Summer Sale Discount Flat 70% Offer - Ends in 0d 00h 00m 00s - Coupon code: 70diswrap

F5 F5CAB4 Dumps

Page: 1 / 7
Total 71 questions

BIG-IP Administration Control Plane Administration (F5CAB4) exam Questions and Answers

Question 1

The BIG-IP Administrator suspects unauthorized SSH login attempts on the BIG-IP system.

Which log file would contain details of these attempts? (Choose one answer)

Options:

A.

/var/log/messages

B.

/var/log/secure

C.

/var/log/audit

D.

/var/log/ltm

Question 2

Administrative user accounts have been defined on the remote LDAP server and are unable to log in to the BIG-IP device.

Which log file should the BIG-IP Administrator check to find the related messages? (Choose one answer)

Options:

A.

/var/log/user.log

B.

/var/log/ltm

C.

/var/log/messages

D.

/var/log/secure

Question 3

A BIG-IP Administrator discovers malicious brute-force attempts to access the BIG-IP device on the management interface via SSH. The BIG-IP Administrator needs to restrict SSH access to the management interface. Where should this be accomplished?

Options:

A.

System > Configuration

B.

Network > Interfaces

C.

Network > Self IPs

D.

System > Platform

Question 4

A BIG-IP Administrator receives an RMA replacement for a failed F5 device. The Administrator tries to restore a UCS taken from the previous device, but the restore fails. The following error appears in the /var/log/ltm:

insufficient pool members. 01070608:3: License is not operational

(expired, digital signature does not match contents)

What should the BIG-IP Administrator do to avoid this error ? (Choose one answer)

Options:

A.

Remove the license information from the UCS archive

B.

Revoke the license prior to restoring

C.

Use the appropriate tmsh command with the no-license option

D.

Reactivate the license on the new device using the manual activation method

Question 5

A BIG-IP Administrator is conducting maintenance on one BIG-IP appliance in an HA Pair. Why should the BIG-IP Administrator put the appliance into FORCED_OFFLINE state?

Options:

A.

To preserve existing connections to Virtual Servers and reduce the CPU load

B.

To allow new connections to Virtual Servers and ensure the appliance becomes active

C.

To terminate connections to the management IP and decrease persistent connections

D.

To terminate existing connections to Virtual Servers and prevent the appliance from becoming active

Question 6

The BIG-IP appliance fails to boot. The BIG-IP Administrator needs to run the End User Diagnostics (EUD) utility to collect data to send to F5 Support. Where can the BIG-IP Administrator access this utility?

Options:

A.

Console Port

B.

Internal VLAN interface

C.

External VLAN interface

D.

Management Port

Question 7

Which method is recommended for creating a new user from the CLI? (Choose one answer)

Options:

A.

Run tmsh create auth user username prompt-for-password from bash

B.

Edit bigip.conf to add the new user and the user’s clear-text password

C.

Run f5adduser ' username ' then f5passwd username from bash or tmsh

D.

Run useradd ' username ' then passwd username from bash or tmsh

Question 8

The BIG-IP system is provisioned for LTM only . The BIG-IP Administrator is tasked with provisioning ASM .

What process restarts when the BIG-IP Administrator changes the module provisioning? (Choose one answer)

Options:

A.

bd

B.

tmm

C.

sshd

D.

httpd

Question 9

A BIG-IP Administrator needs to restore a UCS file to an F5 device using the Configuration Utility. Which section of the Configuration Utility should the BIG-IP Administrator access to perform this task?

Options:

A.

Local Traffic > Virtual Servers

B.

Local Traffic > Policies

C.

System > Archives

D.

System > Configuration

Question 10

The BIG-IP Administrator runs the command:

netstat -an | grep 443

and sees the following output:

tcp 0 0 0.0.0.0:443 0.0.0.0:* LISTEN

What does this output indicate about the service on port 443? (Choose one answer)

Options:

A.

The service is actively listening only on the loopback interface.

B.

The service is actively listening on all interfaces for HTTPS traffic.

C.

The service indicates no connections to the LISTEN port.

D.

The service is in a standby state and unable to accept connections.

Question 11

A BIG-IP Administrator must determine if a Virtual Address is configured to fail over to the standby member of a device group. In which area of the Configuration Utility can this be confirmed?

Options:

A.

Device Management > Traffic Groups

B.

Device Management > Devices

C.

Local Traffic > Virtual Servers

D.

Device Management > Overview

Question 12

Refer to the output.

Color green

Status In Sync

Summary

Details

/Common/host1.company.com: connected (for 2548 seconds)

/Common/sync-fail-test (In Sync):

- all 2 devices consistent

/Common/device_trust_group (In Sync):

- all 2 devices consistent

Which TMSH command generated this output?

Options:

A.

tmsh list /cm sync-status

B.

tmsh show /cm sync-status

C.

tmsh show /sys sync-status

D.

tmsh list /sys sync-status

Question 13

Which log file should the BIG-IP Administrator check to determine if a specific user tried to log in to the BIG-IP Configuration Utility ? (Choose one answer)

Options:

A.

/var/log/pam/tallylog

B.

/var/log/secure

C.

/var/log/ltm

D.

/var/log/httpd

Question 14

A BIG-IP Administrator needs to update the list of configured NTP servers. In which area of the Configuration Utility should the BIG-IP Administrator perform this update?

Options:

A.

System > Configuration

B.

System > Services

C.

System > Preferences

D.

System > Platform

Question 15

One of the two members of a device group has been decommissioned. The BIG-IP Administrator tries to delete the device group, but is unsuccessful.

Prior to removing the device group, which action should be performed? (Choose one answer)

Options:

A.

Remove all members from the device group

B.

Make sure all members of the device group are in sync

C.

Remove the decommissioned device from the device group

D.

Disable the device group

Question 16

A BIG-IP Administrator uses a device group to share the workload and needs to perform service on a BIG-IP device currently active for a traffic group . The administrator needs to enable the traffic group to run on another BIG-IP device in the device group.

What should the administrator do to meet the requirement? (Choose one answer)

Options:

A.

Create a new Traffic Group and then fail to Standby Unit

B.

Select Traffic Group and then select Failover

C.

Select Traffic Group and then select Force to Standby

D.

Select Traffic Group on Primary Unit and then select Demote

Question 17

A configuration change is made on the standby member of a device group. What is displayed as " Recommended Action " on the Device Management Overview screen?

Options:

A.

Force active member of device group to standby

B.

Activate device with the most recent configuration

C.

Synchronize the active member configuration to the group.

D.

Synchronize the standby member configuration to the group

Question 18

What are the recommended methods for forcing a BIG-IP system to standby mode ? (Choose two answers)

Options:

A.

Active BIG-IP: CLI > tmsh run /sys failover device standby

B.

Active BIG-IP: Configuration Utility > Device Management > Devices > Local Device (Self) > Force to Standby

C.

Active BIG-IP: Configuration Utility > Device Management > Traffic Groups > Local Device (Self) > Force to Standby

D.

Active BIG-IP: CLI > tmsh run /sys failover standby

Question 19

Refer to the exhibit.

as

The BIG-IP Administrator runs the command shown and observes a device trust issue between BIG-IP devices in a device group. The issue prevents config sync on device bigip3.local. What is preventing the config sync?

Options:

A.

Next Active Load factor is 0 on bigip1.local

B.

Both devices are standby

C.

Next Active Load factor is 1 on bigip1.local

D.

Time Delta to local system is

Question 20

A BIG-IP Administrator needs to fall over the active device. The administrator logs into the Configuration Utility and navigates to Device Management > Traffic Group. However, " Force to Standby " is greyed out. What is causing this issue?

Options:

A.

The BIG-IP Administrator is NOT logged into command line to tail over

B.

The BIG-IP Administrator is on the Standby Device

C.

The BIG-IP Administrator is logged in as root

D.

The BIG-IP Administrator is logged in as administrator

Question 21

New Syslog servers have been deployed in an organization. The BIG-IP Administrator must reconfigure the BIG-IP system to send log messages to these servers.

In which location in the Configuration Utility can the BIG-IP Administrator make the needed configuration changes to accomplish this? (Choose one answer)

Options:

A.

System > Configuration > Local Traffic

B.

System > Logs > Configuration

C.

System > Logs > Audit

D.

System > Configuration > Device

Page: 1 / 7
Total 71 questions