201 Sample Questions & Answers
Diagnosing basic virtual-server connectivity problems carries the top weight, alongside hardware and performance troubleshooting, device-management connectivity, opening F5 support tickets, reading device status, and overseeing virtual servers plus pools.
Launch the full 201 simulator →Free 201 Sample Questions with Answers
Real questions from the Tmos Administration practice test — answers and explanations included. Showing 10 of 20 free samples.
- Question 1Beginner
Identify and report current device status · Review the Network Map in order to determine the status of objects
An administrator is viewing the Network Map in the BIG-IP Configuration Utility and notices that a pool member is displayed as a blue square. What does this status icon indicate?
Show answer & explanation
Correct answer: D
In the BIG-IP Network Map, different shapes and colors represent the status of objects. A blue square specifically indicates that the object (in this case, a pool member) is available but its health status is unknown because there is no health monitor assigned to it. The system cannot verify its ability to service requests.
- Question 2Intermediate
Maintain system configuration · Given an HA pair, describe the appropriate strategy for deploying a new software image
An administrator needs to perform a software upgrade on a high-availability (HA) pair of BIG-IP devices with minimal downtime. Which of the following represents the correct, F5-recommended strategy for this operation?
Show answer & explanation
Correct answer: C
The standard, best-practice procedure for upgrading an HA pair is to perform the operation on the standby unit first. This allows the active unit to continue handling traffic. Once the standby unit is successfully upgraded and rebooted into the new software version, the administrator can force a failover. The newly upgraded unit becomes active, and the process is repeated on the other unit, which is now the standby. This ensures traffic is always being handled by one of the units.
- Question 3Intermediate
Manage existing system and application services · Distinguish between disabling a member and forcing it down
During a maintenance window, an administrator needs to gracefully remove a pool member from service to perform updates on the backend server. The goal is to prevent any new connections from being sent to this member, while allowing existing, persisted connections to complete. Which action should the administrator take on the pool member?
Show answer & explanation
Correct answer: B
Setting a pool member's state to 'Disabled' is the correct action for graceful removal. This state allows existing connections, including those maintained by persistence, to continue until they are closed or time out. However, it prevents the BIG-IP from sending any new connections to that member. 'Forced Offline', in contrast, marks the member as down and immediately stops it from receiving any traffic, which could disrupt existing user sessions.
- Question 4Advanced
Troubleshoot basic virtual server connectivity issues · Identify a persistence issue
A virtual server is configured with a pool that uses the 'Least Connections (member)' load balancing method. An administrator observes that one pool member, despite being healthy and having a high connection limit, is receiving significantly less traffic than the others. Which of the following is the most likely reason for this behavior?
Show answer & explanation
Correct answer: B
The BIG-IP system checks for a persistence record before making a load balancing decision. If a client has an existing persistence record for a specific pool member, the system will send the new connection to that member, regardless of the 'Least Connections' algorithm. If most returning clients are persisted to other members, a new or underutilized member will receive very little traffic.
- Question 5Beginner
Maintain system configuration · Explain how to modify user properties
An administrator is creating a new user account that should only be allowed to view statistics and object statuses, but not make any configuration changes. Which user role should be assigned to this account?
Show answer & explanation
Correct answer: C
The 'Guest' role in TMOS is specifically designed for read-only access. Users with this role can log in to the Configuration Utility and view configurations, statistics, and statuses, but they are prohibited from making any changes. This is the principle of least privilege in action for monitoring purposes.
- Question 6IntermediateSelect 2
Troubleshoot basic virtual server connectivity issues · Identify the reason a pool member has been marked down by health monitors
A BIG-IP administrator is reviewing the
/var/log/ltmfile and sees repeated log entries indicating that a pool member is alternating between 'up' and 'down' states every few seconds. This is causing service instability. Which TWO of the following are the most likely causes of this 'flapping' behavior? (Select TWO).Show answer & explanation
Correct answers: A, D
If the monitor timeout is shorter than the server's typical response time, the monitor will frequently fail, marking the member down. When the server does respond within the interval, it will be marked up again, leading to a flapping state.
Health monitor probes are network packets. If there is intermittent packet loss or high latency on the path between the BIG-IP and the server, some monitor probes will fail while others succeed, causing the member's status to flap between up and down.
- Question 7Beginner
Maintain system configuration · Identify which modules are licensed and/or provisioned
A new module, Application Security Manager (ASM), needs to be enabled on a licensed BIG-IP system. The administrator has verified that the license includes ASM. What is the next step to make the module's features available for configuration?
Show answer & explanation
Correct answer: B
On a BIG-IP system, being licensed for a module is not enough to use it. An administrator must also provision system resources (CPU, memory) to it. This is done in the System > Resource Provisioning section of the Configuration Utility. After provisioning, the relevant daemons are started and the configuration options appear in the GUI.
- Question 8Intermediate
Maintain system configuration · Create and restore a UCS archive under the appropriate circumstances
True or False: A User Configuration Set (UCS) archive contains all TMOS configuration files, the product license, and SSL private keys.
Show answer & explanation
Correct answer: A
A UCS archive is a comprehensive backup of a BIG-IP system's critical data. By default, it includes all configuration files (like bigip.conf), the system license file, and all locally stored SSL certificates and private keys. This makes it a complete, self-contained backup for system restoration.
- Question 9Advanced
Manage existing system and application services · Modify and manage virtual servers
Case Study:
A financial services company, FinCorp, is deploying a new online banking portal. The portal must be highly available and secure. The BIG-IP infrastructure team has been tasked with configuring the application delivery services. The BIG-IP is currently an active/standby pair.
Current Situation:
The backend application servers are running on a private network (10.10.20.0/24). The BIG-IP has a self-IP (10.10.10.5) on a transit VLAN that can route to the servers. The servers do not have a default gateway pointing back to the BIG-IP. All traffic from the BIG-IP to the servers must appear to originate from a single, consistent IP address on the 10.10.10.0/24 network for firewall rule simplicity.Requirements:
- A new virtual server must be created at
172.16.100.50:443. - Client-side traffic must be encrypted using HTTPS. The BIG-IP must terminate the SSL.
- Server-side traffic must be unencrypted HTTP on port 8080.
- All traffic sent from the BIG-IP to the backend servers must originate from the BIG-IP's self-IP
10.10.10.5. - A health monitor must be applied to check the servers on port 8080.
Which configuration best meets all of FinCorp's requirements?
Show answer & explanation
Correct answer: D
This configuration meets all requirements. 1) The Standard VS listens on 172.16.100.50:443. 2) The Client SSL profile terminates the client-side HTTPS. 3) The HTTP profile allows L7 inspection, and the pool members are set to port 8080. 4) SNAT Automap is crucial because the servers lack a return route; it forces all server-side traffic to originate from the egress self-IP (10.10.10.5). 5) The HTTP monitor correctly checks the application on port 8080.
- A new virtual server must be created at
- Question 10Advanced
Troubleshoot basic virtual server connectivity issues · Given a specific connectivity issue, isolate where the problem might be according to the processing order
A BIG-IP administrator is analyzing a packet capture to troubleshoot a connectivity issue. The capture shows that the client sends a TCP SYN packet to the virtual server, the BIG-IP sends a TCP SYN to the backend server, and the server responds with a TCP SYN-ACK. However, the BIG-IP never forwards the SYN-ACK back to the client. What is the most likely cause of this issue?
Show answer & explanation
Correct answer: D
This is a classic asymmetric routing problem. If SNAT is not used, the server sees the client's real IP and tries to respond directly to it. The server's SYN-ACK goes out its default gateway, bypassing the BIG-IP. The BIG-IP, having never received the SYN-ACK it was expecting from the server, cannot complete the three-way handshake with the client. The solution is typically to enable SNAT on the virtual server.
Ready for the real thing?
The full 201 simulator has every exam-style question, timed mode, and instant scoring.