F5CAB4 Control Plane Administration Practice Question
Which log file is most useful for troubleshooting administrative login attempts and authentication failures on the BIG-IP control plane?
⚠ Common exam trap
Candidates often confuse '/var/log/ltm' with '/var/log/secure', forgetting that LTM logs focus on traffic processing and application events, not system-level authentication or login security.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
/var/log/secure
The /var/log/secure log file is the standard Linux repository for authentication-related events. On a BIG-IP, this includes SSH access, GUI login attempts, and PAM-related authentication activities. Monitoring this file is essential for F5 administrators to detect brute-force attacks, troubleshoot credential issues, and maintain a secure control plane by keeping track of who is accessing the device and when.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
/var/log/ltm
Why it's wrong here
The /var/log/ltm file tracks Local Traffic Manager events, such as virtual server availability, pool member status, and iRule execution. It does not contain administrative login information, making it the wrong place to look when diagnosing issues related to user authentication or management access to the system.
- ✓
/var/log/secure
Why this is correct
The /var/log/secure file records authentication-related activities on the Linux system, including SSH logins and administrative authentication successes or failures. This is the primary log to check for investigating unauthorized access attempts or troubleshooting why a specific administrator cannot log in to the system via the management interface.
- ✗
/var/log/messages
Why it's wrong here
The /var/log/messages file acts as a general-purpose log for system-wide notices and error messages. While it may contain some high-level system information, it is not the designated file for specific authentication events, which are separated into the /var/log/secure file for clearer auditing and security management purposes.
- ✗
/var/log/audit
Why it's wrong here
The /var/log/audit log file is used for recording specific administrative commands executed via tmsh or the GUI when audit logging is enabled. It tracks changes to the configuration, but it is not the primary location for capturing login attempts or failed authentication events for user accounts.
About these practice questions
Courseiva writes every F5CAB4 question from scratch — 40 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official F5 exam blueprint
This F5CAB4 practice question is part of Courseiva's free F5 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the F5CAB4 exam.