F5CAB1 Exam Questions 2026 – Real Practice Test with Verified Answers

Home / F5 / F5CAB1

Latest F5CAB1 Exam Practice Questions

The practice questions for F5CAB1 exam was last updated on 2026-05-25 .

Viewing page 1 out of 1 pages.

Viewing questions 1 out of 6 questions.

Question#1

Which port is an exception to the Port Lockdown function of Self-IPs if a device-group synchronization cluster is configured?

A. TCP 443
B. TCP 4353
C. UDP 53

Explanation:
Self-IPs implement a security feature known as Port Lockdown, which limits which services are reachable on a Self-IP.
However, certain services required for BIG-IP device-to-device communication bypass Port Lockdown to ensure cluster and HA functionality.
TCP 4353
TCP port 4353 is used by Device Service Clustering (DSC) for:
Device trust establishment
Configuration synchronization
Failover communication
Because BIG-IP devices must always be able to communicate for HA functions to remain operational, port 4353 is exempt from Port Lockdown rules.
Why the other options are incorrect
A. TCP 443
Not required for device trust or synchronization.
HTTPS access is fully controlled by Port Lockdown.
C.UDP53
DNS traffic is not required for synchronization and has no exemption under Port Lockdown.

Question#2

The Port Lockdown feature prevents unwanted connection attempts to a Self IP.
Which three types of connection attempts are unaffected by Port Lockdown settings?

A. Defined virtual server traffic, Secure Shell (SSH), Centralized Management Infrastructure (CMI)
B. Centralized Management Infrastructure (CMI), Secure Shell (SSH), Internet Control Message Protocol (ICMP)
C. Defined virtual server traffic, Internet Control Message Protocol (ICMP), Centralized Management Infrastructure (CMI)

Explanation:
Port Lockdown controls which ports and protocols a Self IP will respond to.
However, certain traffic types bypass Port Lockdown for BIG-IP functionality and routing integrity.
The three types that are NOT affected by Port Lockdown are:

Question#3

When is the License Service Check Date enforced on a BIG-IP system?

A. After editing a virtual server
B. During a software install
C. During system startup

Explanation:
The Service Check Date determines whether a particular software version is allowed to run under the device’s license.
When installing or upgrading TMOS, the installer checks the Service Check Date stored in the BIG-IP license file.
If the license date is older than the minimum required for the target version, the software installation is blocked.
This check happens specifically during a software install, not during routine device operations.
Editing virtual servers or system startup do not trigger this validation.
Thus, the enforcement happens during software installation.

Question#4

What will setting a Self IP to “Allow None” for Port Lockdown do?

A. Block HA communications, causing the systems to report their peer as offline and go active-active.
B. Block HA communications, causing the systems to report their peer as online ready.
C. Default allow port 1026 access between peer devices and traffic processing across the network failover.

Explanation:
The Port Lockdown feature controls which services a Self-IP will respond to.
Setting a Self-IP to Allow None means:
The Self-IP will not accept any traffic except the very limited, hard-coded HA ports such as TCP 4353 used for device trust and configuration sync.
All other HA ports, including those needed for network failover and other HA mechanisms, are blocked.
When essential HA services cannot communicate, each device assumes its peer is down.
This results in:
HA failover misbehavior
Both devices thinking the other is offline
Potential active-active condition, which is not intended and can cause traffic disruption Thus, Allow None can break HA functionality unless the Self-IP is not used for HA links.

Question#5

For an upgrade of a standalone BIG-IP, a maintenance window is available in which brief interruptions are allowed.
Actions with no impact can be done outside the maintenance window.
When should a license reactivation be performed?

A. During the maintenance window.
B. Before the maintenance window.
C. After the maintenance window.

Explanation:
License reactivation updates the BIG-IP device’s license file to ensure:
The Service Check Date is current
The device is eligible to install the intended TMOS version
Any module entitlement updates are received
Reactivation does not interrupt traffic and does not require a reboot, making it safe to perform before the maintenance window.
F5 best practices state:
Perform all non-impact tasks prior to the scheduled maintenance window
Leave the window available for activities that require rebooting, such as the software installation itself
Since license reactivation is non-disruptive, it should be done before the upgrade window starts.

Disclaimer

This page is for educational and exam preparation reference only. It is not affiliated with F5, F5-CA, or the official exam provider. Candidates should refer to official documentation and training for authoritative information.

Exam Code: F5CAB1Q & A:  42  Q&As Updated:  2026-05-25

  Get All F5CAB1 Q&As