Cyber Monday Sale Special - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: xmaspas7

Easiest Solution 2 Pass Your Certification Exams

F5CAB1 F5 BIG-IP Administration Install, Initial Configuration, and Upgrade Free Practice Exam Questions (2025 Updated)

Prepare effectively for your F5 F5CAB1 BIG-IP Administration Install, Initial Configuration, and Upgrade certification with our extensive collection of free, high-quality practice questions. Each question is designed to mirror the actual exam format and objectives, complete with comprehensive answers and detailed explanations. Our materials are regularly updated for 2025, ensuring you have the most current resources to build confidence and succeed on your first attempt.

Page: 1 / 1
Total 42 questions

When logged into thebash shellof a BIG-IP system, which of the following commands will display themanagement-ip address?

(Choose two.)

A.

tmsh list /sys management-ip

B.

show mgmt ip

C.

ifconfig mgmt

D.

list / sys management-ip

For security reasons, a BIG-IP Administrator needs to specify allowable IP ranges for access to the Configuration Utility (WebUI).

The exhibit shows the User Administration section of the Configuration Utility.

The administrator could not find any setting that explicitly restricts access to the Configuration Utility.

Which one of the following is a reason for that?

A.

Restricting access to the Configuration Utility can only be done from the Command Line Interface

B.

The administrator must restrict access by IP address for SSH, which will implicitly restrict access to the Configuration Utility

C.

To avoid locking out the administrator, recent versions of BIG-IP no longer allow restricting administrator access to the Configuration Utility by source IP address

D.

The administrator needs to switch to the “Advanced” view mode in order to display the relevant setting

A secondary administrator has been granted access to a BIG-IP device through itsManagement Interface, but is unable to access theConfiguration Utility (WebUI).

What command can be run from the CLI to capture the network traffic on themanagement interfaceand troubleshoot the issue?

(Choose two.)

A.

tcpdump -i eth0 -n port 443

B.

tcpdump -i mgmt -n port 443

C.

tcpdump -i 0.0 -n port 443

D.

tcpdump -i tun0 -n port 443

E.

tcpdump -i management -n port 443

An F5 BIG-IP Administrator is asked to report which modules areprovisionedon the BIG-IP.

In which two ways can this be done?

(Choose two.)

A.

Via the GUI atSystem → Resource Provisioning → Module Allocation

B.

Via TMSH withshow /sys provision

C.

Via the GUI atStatistics → Module Statistics → System

D.

Via TMSH withlist /sys provision

Which port is an exception to the Port Lockdown function of Self-IPs if a device-group synchronization cluster is configured?

A.

TCP 443

B.

TCP 4353

C.

UDP 53

A BIG-IP Administrator discovers malicious brute-force attempts to access the BIG-IP device on themanagement interfacevia SSH.

The administrator needs to restrict SSH access to the management interface.

Where should this be accomplished?

A.

Network > Interfaces

B.

Network > Self IPs

C.

System > Configuration

D.

System > Platform

A BIG-IP device is licensed forLTM, ASM, APM, and AFM.

Currently, it will only be used forload balancingandweb application firewalling.

To ensure optimal performance and efficient resource utilization, which of the following module provisioning combinations is the best choice?

A.

LTM: Dedicated

ASM: Dedicated

APM: Minimal

AFM: Minimal

B.

LTM: Dedicated

ASM: Dedicated

APM: None

AFM: None

C.

LTM: Nominal

ASM: Nominal

APM: None

AFM: None

D.

LTM: Nominal

ASM: Nominal

APM: Minimal

AFM: Minimal

Which command will display thecurrent active volumeon a BIG-IP system?

A.

tmsh show sys version

B.

tmsh show sys software status

C.

tmsh list sys software update

The BIG-IP Administrator wants to manage the newly built F5 system through anin-band Self-IP.

The administrator has configured a VLAN and Self-IP and can ping the IP from their workstation, but cannot access the system viaSSHorHTTPS.

Whatport lockdownsettings should the BIG-IP Administrator use to allow management access on the Self-IP?

(Choose two.)

A.

The Self-IP port lockdown behavior could be adjusted toAllow Default

B.

The Self-IP port lockdown behavior could be adjusted toAllow All

C.

The Self-IP port lockdown behavior could be adjusted toAllow Mgmt

D.

The Self-IP port lockdown behavior could be adjusted toAllow Management

Which one of the following is aport and protocol combination allowedby theAllow Defaultsetting for Port Lockdown?

A.

TCP 80

B.

UDP 8443

C.

TCP 443

A BIG-IP Administrator needs to purchase new licenses for a BIG-IP appliance.

The administrator needs to know:

    Whether a module is licensed

    The memory requirement for that module

Where should the administrator view this information in theSystem menu?

A.

Configuration » OVSDB

B.

Software Management

C.

Configuration » Device

D.

Resource Provisioning

The BIG-IP Administrator needs to update access to the Configuration Utility to include the172.28.31.0/24and172.28.65.0/24networks.

From the TMOS Shell (tmsh), which command should the BIG-IP Administrator use to complete this task?

A.

modify /sys httpd allow add { 172.28.31.0/255.255.255.0 172.28.65.0/255.255.255.0 }

B.

modify /sys httpd allow add { 172.28.31.0 172.28.65.0 }

C.

modify /sys httpd permit add { 172.28.31.0/255.255.255.0 172.28.65.0/255.255.255.0 }

Page: 1 / 1
Total 42 questions
Copyright © 2014-2025 Solution2Pass. All Rights Reserved