Spring Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save70

Free and Premium F5 F5CAB4 Dumps Questions Answers

Page: 1 / 5
Total 67 questions

BIG-IP Administration Control Plane Administration (F5CAB4) exam Questions and Answers

Question 1

A BIG-IP Administrator needs to restore a UCS file to an F5 device using the Configuration Utility.

Which section of the Configuration Utility should the BIG-IP Administrator access to perform this task? (Choose one answer)

Options:

A.

System > Configuration

B.

System > Archives

C.

Local Traffic > Virtual Servers

D.

Local Traffic > Policies

Buy Now
Question 2

The BIG-IP Administrator runs the command:

netstat -an | grep 443

and sees the following output:

tcp 0 0 0.0.0.0:443 0.0.0.0:* LISTEN

What does this output indicate about the service on port 443? (Choose one answer)

Options:

A.

The service is actively listening only on the loopback interface.

B.

The service is actively listening on all interfaces for HTTPS traffic.

C.

The service indicates no connections to the LISTEN port.

D.

The service is in a standby state and unable to accept connections.

Question 3

Users are unable to reach an application. The BIG-IP Administrator checks the Configuration Utility and observes that the Virtual Server has a red diamond in front of the status.

What is causing this issue? (Choose one answer)

Options:

A.

The Virtual Server is receiving HTTPS traffic over an HTTP virtual

B.

All pool members are down

C.

All pool members have been disabled

D.

The Virtual Server is disabled

Question 4

A BIG-IP Administrator defines a device Self IP. The Self IP is NOT reachable from the network. What should the administrator verify first?

Options:

A.

The correct Trunk has been selected.

B.

The correct VLAN has been selected.

C.

Verify if auto last hop is disabled.

D.

The correct Interface has been selected.

Question 5

A BIG-IP Administrator is unable to connect to the management interface via HTTPS. What is a possible reason for this issue?

Options:

A.

The port lockdown setting is configured to Allow None.

B.

An incorrect management route is specified.

C.

The IP address of the device used to access the management interface is NOT included in the "P Allow" list in the Configuration Utility.

D.

The IP address of the device used to access the management interface is NOT included in the "httpd Allow" list in the CLI.

Question 6

A BIG-IP Administrator needs to update the list of configured NTP servers. In which area of the Configuration Utility should the BIG-IP Administrator perform this update?

Options:

A.

System > Configuration

B.

System > Services

C.

System > Preferences

D.

System > Platform

Question 7

The BIG-IP Administrator has modified an iRule on one device of an HA pair. The BIG-IP Administrator notices there is NO traffic on the BIG-IP device in which they are logged into. What should the BIG-IP Administrator do to verify if the iRule works correctly?

Options:

A.

Push configuration from this device to the group and start to monitor traffic on this device

B.

Pull configuration to this device to the cluster and start to monitor traffic on this device

C.

Log in to the other device in the cluster, push configuration from it, and start to monitor traffic on that device

D.

Log in to the other device in the cluster, pull configuration to it, and start to monitor traffic on that device

Question 8

A BIG-IP Administrator needs to fall over the active device. The administrator logs into the Configuration Utility and navigates to Device Management > Traffic Group. However, "Force to Standby" is greyed out. What is causing this issue?

Options:

A.

The BIG-IP Administrator is NOT logged into command line to tail over

B.

The BIG-IP Administrator is on the Standby Device

C.

The BIG-IP Administrator is logged in as root

D.

The BIG-IP Administrator is logged in as administrator

Question 9

A BIG-IP administrator is troubleshooting inconsistent configuration objects on devices in a device group. The administrator uses the command:

tmsh run /cm watch-devicegroup-device

and observes the following output:

devices device clu_id cl_orig cl_time last_sync

20:21 sync_test bigip_a 3273 bigip_a 14:27:00

20:21 sync_test bigip_b 1745 bigip_b 13:52:34 13:42:04

20:21 sync_test bigip_c 1745 bigip_a 13:52:34 13:42:04

What two conclusions can be made about this output? (Choose two answers)

Options:

A.

bigip_a has the latest configuration.

B.

Two of the devices in the device group have a configuration that is out of date.

C.

The config from bigip_c was synced to the other devices in the device group during the most recent ConfigSync.

D.

The correct configuration exists on bigip_b and bigip_c because their cluster times match.

E.

The correct configuration exists on bigip_a and bigip_c because their cluster times match.

Question 10

A BIG-IP Administrator is setting up a new BIG-IP device. The network administrator reports that the interface has an incompatible media speed. The BIG-IP Administrator needs to change this setting manually. From which location should the BIG-IP Administrator perform this task?14

Options:

A.

On the Front Console15

B.

In the TMOS Shell Command line16

C.

In the Configuration Utility, Network > Interface17

D.

In the Configuration Utility, System > Configuration18

Question 11

A BIG-IP Administrator runs the initial configuration wizard and learns that the NTP servers were invalid.

In which area of the Configuration Utility should the BIG-IP Administrator update the list of configured NTP servers? (Choose one answer)

Options:

A.

System > Platform

B.

System > Preferences

C.

System > Services

D.

System > Configuration

Question 12

As an organization grows, more people have to log into the BIG-IP. Instead of adding more local users, the BIG-IP Administrator is asked to configure remote authentication against a central authentication server.

Which two types of remote server can be used here? (Choose two answers)

Options:

A.

LDAP

B.

OAUTH

C.

RADIUS

D.

SAML

Question 13

The BIG-IP Administrator suspects unauthorized SSH login attempts on the BIG-IP system.

Which log file would contain details of these attempts? (Choose one answer)

Options:

A.

/var/log/messages

B.

/var/log/secure

C.

/var/log/audit

D.

/var/log/ltm

Question 14

Administrative user accounts have been defined on the remote LDAP server and are unable to log in to the BIG-IP device.

Which log file should the BIG-IP Administrator check to find the related messages? (Choose one answer)

Options:

A.

/var/log/user.log

B.

/var/log/ltm

C.

/var/log/messages

D.

/var/log/secure

Question 15

A BIG-IP Administrator needs to check the memory utilization on a BIG-IP system. Which two methods can the BIG-IP Administrator use? (Choose two.)

Options:

A.

Run the tmsh show /sys memory command

B.

Run the tmsh show /sys traffic command

C.

Go to Statistics > Module Statistics > Traffic Summary in the configuration utility

D.

Go to Statistics > Module Statistics > Memory in the configuration utility

Question 16

A BIG-IP Administrator needs to verify system time synchronization. Where should this be checked?

Options:

A.

System > Platform

B.

System > Configuration > Device

C.

System > Logs

D.

System > Software Management

Question 17

New Syslog servers have been deployed in an organization. The BIG-IP Administrator must reconfigure the BIG-IP system to send log messages to these servers.

In which location in the Configuration Utility can the BIG-IP Administrator make the needed configuration changes to accomplish this? (Choose one answer)

Options:

A.

System > Configuration > Local Traffic

B.

System > Logs > Configuration

C.

System > Logs > Audit

D.

System > Configuration > Device

Question 18

A local user account (Users) on the BIG-IP device is assigned the User Manager role. User1 attempts to modify the properties of another account (User2), but the action fails. The BIG-IP Administrator can successfully modify the User2 account. Assuming the principle of least privilege, what is the correct way to allow User1 to modify User2 properties?

Options:

A.

Move User2 to the same partition as User1

B.

Grant User administrator privileges

C.

Move User1 to the same partition as User2

D.

Modify the partition access for User1

Question 19

A BIG-IP Administrator discovers malicious brute-force attempts to access the BIG-IP device on the management interface via SSH. The BIG-IP Administrator needs to restrict SSH access to the management interface. Where should this be accomplished?

Options:

A.

System > Configuration

B.

Network > Interfaces

C.

Network > Self IPs

D.

System > Platform

Question 20

A BIG-IP Administrator receives an RMA replacement for a failed F5 device. The Administrator tries to restore a UCS taken from the previous device, but the restore fails. The following error appears in the /var/log/ltm:

insufficient pool members. 01070608:3: License is not operational

(expired, digital signature does not match contents)

What should the BIG-IP Administrator do to avoid this error? (Choose one answer)

Options:

A.

Remove the license information from the UCS archive

B.

Revoke the license prior to restoring

C.

Use the appropriate tmsh command with the no-license option

D.

Reactivate the license on the new device using the manual activation method

Page: 1 / 5
Total 67 questions