Courseiva

F5CAB1 Install, Initial Configuration, and Upgrade Practice Question

Which action should an administrator take to ensure that a newly installed BIG-IP system is secure before placing it into a production environment?

⚠ Common exam trap

Candidates often assume that applying a base license or configuring VLANs is sufficient for securing a new system, forgetting that default administrative accounts remain a critical vulnerability.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Change the default 'root' and 'admin' passwords.

Security is paramount in initial configuration. Changing default credentials, disabling unnecessary services, and configuring management network restrictions are fundamental steps to harden the appliance. By addressing these items immediately, administrators prevent unauthorized access and reduce the attack surface, ensuring the system aligns with corporate security policies before it starts handling any sensitive client-side traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Change the default 'root' and 'admin' passwords.

    Why this is correct

    Default passwords are a primary target for attackers. Changing them immediately upon initialization is the most critical step in securing the BIG-IP. This prevents unauthorized administrative access, which could lead to full system compromise, data breaches, or complete disruption of network services managed by the device.

  • ✗

    Enable all available management services.

    Why it's wrong here

    Enabling all services increases the attack surface unnecessarily. Only essential services like SSH or HTTPS should be enabled. Unnecessary services, such as Telnet or legacy protocols, can contain vulnerabilities that attackers can exploit to gain unauthorized access to the BIG-IP system management plane.

  • ✗

    Keep the default SSL certificate for management.

    Why it's wrong here

    The default SSL certificate is self-signed and known to everyone. Using it for the management GUI exposes administrators to man-in-the-middle attacks. Replacing it with a certificate signed by a trusted internal CA ensures secure, authenticated communication between the administrator's workstation and the BIG-IP management interface.

  • ✗

    Disable logging to save disk space.

    Why it's wrong here

    Disabling logging is a security risk because it eliminates audit trails. In the event of a security incident, logs are required for forensic analysis. Without logs, administrators cannot determine the scope of a breach, identify the attacker, or verify if unauthorized changes were made to the configuration.

About these practice questions

This F5CAB1 question is part of Courseiva's 80-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official F5 exam blueprint

This F5CAB1 practice question is part of Courseiva's free F5 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the F5CAB1 exam.