Courseiva

F5CAB4 Control Plane Administration Practice Question

An administrator needs to restrict administrative access to the BIG-IP system so that only specific source IP addresses can reach the Configuration Utility. Which feature should be configured to ensure this security requirement?

⚠ Common exam trap

Candidates often confuse the data plane packet filters or standard self IP allow lists with the specific system-level Management IP configuration whitelist required for GUI access restriction.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Update the Management IP Allow list in System Configuration.

Restricting management access via the Management IP allows administrators to define a whitelist of trusted networks. This is a critical security practice in F5 Control Plane Administration to prevent unauthorized access to the management plane from untrusted segments. By using the 'Allow' list under System > Configuration > Device > Management IP, the BIG-IP will drop any packets originating from non-authorized IPs, effectively securing the administrative interface from external threats.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable Packet Filtering on the external VLAN.

    Why it's wrong here

    Packet filtering on a data plane VLAN affects traffic passing through the BIG-IP as an application delivery controller. It does not control access to the management IP or the Configuration Utility, which are handled through dedicated management plane settings or the management port's specific security configurations.

  • ✗

    Configure an iRule to drop traffic on the management port.

    Why it's wrong here

    iRules are processed by the TMM (Traffic Management Microkernel) and are applied to virtual servers handling application traffic. They cannot be applied to the management IP or the underlying Linux management plane services, making this approach ineffective for securing administrative access to the BIG-IP system.

  • ✓

    Update the Management IP Allow list in System Configuration.

    Why this is correct

    The Management IP Allow list specifically controls which source IP addresses are permitted to access the BIG-IP management interface. By defining allowed subnets here, the administrator ensures that only authorized management workstations can reach the GUI, SSH, or SNMP services residing on the control plane.

  • ✗

    Modify the global Firewall policy for the Data Plane.

    Why it's wrong here

    The global firewall policy governs traffic moving through the data plane interfaces of the BIG-IP. It is intended to manage application traffic flows rather than the administrative traffic destined for the control plane. This setting will not impact access to the Configuration Utility or SSH.

About these practice questions

One of 40 original F5CAB4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official F5 exam blueprint

This F5CAB4 practice question is part of Courseiva's free F5 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the F5CAB4 exam.