F5CAB4 Control Plane Administration Practice Question
An administrator needs to restrict administrative access to the BIG-IP system so that only specific management workstations can reach the Configuration Utility and SSH. Which control plane mechanism should be configured to implement this access control?
⚠ Common exam trap
Candidates often confuse data plane traffic filters (like self IP packet filters) with control plane protections, failing to realize that management interface protection specifically requires management packet filters.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Define a management packet filter policy on the management interface.
Implementing packet filters on the management interface is the standard security practice to harden the control plane. By defining an Allow rule for authorized subnets and a Drop rule for all other traffic, you prevent unauthorized reconnaissance and brute-force attempts. This is critical for maintaining the integrity of the administrative plane, ensuring that management access remains restricted to secure, trusted administrative jump hosts or network segments.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure an iRule on the Management Virtual Server.
Why it's wrong here
iRules are designed for processing traffic through the data plane via the TMM process. They are not intended for securing the management interface or the underlying Linux host process, which handles control plane access independently of the Traffic Management Microkernel's standard processing logic.
- ✗
Enable the 'Allow All' policy in the Device Service Group.
Why it's wrong here
Enabling an 'Allow All' policy would remove restrictions rather than impose them. This would expose the management interface to the entire network, significantly increasing the attack surface of the control plane and violating the principle of least privilege required for secure administrative access.
- ✓
Define a management packet filter policy on the management interface.
Why this is correct
Management packet filters act as a host-based firewall for the BIG-IP management interface. By configuring these filters, you explicitly permit or deny traffic based on IP address and port, ensuring that only sanctioned management stations can communicate with the system's SSH and HTTPS administrative services.
- ✗
Modify the global db variable 'httpd.allowed.ips'.
Why it's wrong here
While db variables exist for various configuration aspects, modifying internal database variables is not the supported method for controlling network access at the interface level. Packet filters are the official, supported mechanism for granular access control on the management interface, offering better visibility and auditability.
Visual reference
About these practice questions
This F5CAB4 question is part of Courseiva's 40-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official F5 exam blueprint
This F5CAB4 practice question is part of Courseiva's free F5 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the F5CAB4 exam.