F5CAB1 Install, Initial Configuration, and Upgrade Practice Question
An administrator is configuring a new BIG-IP and needs to ensure that the device's management interface is accessible only from a specific secure jump host. Which configuration element should be modified?
⚠ Common exam trap
Candidates mistakenly modify general firewall rules or VLAN security settings instead of the specific management interface allowed IP configuration list.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Update the Management Interface allowed list.
Restricting management access is a fundamental security practice. By modifying the 'Allowed IP addresses' list within the management interface configuration, the BIG-IP will only accept traffic from designated IP addresses. This effectively mitigates the risk of unauthorized access attempts from the broader network, ensuring that only trusted machines, such as a secure jump host, can interact with the system's management services.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Modify the Virtual Server access list.
Why it's wrong here
Virtual Server access lists manage client-to-application traffic. They do not control access to the management plane of the BIG-IP itself. Modifying these lists would only restrict access to the hosted applications, leaving the management interface open to unauthorized attempts from anywhere on the network, which is insecure.
- ✓
Update the Management Interface allowed list.
Why this is correct
The 'Allowed IP addresses' field for the management interface is the specific setting designed to control which source IPs can access the device's management GUI, SSH, and other services. By restricting this to a jump host, you ensure that only authorized administrative sources can access the management plane.
- ✗
Create a packet filter on the external interface.
Why it's wrong here
A packet filter on an external interface manages data plane traffic (application traffic). Management traffic typically traverses the dedicated management interface. Relying on an external interface filter is ineffective for managing access to the management IP, as management traffic does not pass through the data plane interfaces.
- ✗
Disable the HTTPS service on the device.
Why it's wrong here
Disabling HTTPS completely would prevent all GUI-based management, forcing the administrator to use the command line. While secure, this is an extreme measure that is unnecessary when simple IP-based access control lists (ACLs) can achieve the same security goal while maintaining the usability of the administrative dashboard.
About these practice questions
This F5CAB1 question is part of Courseiva's 80-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official F5 exam blueprint
This F5CAB1 practice question is part of Courseiva's free F5 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the F5CAB1 exam.