Courseiva

F5CAB1 Install, Initial Configuration, and Upgrade Practice Question

After a fresh installation of BIG-IP, which task is considered a 'Day 0' security hardening requirement?

⚠ Common exam trap

Candidates often assume that applying software updates or configuring high availability pools constitutes a Day 0 security requirement, overlooking basic credential management for root and admin accounts.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Change default administrative passwords.

Changing default passwords for the root and admin accounts is the most fundamental security step. F5 appliances come with well-known default credentials; leaving these unchanged allows anyone with network access to gain administrative control. This is the first action an administrator should take to secure the management plane and prevent unauthorized access before any other network configuration or traffic management policies are implemented.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure an NTP server.

    Why it's wrong here

    While NTP is vital for log synchronization and time-based security certificates, it is not a 'Day 0' security hardening step in the same category as changing default passwords. The system can function without NTP initially, but it cannot be considered secure if default credentials are still in place.

  • ✗

    Enable the 'bigdb' security variable.

    Why it's wrong here

    Bigdb variables are secondary to basic authentication security. Hardening the system begins with fundamental access controls like passwords and allowed-IP lists. Enabling internal variables without addressing account security leaves the system vulnerable regardless of the internal hardening settings applied to the traffic management software.

  • ✓

    Change default administrative passwords.

    Why this is correct

    Default passwords are the primary vulnerability for new installations. Changing these immediately ensures that only authorized administrators can access the system. This step is mandatory in any secure environment to protect the management plane, which is the gateway to all traffic control and data management functions.

  • ✗

    Assign a management VLAN ID.

    Why it's wrong here

    Assigning a management VLAN is a network segmentation task, not a direct security hardening requirement for the appliance itself. While it adds a layer of security by isolating management traffic, it does not mitigate the risk posed by default credentials, which are the highest priority security concern.

About these practice questions

This F5CAB1 question is part of Courseiva's 80-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official F5 exam blueprint

This F5CAB1 practice question is part of Courseiva's free F5 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the F5CAB1 exam.