Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free F5 Networks BIG-IP Administration Control Plane Administration F5CAB4 Exam Questions

Page: 1 / 7 Total 67 questions

Want more questions? Get Premium Access.

Question 1

A BIG-IP Administrator needs to fall over the active device. The administrator logs into the Configuration Utility and navigates to Device Management > Traffic Group. However, "Force to Standby" is greyed out. What is causing this issue?

Correct Answer: B. The BIG-IP Administrator is on the Standby Device
Explanation:

In a High Availability pair, the 'Force to Standby' action is a Control Plane command used to trigger a manual failover. This option is only logical and available on the device that is currently in the Active state. If the button is greyed out, it indicates that the administrator is already logged into the Standby unit, which has no active traffic groups to relinquish.


Question 2

What is the tmsh command to list the IP ranges that can access the management interface via SSH? (Choose one answer)

Correct Answer: B. tmsh list /sys sshd allow
Explanation:

On BIG-IP systems, SSH access restrictions are configured under the /sys sshd object. The allow property defines the IP addresses or networks permitted to connect to the management interface using SSH.

The list command is used to display the current configuration settings.

Therefore, tmsh list /sys sshd allow correctly displays the configured allowed IP ranges.

Why the other options are incorrect:

A (show) displays runtime or statistical information, not configuration values.

C and D incorrectly reference /etc/hosts.allow; BIG-IP manages SSH access through TMSH objects, not by directly listing host files in this context.


Question 3

The BIG-IP appliance fails to boot. The BIG-IP Administrator needs to run the End User Diagnostics (EUD) utility to collect data to send to F5 Support. Where can the BIG-IP Administrator access this utility?

Correct Answer: A. Console Port
Explanation:

The EUD is a 33hardware-level diagnostic tool that runs outside of the TMOS operating system. Because it is used when the system cannot boot or is in a pre-boot state, it cannot be accessed via the GUI or management network. The administrator must connect physically via the serial Console Port to interact with the boot menu and initiate the hardware tests.


Question 4

What are the recommended methods for forcing a BIG-IP system to standby mode? (Choose two answers)

Correct Answer: A. Active BIG-IP: CLI > tmsh run /sys failover device standby; B. Active BIG-IP: Configuration Utility > Device Management > Devices > Local Device (Self) > Force to Standby
Explanation:

BIG-IP provides two supported and documented methods to manually force a device into standby state in a high-availability (HA) configuration:

CLI method (A):

tmsh run /sys failover device standby

This is the correct and supported TMSH command to force the local device to transition from active to standby.

Configuration Utility method (B):

Navigating to Device Management > Devices > Local Device (Self) and selecting Force to Standby performs the same operation through the GUI and is fully supported.

Why the other options are incorrect:

C is incorrect: Traffic Groups do not provide a ''Force to Standby'' option for the local device; traffic groups are used to manage which device owns specific traffic, not to force device-level failover.

D is incorrect: tmsh run /sys failover standby is not a valid TMSH command. The correct syntax requires device standby.

Thus, the correct answers are A and B.


Question 5

A BIG-IP Administrator needs to restore a UCS file to an F5 device using the Configuration Utility. Which section of the Configuration Utility should the BIG-IP Administrator access to perform this task?

Correct Answer: C. System > Archives
Explanation:

Managing the state of a device often involves restoring configuration backups known as User Configuration Set (UCS) files These archives contain the full system configuration, including licenses and SSL certificates. The Control Plane provides a dedicated management area for these files under System > Archives, where administrators can upload, create, and restore configuration snapshots


Question 6

A BIG-IP Administrator needs to restore an encrypted UCS archive from the command line using the TMSH utility. Which TMSH command should the BIG-IP Administrator use to accomplish this?

Correct Answer: D. load /sys ucs <filepath> passphrase
Explanation:

Restoring system states from backups is a fundamental Control Plane administrative task2. When a User Configuration Set (UCS) archive is created with encryption, it requires the correct passphrase to be decrypted and loaded during the restoration process.

UCS Command Structure: The tmsh load /sys ucs command is the specific utility for restoring these comprehensive configuration archives.

Encrypted Restores: If the archive was encrypted during creation, the passphrase argument must be appended to the command followed by the actual password used to encrypt the file.

Comparison with Other Options:

load /sys config file is used for loading text-based configuration files (like bigip.conf), not full UCS archives6.

The no-license flag is used when you want to restore a configuration without overwriting the existing license (common during RMA replacements), but it does not provide the mechanism for entering an encryption passphrase.


Question 7

A BIG-IP Administrator needs to find which modules have been licensed for use on the BIG-IP system. In which section of the Configuration Utility can the BIG-IP Administrator find this information?

Correct Answer: B. System > Resource Provisioning
Explanation:

Identifying the current device status includes knowing which software modules (such as LTM, ASM, or APM) are active and how much hardware resource (CPU/Memory) is allocated to them40404040. The System > Resource Provisioning screen displays the licensing status and allows the administrator to set the provisioning level (Nominal, Dedicated, or Minimum) for each module.


Question 8

The BIG-IP Administrator runs the command:

netstat -an | grep 443

and sees the following output:

tcp 0 0 0.0.0.0:443 0.0.0.0:* LISTEN

What does this output indicate about the service on port 443? (Choose one answer)

Correct Answer: B. The service is actively listening on all interfaces for HTTPS traffic.
Explanation:

In netstat output:

0.0.0.0:443 means the service is bound to all available IPv4 interfaces on the system.

LISTEN indicates the service is actively waiting for incoming connection requests.

Therefore, this output confirms that a service (commonly HTTPS/443, such as the BIG-IP Configuration Utility or an application listener) is actively listening on all interfaces, making B the correct answer.

Why the other options are incorrect:

A would show 127.0.0.1:443 if it were loopback-only.

C is incorrect because LISTEN explicitly indicates readiness to accept connections.

D is unrelated; standby state does not affect socket binding shown by netstat.

Hence, the correct answer is B.


Question 9

A BIG-IP Administrator reviews the Plane CPU Usage performance chart and discovers a high percentage of Control Plane utilization. Which type of traffic does this indicate a higher usage of?

Correct Answer: A. Administrative
Explanation:

F5 architecture distinguishes between the Data Plane (TMM processing application traffic) and the Control Plane (Linux host processing management tasks). High Control Plane CPU utilization typically points to administrative activities such as heavy GUI usage, complex API calls (iControl), large-scale configuration synchronizations, or intensive logging/monitoring tasks rather than the actual switching or load balancing of application data.


Question 10

A BIG-IP Administrator needs to view the CPU utilization of a particular Virtual Server. Which section of the Configuration Utility should the administrator use for this purpose?

Correct Answer: D. Statistics > Module Statistics > Local Traffic > Virtual Servers567
Explanation:

Comprehensive and Detailed Exp11lanation From BIG-IP Administration Control Plane Administration documents: Monitoring specific object health is a core function of the Control Plane. While the dashbo12ard provides a global overview, granular per13formance data---such as the CPU overhead a specific Virtual Server is placing on the Traffic Management Microkernel (TMM)---is found under the Module Statistics. Navigating to Statistics > Module Statistics > Local Traffic > Virtual Servers allows an administrator to report on the current status and resource consumption of individual traffic objects.