Courseiva

F5CAB1 Install, Initial Configuration, and Upgrade Practice Question

You are preparing a BIG-IP for production. You need to ensure that the system is secure by default. Which task should be performed as part of the initial configuration hardening process?

⚠ Common exam trap

Candidates often assume that enabling a firewall or configuring VLANs is the primary hardening step, overlooking the fact that default credentials are the most common entry point for unauthorized access during initial deployment.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Change the default 'root' and 'admin' passwords.

Hardening is a critical phase of the initial configuration. Changing default credentials, disabling unused services, and ensuring the root account is restricted are essential to protect the device from unauthorized access. These steps reduce the attack surface of the appliance, ensuring that the BIG-IP is not vulnerable to common automated exploits that target default configurations and factory settings immediately upon being deployed to the network.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Disable the GUI and only use CLI for all configuration tasks.

    Why it's wrong here

    While CLI is powerful, disabling the GUI is not a hardening requirement. The GUI is a core component of the BIG-IP management experience. Properly securing the GUI through access control lists and strong authentication is the appropriate approach, rather than completely removing a primary management interface.

  • ✓

    Change the default 'root' and 'admin' passwords.

    Why this is correct

    Changing default passwords is the single most important hardening step. Default credentials are widely known and are the first targets for attackers. Ensuring unique, complex passwords for both the root and admin accounts immediately mitigates the risk of unauthorized access via factory-default login credentials.

  • ✗

    Remove the default 'Common' partition from the configuration.

    Why it's wrong here

    The 'Common' partition is a required system partition in BIG-IP. It cannot be deleted. Attempting to remove it would break the system's configuration structure and cause critical errors. Hardening should focus on access control and configuration policies, not on attempting to delete mandatory core system components.

  • ✗

    Enable all available F5 features to test functionality.

    Why it's wrong here

    Enabling unnecessary features increases the attack surface and potential for misconfiguration. A secure deployment follows the principle of least privilege, enabling only the specific features required for the intended application delivery tasks. Unused services should remain disabled to minimize potential vulnerabilities and maintain a smaller, more secure footprint.

About these practice questions

Courseiva writes every F5CAB1 question from scratch — 80 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official F5 exam blueprint

This F5CAB1 practice question is part of Courseiva's free F5 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the F5CAB1 exam.