F5CAB1 Install, Initial Configuration, and Upgrade Practice Question
Which component of the BIG-IP initial setup is used to ensure that administrative access to the system is restricted to trusted management subnets?
⚠ Common exam trap
Candidates often focus only on the management IP and ignore access restrictions. Leaving the management interface open to all subnets is a major security vulnerability that should be mitigated immediately.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Management port allowed addresses
The 'Management IP' configuration includes the ability to set packet filter rules or restrict GUI/SSH access via management allowed lists. Limiting access ensures that only specific, authorized subnets can interact with the management plane. This is a vital security best practice, preventing unauthorized actors from attempting to log in to the management interface of the F5 device from public or untrusted network segments.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Self-IP allow list
Why it's wrong here
Self-IP allow lists manage traffic passing through TMM (the traffic processing plane), not access to the BIG-IP management interface. While important for application security, these rules do not control access to the Configuration Utility or SSH shell, which are managed by the management interface settings and system-wide access controls.
- ✓
Management port allowed addresses
Why this is correct
This setting directly controls which source IP addresses are permitted to connect to the BIG-IP management interface. By restricting access to internal or VPN subnets, the administrator significantly hardens the device against brute-force attacks and unauthorized access attempts aimed at the management plane, which is a core security requirement.
- ✗
Route table configuration
Why it's wrong here
The route table determines how the BIG-IP sends outbound traffic, such as to an NTP server or syslog server. It does not control incoming traffic access or restrict who can reach the management IP. Using routing to attempt to secure the interface is ineffective and technically inappropriate for access control.
- ✗
VLAN tagging policies
Why it's wrong here
VLAN tagging is a Layer 2 concept used to segment traffic at the data-link layer. It does not provide Layer 3 or Layer 4 access controls that restrict management logins. While VLANs help organize traffic, they do not replace the need for explicit access control lists on the management interface.
Visual reference
About these practice questions
This F5CAB1 question is part of Courseiva's 80-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official F5 exam blueprint
This F5CAB1 practice question is part of Courseiva's free F5 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the F5CAB1 exam.