configure a serial failover cable for mirror traffic
  • B. enable Clone Pools for a virtual server and a persistence profile
  • C. configure a VLAN and primary mirroring address for mirror traffic
  • D. enable Mirroring for a virtual server and persistence profile
  • E. configure a OneConnect profile to mirror connections

Answer: C,D


NEW QUESTION # 109
An LTM Specialist needs to use the tmsh command to create a pool named http_pool with member
10.10.101:80 on an LTM device.
Which expression should the LTM Specialist use?

  • A. # tmsh create it pool http_pool members {10.10.10.101:80}
  • B. # tmsh create itm pool http_pool member {10.10.10.101:80}
  • C. # tmsh create pool http_pool members add {10.10.10.101:80}
  • D. # tmsh create pool http_pool members {10.10.10.101:80}

Answer: A

Explanation:
The option should be wrong, it should ne itm instead of it, the correct command is:tmsh create itm pool http_pool members add (10.10.10.101:80}


NEW QUESTION # 110
Traffic to a pool of SFTP servers that share storage must be balanced by an LTM device.
What are the required profile and persistence settings for a standard virtual server?

  • A. tcp - no persistence profile will be used
  • B. tcp, ctientsst, ftp serverssl persistence
  • C. tcp, clientssl, serverssl persistence
  • D. tcp, ftp - Source address persistence

Answer: D


NEW QUESTION # 111
......


To qualify for the F5 301a certification exam, candidates must have a minimum of two years of experience in network administration and have completed F5's BIG-IP LTM Essentials course. Additionally, candidates should have a solid understanding of networking concepts, protocols, and technologies, as well as a familiarity with Linux operating systems and scripting languages.

 

301a dumps Sure Practice with 150 Questions: https://www.trainingquiz.com/301a-practice-quiz.html

Get New 301a Certification – Valid Exam Dumps Questions: https://drive.google.com/open?id=1xgmUnO_bFTbTedRYBCim5I-qpl1kxAAR