
F5 Certified Administrator, BIG-IP
The F5 BIG-IP Administration Control Plane Administration exam validates your ability to perform day-to-day operations and basic deployment, management, security, and support of BIG-IP in various application environments. It focuses on control plane tasks such as managing high availability pairs, authentication, system services, and UCS archives. Earning this certification demonstrates your competence in administering BIG-IP systems.
661 practice questions · Updated 2026-07-30
10Domains
38Objectives
182Concepts
661Questions
F5CAB4 Curriculum
Every domain, objective, and concept the F5CAB4 exam measures.
- Understanding force to standby
- Prerequisites for force to standby
- Executing force to standby via CLI
- Executing force to standby via GUI
- Verifying standby state
- Impact on active traffic
- Identify failover state indicators
- Interpret failover state output
- Verify failover state consistency
- Force to offline procedure overview
- Preconditions for force to offline
- Executing force to offline via CLI
- Executing force to offline via GUI
- Verifying offline state
- Impact on traffic and failover
- Recovery and returning to active
- Device trust status overview
- Viewing device trust status via CLI
- Viewing device trust status via GUI
- Interpreting device trust status output
- Troubleshooting device trust issues
- Management IP address definition
- Locating management IP configuration
- Verifying management IP address
- Port lockdown basics
- Default port lockdown settings
- Port lockdown options
- Configuring custom port lockdown
- Interpreting port lockdown effects
- Troubleshooting port lockdown
- Identify management interface connectivity
- Recognize remote connectivity methods
- Determine management IP address
- Verify remote connectivity
- Management IP address configuration
- Management interface and network isolation
- Common management connectivity issues
- Diagnostic tools for management connectivity
- Impact of routing and VLANs on management access
- Management access via self-IP vs. management IP
- HTTP access list configuration
- SSH access list configuration
- Management IP address identification
- Access list enforcement and verification
- LCD panel warning message types
- Interpreting warning message content
- Responding to LCD warnings
- Dashboard Overview
- System Status Indicators
- Traffic and Performance Metrics
- Alerts and Notifications
- Resource Utilization
- Dashboard Customization
- Accessing the Network Map
- Interpreting object status indicators
- Identifying object types on the Network Map
- Reporting device status from the Network Map
- Identify current device status via GUI
- Identify current device status via TMSH
- Report current device status
- High availability status indicators
- Device trust status indicators
- Interpreting HA status output
- Interpreting device trust status output
- Correlating HA and device trust status
- Purpose of /var/log/ltm
- Purpose of /var/log/secure
- Purpose of /var/log/audit
- Locating log files
- Severity log levels
- Mapping events to severity levels
- Reading log entries
- Log message structure
- Event classification
- Event severity levels
- Event source identification
- Event correlation
- UCS backup overview
- Pre-backup checks
- Initiating UCS backup via CLI
- Initiating UCS backup via GUI
- Verifying UCS backup success
- Managing UCS backup files
- Restoring from a UCS archive
- UCS restore prerequisites
- UCS restore procedure steps
- Post-restore verification
- Restore failure handling
- Purpose of UCS backup
- Scenarios for UCS backup
- Scope of UCS backup
- UCS backup file characteristics
- Storage media requirements
- Storage location considerations
- Backup file naming and versioning
- Retention policy definition
- Integrity verification for long-term storage
- Documentation and labeling
- UCS file structure
- Private keys in UCS
- Key types and formats
- Key security considerations
- User creation prerequisites
- User creation methods
- User attributes configuration
- User role assignment
- User authentication settings
- User account verification
- User property overview
- Modifying user properties via GUI
- Modifying user properties via CLI
- Password policy enforcement
- Partition and role assignment
- User account status management
- Remote Authentication Provider Options
- Configuration of Remote Authentication Providers
- Authentication Flow and Fallback
- Troubleshooting Remote Authentication
- Remote authentication provider groups
- Group mapping and membership
- Group-based access control
- Configuration of group support
- DNS configuration
- NTP configuration
- SNMP configuration
- syslog configuration
- Identify prerequisites for config sync
- Initiate config sync from the UI
- Initiate config sync from the CLI
- Verify sync status
- Troubleshoot common sync failures
- Identify config sync error types
- Interpret config sync error messages
- Troubleshoot config sync errors
- Report config sync errors
- Identify scenarios requiring config sync
- Understand the role of config sync in high availability
- Differentiate config sync from other synchronization mechanisms
- Recognize triggers for automatic config sync
- Determine when manual config sync is required
- Config sync status overview
- Viewing config sync status via CLI
- Viewing config sync status via GUI
- Interpreting sync status values
- Troubleshooting sync status issues
- Configuration timestamp definition
- Timestamp comparison purpose
- Timestamp display in UI
- Timestamp interpretation
- Timestamp and sync status
- Upgrade eligibility criteria
- Supported upgrade paths
- Pre-upgrade checks
- End-of-life and end-of-support considerations
- License and feature compatibility
- Upgrade eligibility criteria
- End-of-life and end-of-support status
- Hardware compatibility
- Licensing and feature availability
- Upgrade path and version constraints
- Platform-specific limitations
- Pre-upgrade preparation
- Backup and snapshot procedures
- Upgrade path planning
- Minimizing traffic disruption
- Post-upgrade verification
- Active vs inactive ADC elements
- Identifying active elements
- Identifying inactive elements
- Interpreting service status
- Comparing active and inactive states
- Reading netstat output
- Interpreting TCP connection states
- Mapping ports to services
- Inferring service status from connections
- netstat output basics
- listening state recognition
- port and address parsing
- matching service to port
- IPv4 and IPv6 handling
- TCP and UDP considerations
- netstat command variations
Ready to practice?Test your knowledge with exam-style questions or take an intelligent quiz tailored to your level.
Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for F5CAB4, so none is invented.