Courseiva

F5CAB4 Control Plane Administration Practice Question

An administrator wants to restrict the types of ciphers used for SSH access to the BIG-IP system. Which configuration file or tool should be modified?

⚠ Common exam trap

Candidates often look for a GUI setting or a specific F5-proprietary command. They frequently forget that SSH is a standard Linux service managed via the underlying OS configuration files.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Modify the sshd_config file.

SSH access is governed by the 'sshd' service configuration. Modifying the configuration to limit ciphers is a standard task for hardening the management plane. By enforcing stronger ciphers, the administrator protects administrative sessions from potential cryptographic attacks, ensuring that only secure, modern encryption methods are used when managing the BIG-IP, which is essential for maintaining a secure and compliant control plane environment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Modify the sshd_config file.

    Why this is correct

    The /etc/ssh/sshd_config file is the standard configuration file for the SSH daemon on Linux systems, including BIG-IP. By editing this file and specifying the allowed Ciphers and MACs, administrators can restrict SSH access to use only secure cryptographic standards, which is a vital part of hardening the control plane.

  • ✗

    Update the global firewall policy.

    Why it's wrong here

    The global firewall policy governs data plane traffic. It does not control SSH daemon configuration or the cryptographic protocols used for administrative sessions. Modifying this policy will not restrict or influence the SSH ciphers used by the system for management access, making it ineffective for this specific security task.

  • ✗

    Change the system time settings.

    Why it's wrong here

    System time settings are used for log correlation and certificate validity. They have no impact on the SSH configuration or the cryptographic ciphers used for management access. Adjusting the time will not change the security protocols of the SSH service, as these are independent configurations within the operating system.

  • ✗

    Modify the iRule settings.

    Why it's wrong here

    iRules are specific to traffic management and operate at the virtual server level to manipulate application data. They cannot be used to modify the configuration of system-level services like the SSH daemon. SSH security settings must be managed through the native Linux configuration files on the management plane.

About these practice questions

This F5CAB4 question is part of Courseiva's 40-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official F5 exam blueprint

This F5CAB4 practice question is part of Courseiva's free F5 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the F5CAB4 exam.