
F5Certified Administrator, BIG-IP
Domain 2Objective 5
Identify HTTP/SSH Access List to management-IP Address F5CAB1 Practice Questions (Page 2)
Part of the Identify management connectivity configurations domain, which makes up ~19% of our current practice bank. F5 does not publish an official question count, but from its 30-minute exam (~10–20 total, ~2–4 in this domain), expect 1–1 from this objective — we provide 13 practice questions to prepare you well beyond it. (estimate)
13questions here
3free pages
3concepts
Questions 6–10
- 6
Which command-line utility can be used to verify that a management access list is permitting traffic from a specific source IP?
Select an answer first - 7
A BIG-IP administrator is verifying that an HTTP access list is correctly enforcing a security policy. The access list allows 10.0.0.0/8 and denies all others. The administrator tests HTTPS from 10.1.1.1 and is able to connect, and tests from 192.168.1.1 and is blocked. What additional verification should the administrator perform to ensure the access list is working as intended?
Select an answer first - 8
A security policy requires that only the IT department's subnet (10.50.0.0/16) can access the BIG-IP management interface via SSH. The administrator configures an SSH access list with an allow rule for 10.50.0.0/16 and a deny-all rule. After binding the list, the administrator tests SSH from a host at 10.50.1.10 and is able to connect. What is the next step to fully verify the access list is working as intended?
Select an answer first - 9
An administrator has configured an HTTP access list to allow only 10.0.0.0/8 for management access. After binding the list, the administrator tests from a host at 10.1.1.1 and is able to access the web UI. However, the administrator notices that the access list is not blocking traffic from 192.168.1.1. What is the most likely reason for this?
Select an answer first - 10
A BIG-IP administrator is deploying a new device in a shared colocation facility. The security team mandates that only the corporate jump host (IP 10.10.10.10) may reach the management interface over HTTPS, and all other sources must be blocked. The administrator creates an HTTP access list with a rule to allow 10.10.10.10 and a rule to deny all others. What additional configuration is required to ensure the access list is enforced for HTTPS management traffic?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by F5. “F5CAB1” is a trademark of its owner, used for identification only.