F5CAB1 Install, Initial Configuration, and Upgrade Practice Question
An administrator is upgrading a BIG-IP instance and notices that the configuration load is taking an unusually long time. Which log file should be checked to identify the cause?
⚠ Common exam trap
Candidates often check traffic management logs like 'apm' or 'gtm' when troubleshooting core system configuration loading issues, forgetting that general system and Traffic Management Microkernel events reside in the 'ltm' log.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
/var/log/ltm
Monitoring logs during the upgrade process is critical for identifying why a system is stalling. The 'ltm' log file contains high-level information about system events, including configuration loading and daemon initialization status. By checking this file, the administrator can see if the configuration parser is stuck on a specific object or if a process is failing to start, allowing for targeted troubleshooting rather than guessing the reason for the delay.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
/var/log/ltm
Why this is correct
The ltm log file records status messages for the Local Traffic Manager, which includes configuration loading events. If the system is hanging during the boot-up phase, the ltm log will typically contain entries indicating the last successfully loaded object, helping the administrator identify which configuration item is causing the delay or failure.
- ✗
/var/log/audit
Why it's wrong here
The audit log records user actions and configuration changes made via the GUI or CLI. It is not used for monitoring the progress of system boot-up or configuration loading during an upgrade. While useful for tracking who did what, it does not provide insight into system performance bottlenecks during the startup sequence.
- ✗
/var/log/kern.log
Why it's wrong here
The kernel log records low-level operating system events and hardware drivers. While useful for debugging hardware-related issues, it rarely provides specific information regarding the status of the configuration loading process during a BIG-IP upgrade. Configuration issues are handled by application daemons, not the kernel, making this log less relevant for this problem.
- ✗
/var/log/secure
Why it's wrong here
The secure log tracks authentication and authorization attempts, including SSH logins and other access-related activity. It has no role in recording the progress of configuration loading or system service startup. Checking this file is irrelevant when troubleshooting a hang or delay in the BIG-IP system's configuration reload process after an upgrade.
About these practice questions
One of 80 original F5CAB1 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official F5 exam blueprint
This F5CAB1 practice question is part of Courseiva's free F5 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the F5CAB1 exam.