Courseiva

F5CAB1 Install, Initial Configuration, and Upgrade Practice Question

Which component of the BIG-IP initial setup is used to ensure that administrative access to the system is restricted to trusted management subnets?

⚠ Common exam trap

Candidates often focus only on the management IP and ignore access restrictions. Leaving the management interface open to all subnets is a major security vulnerability that should be mitigated immediately.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Management port allowed addresses

The 'Management IP' configuration includes the ability to set packet filter rules or restrict GUI/SSH access via management allowed lists. Limiting access ensures that only specific, authorized subnets can interact with the management plane. This is a vital security best practice, preventing unauthorized actors from attempting to log in to the management interface of the F5 device from public or untrusted network segments.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Self-IP allow list

    Why it's wrong here

    Self-IP allow lists manage traffic passing through TMM (the traffic processing plane), not access to the BIG-IP management interface. While important for application security, these rules do not control access to the Configuration Utility or SSH shell, which are managed by the management interface settings and system-wide access controls.

  • ✓

    Management port allowed addresses

    Why this is correct

    This setting directly controls which source IP addresses are permitted to connect to the BIG-IP management interface. By restricting access to internal or VPN subnets, the administrator significantly hardens the device against brute-force attacks and unauthorized access attempts aimed at the management plane, which is a core security requirement.

  • ✗

    Route table configuration

    Why it's wrong here

    The route table determines how the BIG-IP sends outbound traffic, such as to an NTP server or syslog server. It does not control incoming traffic access or restrict who can reach the management IP. Using routing to attempt to secure the interface is ineffective and technically inappropriate for access control.

  • ✗

    VLAN tagging policies

    Why it's wrong here

    VLAN tagging is a Layer 2 concept used to segment traffic at the data-link layer. It does not provide Layer 3 or Layer 4 access controls that restrict management logins. While VLANs help organize traffic, they do not replace the need for explicit access control lists on the management interface.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

This F5CAB1 question is part of Courseiva's 80-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official F5 exam blueprint

This F5CAB1 practice question is part of Courseiva's free F5 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the F5CAB1 exam.