F5CAB4 Control Plane Administration Practice Question
An administrator is troubleshooting a BIG-IP device that is failing to synchronize configuration changes with its peer. The administrator runs 'tmsh show cm sync-status' and sees 'Changes Pending'. Which action should the administrator take first to identify the cause?
⚠ Common exam trap
The trap here is jumping to detailed configuration comparison before verifying basic device trust and group membership.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Run 'tmsh show cm device' to check the device group and trust status.
When synchronization fails with 'Changes Pending', the first step is to verify that the device is trusted and properly configured in the device group. The 'show cm device' command provides this information. If trust is broken or the device is not in the correct group, synchronization cannot occur. Once trust and group membership are confirmed, further troubleshooting can focus on specific configuration differences or network connectivity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Run 'tmsh show sys mcp-state' to verify the mcpd daemon is running.
Why it's wrong here
While mcpd is essential for configuration management, if it were not running, the device would likely be in a different state and 'show cm sync-status' would not return 'Changes Pending'. The issue is specifically about synchronization between peers, so verifying the daemon state is less directly relevant than checking device trust and group membership.
- ✓
Run 'tmsh show cm device' to check the device group and trust status.
Why this is correct
This command displays the device's synchronization state, trust status, and device group membership. If the device is not trusted or not in the correct device group, synchronization will fail. Checking this first is logical because it verifies the foundational communication and group configuration before diving deeper into specific configuration differences.
- ✗
Run 'tmsh show cm sync-status' with the 'verbose' option to see detailed differences.
Why it's wrong here
The 'verbose' option may provide more detail, but it is not the first step. The 'Changes Pending' status indicates that there are unsynchronized changes, but the root cause could be a trust issue or device group misconfiguration. Checking device trust and group status is a more fundamental first step to rule out communication problems.
- ✗
Run 'tmsh show sys config' to compare the running configuration with the saved configuration.
Why it's wrong here
This command shows the current running configuration but does not directly help with synchronization between peers. The issue is not about running vs. saved config on this device, but about why changes are not being synchronized to the peer. Comparing configurations manually is inefficient and does not address trust or device group issues.
About these practice questions
This F5CAB4 question is part of Courseiva's 40-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official F5 exam blueprint
This F5CAB4 practice question is part of Courseiva's free F5 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the F5CAB4 exam.