
F5 Certified Administrator, BIG-IP
The F5 Certified Administrator, BIG-IP certification validates your ability to perform day-to-day operations, basic deployment, management, security, and support of BIG-IP in various application environments. This exam focuses on installing, configuring, and upgrading BIG-IP, covering security, licensing, software images, and module provisioning. Earning this credential demonstrates your competence in BIG-IP administration for both data plane and control plane.
479 practice questions · Updated 2026-07-30
5Domains
30Objectives
139Concepts
479Questions
F5CAB1 Curriculum
Every domain, objective, and concept the F5CAB1 exam measures.
- Management-IP Overview
- Management-IP Configuration
- Management-IP Access Control
- Management-IP Security Hardening
- Management-IP Troubleshooting
- Port lockdown overview
- Port lockdown modes
- Configuring port lockdown
- Custom port lockdown rules
- Verifying port lockdown
- Self-IP Firewall Rule Purpose
- Default Self-IP Firewall Behavior
- Creating Firewall Rules for Self-IPs
- Rule Ordering and Precedence
- Verifying Self-IP Firewall Rules
- Identify DDoS attack vectors
- Configure DDoS protection profiles
- Apply DDoS vectors to virtual servers
- Tune DDoS vector thresholds
- Monitor DDoS vector events
- Password Policy Configuration
- Password Aging and Expiration
- Password History and Reuse Prevention
- Account Lockout Policies
- Password Policy Enforcement for Administrative Accounts
- SSHD ACL Overview
- ACL Configuration Methods
- ACL Rule Structure
- Ordering and Precedence
- Default Behavior
- Verification and Testing
- Troubleshooting
- HTTPd ACL Overview
- ACL Configuration
- ACL Rule Ordering
- ACL Verification
- BIG-IP Administrative Access
- BIG-IP Security Features
- BIG-IP Traffic Management Security
- BIG-IP SSL/TLS Configuration
- BIG-IP Logging and Monitoring
- Management IP address definition
- Locating management IP in configuration
- Verifying management IP via GUI
- Verifying management IP via CLI
- Distinguishing management IP from self IPs
- Port lockdown basics
- Default port lockdown behavior
- Port lockdown options
- Allow Default specifics
- Allow Custom configuration
- Impact on management connectivity
- Troubleshooting port lockdown
- Remote management access methods
- Management interface IP configuration
- Network routing for management traffic
- Access control and authentication
- Troubleshooting remote connectivity
- Management IP address configuration
- Management interface and network settings
- Connectivity troubleshooting basics
- Verification of management connectivity
- Impact of management IP on system access
- Purpose of management access lists
- Configuration of HTTP/SSH access lists
- Verification of access list enforcement
- Management connectivity overview
- Management IP configuration
- Management route configuration
- Management interface settings
- Accessing the management interface
- Management access controls
- Verifying management connectivity
- Accessing the licensing portal
- Navigating the licensing portal
- Common license issues
- Diagnostic tools for licensing
- Troubleshooting steps
- Service Check Date definition
- Locating Service Check Date
- Impact of Service Check Date on upgrades
- Checking Service Check Date before upgrade
- Handling expired Service Check Date
- Identify provisioned modules via TMUI
- Identify provisioned modules via CLI
- Identify provisioned modules via config files
- Identify licensed modules via CLI
- Identify licensed modules via config files
- Identify licensed modules via TMUI
- Compare licensing information across interfaces
- Licensing Process
- License Reactivation
- License Modification
- HA Pair Software Upgrade Overview
- Pre-Upgrade Preparation
- Upgrade Sequence for Active and Standby Units
- Failover and Traffic Impact
- Post-Upgrade Verification and Rollback
- Identify software image file requirements
- Access the software management interface
- Upload software image via web interface
- Upload software image via SCP
- Verify software image upload integrity
- Prepare for image installation
- Identify boot location configuration
- Access boot location settings
- Interpret boot location output
- Verify boot location against expected state
- Volume creation prerequisites
- Creating a new volume
- Verifying volume creation
- Software Image Management Overview
- Image Storage and Locations
- Image Upload Methods
- Image Validation and Integrity
- Image Installation Procedures
- Image Upgrade Paths and Compatibility
- Image Rollback and Recovery
- Image Management Best Practices
- Accessing the provisioned modules list
- Interpreting module provisioning status
- Using TMSH commands to show modules
- Using the Configuration utility to show modules
- Identify licensed modules
- Identify provisioned modules
- Use command-line tools for module status
- Interpret license and provisioning output
- Accessing resource utilization
- Interpreting utilization metrics
- Correlating modules with resource usage
- Monitoring real-time utilization
- Identify licensed modules
- Identify provisioned modules
- Compare licensed vs provisioned modules
- Report provisioned but unlicensed modules
- Licensing vs. provisioning
- Identifying licensed modules
- Identifying provisioned modules
- Module provisioning states
Ready to practice?Test your knowledge with exam-style questions or take an intelligent quiz tailored to your level.
Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for F5CAB1, so none is invented.