Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free F5 Networks BIG-IP Administration Install, Initial Configuration, and Upgrade F5CAB1 Exam Questions

Page: 1 / 9 Total 49 questions

Want more questions? Get Premium Access.

Question 1

What are the two options for securing a BIG-IP's management interface?

(Choose two.)

Correct Answer: A. Limiting network access through the management interface to a trusted/secured network VLAN.; D. Restrict administrative HTTPS and SSH access to specific IP addresses or IP ranges.
Explanation:

Securing the BIG-IP management interface is a fundamental administrative responsibility. F5 best practices emphasize restricting who can reach the management port and ensuring that only authorized systems are allowed access.

A . Limiting management access to trusted network segments

F5 recommends placing the management interface on a dedicated, isolated, and secured management network or VLAN, rather than exposing it to production or untrusted networks.

This reduces the attack surface by ensuring only trusted segments have visibility to administrative interfaces.

D . Restricting management access by IP or subnet

F5 BIG-IP uses the /sys httpd allow list (for HTTPS) and configuration options in sshd (for SSH) to control which IP addresses or subnets can access the device.

By specifying only known administrative IPs or ranges, unauthorized users cannot reach the login services.

Why the other options are incorrect

B . Blocking all management HTTPS/SSH ports

This would prevent any administrative access and is not a viable security practice.

C . Using Self-IP addresses for administrative access

F5 explicitly warns against using Self-IPs for management access unless strictly necessary.

Self-IPs are exposed to the data plane and should not be used as the primary administrative interface.


Question 2

When logged into the bash shell of a BIG-IP system, which of the following commands will display the management-ip address?

(Choose two.)

Correct Answer: A. tmsh list /sys management-ip; C. ifconfig mgmt
Explanation:

When logged into the bash shell of a BIG-IP system, there are two valid ways to view the management-ip address:

A . tmsh list /sys management-ip

Even from the bash shell, the administrator can enter a tmsh command by typing:

tmsh list /sys management-ip

This displays:

Management IP address

Netmask

Any configured management routes

This is the official tmsh method for viewing the management-ip configuration.

C . ifconfig mgmt

In the underlying Linux OS, the management interface maps to the mgmt interface.

Running:

ifconfig mgmt

displays:

Assigned management IP

Netmask

Link-level status

This is a valid Linux-level method used frequently for troubleshooting.

Why the other options are incorrect:

B . show mgmt ip

Not a valid bash or tmsh command on BIG-IP.

D . list / sys management-ip

Missing the tmsh prefix.

In bash, this will generate a syntax error.

The correct form requires:

tmsh list /sys management-ip


Question 3

An F5 VE has been deployed into a VMware environment via an OVF file.

An administrator wants to configure the management IP address so the VE can be accessed for further setup.

Which two are valid methods for configuring the management-ip address? (Choose two.)

Correct Answer: A. Log into the remote console and configure the management IP by running the config executable.; B. Log into the remote console and configure the management IP through TMSH using: create sys management-ip <ip address>/<mask>
Explanation:

A newly deployed BIG-IP Virtual Edition (VE) in VMware requires initial configuration of its management-ip address so it can be accessed over the network. F5 provides several valid mechanisms during initial console access:

A . Running the config utility

The config script is available on new BIG-IP installations and VE deployments.

It launches a guided text-based wizard allowing configuration of:

Management IP

Netmask

Default route

This is a standard and recommended method during first-time setup.

B . Using TMSH with create sys management-ip

Administrators can enter TMSH directly from the console and run:

create sys management-ip <ip>/<mask>

The management-ip object resides under sys, not under ltm or any other module.

This is the correct tmsh method for defining the management interface address.

Why the other options are incorrect:

C . create ltm management-ip

There is no such object under /ltm.

LTM handles traffic objects (virtual servers, pools), not system management interfaces.

D . Running the setup command

The setup command is used for general system configuration but does not configure the management-ip.

It is not the supported method for initial management IP assignment on VE deployments.

Therefore, the valid methods are running the config utility and using the sys management-ip command within TMSH.


Question 4

Which of the following are resource allocation settings for modules? (Pick the 2 correct responses below)

Correct Answer: B. Nominal; D. Dedicated
Explanation:

Comprehensive and Detailed Explanation From BIG-IP Administration --- Install, Initial Configuration, and Upgrade:

When provisioning modules on a BIG-IP system, F5 provides specific resource allocation settings that define how system resources --- CPU, memory, and disk --- are distributed to each licensed module. The two valid and officially recognised allocation settings are Nominal and Dedicated.

Nominal instructs the system to allocate a moderate, balanced share of resources to the module. It allows the module to function effectively while sharing system resources with other provisioned modules. This is the most commonly used setting in multi-module deployments.

Dedicated allocates the maximum available system resources exclusively to a single module. When this setting is applied, it is typically the only module provisioned, as it consumes resources at a level that prevents other modules from operating concurrently in a meaningful capacity.

Option A --- Maximum is not a valid BIG-IP provisioning allocation level; it does not appear in the official provisioning interface or documentation as a selectable resource tier.

Option C --- Limited similarly does not exist as a defined resource allocation setting within BIG-IP module provisioning. It may superficially resemble valid terminology but has no standing in the official provisioning framework.

Administrators access these settings via System Resource Provisioning in the Configuration Utility, where each licensed module displays its available allocation options.

Reference Topics: Module Resource Provisioning, Nominal vs. Dedicated Allocation, System Resource Management --- BIG-IP Administration Study Guide.


Question 5

modification]

For an upgrade of a standalone BIG-IP, a maintenance window is available in which brief interruptions are allowed.

Actions with no impact can be done outside the maintenance window.

When should a license reactivation be performed?

Correct Answer: B. Before the maintenance window.
Explanation:

License reactivation updates the BIG-IP device's license file to ensure:

The Service Check Date is current

The device is eligible to install the intended TMOS version

Any module entitlement updates are received

Reactivation does not interrupt traffic and does not require a reboot, making it safe to perform before the maintenance window.

F5 best practices state:

Perform all non-impact tasks prior to the scheduled maintenance window

Leave the window available for activities that require rebooting, such as the software installation itself

Since license reactivation is non-disruptive, it should be done before the upgrade window starts.


Question 6

A secondary administrator has been granted access to a BIG-IP device through its Management Interface, but is unable to access the Configuration Utility (WebUI).

What command can be run from the CLI to capture the network traffic on the management interface and troubleshoot the issue?

(Choose two.)

Correct Answer: A. tcpdump -i eth0 -n port 443; B. tcpdump -i mgmt -n port 443
Explanation:

The BIG-IP has two distinct planes:

Management-plane handled entirely by the management interface (MGMT)

Data-plane (TMM) handles Self IPs, VLAN interfaces, and traffic processing

To capture traffic on the management interface, only the management-side NICs may be used:

mgmt Logical name for the management interface

eth0 Physical Linux interface mapped to the management port on most BIG-IP platforms

Both of these correctly capture inbound/outbound WebUI (HTTPS/443) traffic on the management port.

Why the correct answers are A and B

A . tcpdump -i eth0 -n port 443

On BIG-IP appliances and VMs, the management port maps to eth0 at the Linux OS level.

Capturing on eth0 correctly shows HTTPS traffic to the WebUI.

B . tcpdump -i mgmt -n port 443

mgmt is the BIG-IP alias for the management interface.

This is the preferred and most explicit capture interface for management-plane packet captures.

Why the other options are incorrect:

C . tcpdump -i 0.0

Interface 0.0 is the TMM switch interface used for data-plane packet captures.

It does NOT capture management-plane traffic.

D . tcpdump -i tun0

Used for tunnel interfaces (IPsec, VXLAN, etc.)

Not related to management access.

E . tcpdump -i management

There is no interface named management on BIG-IP.

The correct names are mgmt or eth0.