
F5Certified Administrator, BIG-IP
Domain 1Objective 3
Firewall Rules for Self-IPs F5CAB1 Practice Questions (Page 1)
Part of the Securing BIG-IP domain, which makes up ~29% of our current practice bank. F5 does not publish an official question count, but from its 30-minute exam (~10–20 total, ~3–6 in this domain), expect 1–1 from this objective — we provide 17 practice questions to prepare you well beyond it. (estimate)
17questions here
4free pages
5concepts
Questions 1–5
- 1
A BIG-IP Administrator notices that the Self-IP on VLAN internal (192.168.10.1/24) is responding to ICMP echo requests from any source on the internal network. The security policy requires that only the monitoring server at 192.168.10.100 should be able to ping the Self-IP. The administrator adds a firewall rule to the Self-IP rule list: source 192.168.10.100, destination 192.168.10.1, port 8 (ICMP echo), action Accept. After applying the rule, the monitoring server can ping the Self-IP, but other hosts can still ping it. What is the most likely reason for this?
Select an answer first - 2
A BIG-IP Administrator is troubleshooting why a Self-IP firewall rule is not working as expected. The rule is intended to allow HTTPS (port 443) from the admin subnet 10.10.10.0/24 to the Self-IP 10.10.10.1. The rule is placed at the top of the Self-IP rule list. The administrator verifies that the rule is correctly configured and applied. However, HTTPS access from the admin subnet is failing, while HTTPS access from other subnets is working. What is the most likely cause?
Select an answer first - 3
An administrator is configuring Self-IP firewall rules on a BIG-IP device. The requirement is to allow HTTPS management access (port 443) from the corporate admin subnet 10.20.0.0/24, and to block all other management access. The administrator creates two rules: Rule 1 (Accept, source 10.20.0.0/24, destination Self-IP, port 443) and Rule 2 (Deny, source any, destination Self-IP, port any). What is the correct order for these rules in the Self-IP firewall rule list?
Select an answer first - 4
An administrator is creating Self-IP firewall rules on a BIG-IP device. The requirement is to allow NTP (port 123) from the time server 192.168.2.10 to the Self-IP 192.168.2.1, and to block all other NTP traffic. The administrator creates an Accept rule for the time server and a Deny rule for all other sources. What is the correct order for these rules?
Select an answer first - 5
A BIG-IP Administrator is troubleshooting why a new firewall rule for a Self-IP is not working as expected. The rule is intended to allow SNMP (port 161) from the monitoring server 192.168.1.50 to the Self-IP 192.168.1.1. The rule is placed at the bottom of the Self-IP firewall rule list. The administrator verifies that the rule is correctly configured and applied. However, SNMP queries from the monitoring server are still failing. What is the most likely cause?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by F5. “F5CAB1” is a trademark of its owner, used for identification only.