Free F5CAB1: BIG-IP Administration Install, Initial Configuration, and Upgrade Exam Questions and Answers
27 verified practice questions for F5CAB1.
The first 10 questions on this page are free to read, answers included — no account and no card. A plan opens the rest of the bank, the full timed practice test and your weak-topic reporting.
Last updated: September 19, 2026
- Provider
- F5
- Questions in our bank
- 1000+
- Free to read
- First 10, with answers
- Our test mode duration & pass mark
- 130 mins · 70%
- Verified answers
- Reviewed weekly
- Practice format
- Multiple choice
Recommended: Switch to Test Mode to start a practice test that simulates the real exam experience.
Question #1
A secondary administrator has been granted access to a BIG-IP device through its Management Interface, but is unable to access the Configuration Utility (WebUI). What command can be run from the CLI to capture the network traffic on the management interface and troubleshoot the issue? (Choose two.)
Select 2 answers.
Please select an optionIncorrectCorrect answer: A, B
The management port is the Linux eth0 interface, aliased as mgmt on BIG-IP, so tcpdump -i eth0 or tcpdump -i mgmt captures HTTPS traffic to the Configuration Utility. Interface 0.0 is the TMM data-plane capture interface and tun0 is a tunnel interface.
Was this answer correct?Question #2
An organization is planning to upgrade a BIG-IP system from 16.1.x to 17.1.x. For a successful upgrade, the Service Check Date must be equal to or newer than the License Check Date required for 17.1.x. Which command will show the Service Check Date on the BIG-IP system being upgraded?
Please select an optionIncorrectCorrect answer: A
License attributes, including the Service check date, are stored in /config/bigip.license, so grep against that file shows the date. bigip.conf holds configuration objects and BigDB.dat holds database variables; svc_chk_date.dat does not exist.
Was this answer correct?Question #3
The BIG-IP Administrator needs to update access to the Configuration Utility to include the 172.28.31.0/24 and 172.28.65.0/24 networks. From the TMOS Shell (tmsh), which command should the BIG-IP Administrator use to complete this task?
Please select an optionIncorrectCorrect answer: A
Configuration Utility access is controlled by the /sys httpd allow list, and tmsh expects network/netmask entries. modify /sys httpd allow add appends both subnets without removing existing entries; 'permit' is not a valid attribute and bare network addresses lack masks.
Was this answer correct?Question #4
The Port Lockdown feature prevents unwanted connection attempts to a Self IP. Which three types of connection attempts are unaffected by Port Lockdown settings?
Please select an optionIncorrectCorrect answer: C
Port Lockdown only governs traffic destined to the self IP itself. Traffic matching a configured virtual server, ICMP, and CMI (TCP 4353 device trust/ConfigSync) traffic are not blocked by the setting, whereas SSH is restricted unless explicitly allowed.
Was this answer correct?Question #5
How can the BIG-IP Administrator tell when an unlicensed module has been provisioned?
Please select an optionIncorrectCorrect answer: C
The system allows the module to be provisioned but then displays a Provisioning Warning banner in the upper left corner of the Configuration Utility until the module is deprovisioned or the license is updated.
Was this answer correct?Question #6
A BIG-IP device is licensed for LTM, ASM, APM, and AFM. Currently, it will only be used for load balancing and web application firewalling. To ensure optimal performance and efficient resource utilization, which of the following module provisioning combinations is the best choice?
Please select an optionIncorrectCorrect answer: C
Only LTM and ASM are needed, so provision both at Nominal and set APM and AFM to None so they consume no resources. Dedicated allocates all resources to a single module, so two modules cannot both be Dedicated; Minimal still consumes resources for unused modules.
Was this answer correct?Question #7
The device is currently on v15.1.2.1. The BIG-IP Administrator needs to boot the device back to v13.1.0.6to gather data for troubleshooting. The system shows: Sys::Software Status Volume Product Version Build Active Status Allowed HD1.1 BIG-IP 15.1.2.1 0.0.10 yes complete yes HD1.2 BIG-IP 13.1.0.6 0.0.3 no complete yes Which is the correct command-line sequence to boot the device to version 13.1.0.6?
Please select an optionIncorrectCorrect answer: B
switchboot -b <volume> marks a boot location as the one to use on the next reboot, so switchboot -b HD1.2 followed by reboot boots into 13.1.0.6. switchboot is a shell utility, not a tmsh command, and -I is not a valid flag.
Was this answer correct?Question #8
A BIG-IP Administrator needs to purchase new licenses for a BIG-IP appliance. The administrator needs to know: Whether a module is licensed The memory requirement for that module Where should the administrator view this information in the System menu?
Please select an optionIncorrectCorrect answer: D
System > Resource Provisioning lists every module in the license, whether it is licensed, its provisioning level, and the memory, CPU and disk required to provision it. OVSDB, Software Management and Device settings do not show module licensing or resource requirements.
Was this answer correct?Question #9
A BIG-IP Administrator is responsible for deploying a new software image on an F5 BIG-IP HA pair and has scheduled a one-hour maintenance window. With a focus on minimizing service disruption, which of the following strategies is the most appropriate?
Please select an optionIncorrectCorrect answer: C
F5's recommended HA upgrade is to install the image on the standby unit, reboot it into the new volume, fail over to it and verify, then repeat on the former active unit, which is now standby. Only one unit is ever out of service, minimizing disruption.
Was this answer correct?Question #10
What will setting a Self IP to "Allow None" for Port Lockdown do?
Please select an optionIncorrectCorrect answer: A
Allow None blocks all traffic to the self IP except CMI (TCP 4353) when it is the config sync address, so network failover (UDP 1026) and mirroring traffic between peers is dropped. Each device then sees its peer as offline and both go active.
Was this answer correct?
Continue with F5CAB1: BIG-IP Administration Install, Initial Configuration, and Upgrade
Unlock the full question bank
You have read the first 10 questions. A subscription opens every question in F5CAB1: BIG-IP Administration Install, Initial Configuration, and Upgrade, the full timed practice test, and your progress and weak-topic reporting.
Single exam
$19.99for 30 days
Full question bank and practice test for one exam, for 30 days.
Single exam
$49.99for 1 year
One exam for a full year. Nothing renews and nothing to cancel.
Full access
$39.99/mo
Every exam in the catalogue, month to month.
Full access
$199.99/yr
Every exam in the catalogue for a year.
Already subscribed? Sign in to pick up where you left off.
Other F5 certifications
Reviews
★★★★★
This platform is a lifesaver. The practice questions and explanations are so detailed. It’s the best study tool I’ve ever used.
Hannah Smith
USA
★★★★★
I highly recommend Exam Practice. The feedback after each test helped me improve significantly, and I passed my exams easily.
Oscar Nyström
Sweden
★★★★★
Exam Practice is worth every penny. The mock exams are realistic, and the feedback helped me focus on key areas.
Amit Sharma
India
FAQ
Learn More: https://www.f5.com/learn/certification
- Q1: What are F5 Certification Exams?
- A: F5 Certification Exams validate your expertise in managing and optimizing F5’s application delivery and security solutions, including BIG-IP, BIG-IQ, and other F5 technologies. These certifications demonstrate your proficiency in deploying, configuring, and troubleshooting F5 products to ensure secure and high-performing applications.
- Q2: Why should I pursue F5 Certification?
- A: F5 Certification enhances your professional credibility, showcasing your skills and knowledge in application delivery and security. This can lead to better job opportunities, higher salaries, and career advancement in network administration, security, and IT infrastructure roles.
- Q3: What are the benefits of F5 Certification?
- A: Benefits include recognition as a certified F5 professional, improved job performance, access to exclusive resources, continuing education opportunities, and staying current with the latest F5 technologies and best practices.
- Q4: Who should take F5 Certification Exams?
- A: Network engineers, system administrators, security professionals, and anyone involved in managing and securing application delivery using F5 products should consider these certifications to validate their expertise and advance their careers.
- Q5: What types of F5 Certification Exams are available?
- A: F5 offers various certification paths, including:
- Q6: How do I prepare for F5 Certification Exams?
- A: Preparation can include official F5 training courses, study guides, practice exams, online tutorials, and hands-on experience with F5 products and solutions.
- Q7: Where can I take F5 Certification Exams?
- A: F5 Certification Exams can be taken at authorized Pearson VUE testing centers worldwide or online, providing flexibility to fit your schedule and location.
- Q8: How do F5 Certifications impact my career?
- A: F5 Certifications significantly boost your career by demonstrating your expertise to employers, making you a more competitive candidate for advanced roles and promotions in network administration, security, and IT infrastructure.
- Q9: Are there any prerequisites for F5 Certification Exams?
- A: Some exams may have prerequisites, such as foundational knowledge or prior experience with F5 products. Check the specific requirements for each certification path on the F5 Certification website.
- Q10: How often do I need to recertify for F5 Certifications?
- A: F5 Certifications typically require recertification every two years to ensure that certified professionals stay updated with the latest F5 technologies and industry practices.



