F5 Networks BIG-IP Administration Data Plane Concepts F5CAB2 Exam Questions

Page: 1 / 14
Total 66 questions
Question 1

An application is configured so that the same pool member must be used for an entire session, as well as for HTTP and FTP traffic. A user reports that a session has terminated, and the user must restart the session. The BIG-IP Administrator determines that the active BIG-IP device failed over to the standby BIG-IP device. Which configuration settings should the BIG-IP Administrator verify to ensure proper behavior when BIG-IP failover occurs?



Answer : D

In this scenario, two specific High Availability and Persistence requirements must be met to ensure session continuity during a failover.

Persistence Mirroring: By default, persistence records (which map a client to a specific server) exist only on the memory of the active BIG-IP. If a failover occurs, the standby unit has no knowledge of these sessions and will re-load-balance the client, likely to a different server. Enabling Persistence Mirroring ensures that the persistence table is synchronized in real-time to the standby peer.

Match Across Services: The requirement specifies that the session must persist across both HTTP and FTP. These are different Virtual Servers (and likely different ports). The Match Across Services setting in the persistence profile allows the BIG-IP to use the same persistence record for any Virtual Server that shares the same IP address and pool, regardless of the service port.


Question 2

The BIG-IP Administrator needs to ensure that if a pool member is marked down by the monitor, the BIG-IP system sends existing connections to another available pool member. Which task should the BIG-IP Administrator perform to meet this goal?



Answer : D

By default, when a pool member is marked 'down' by a monitor, the BIG-IP system stops sending new connections to that member, but it typically allows existing connections to time out naturally (or resets them depending on profile settings).

Action on Service Down: This setting is configured at the Pool level.

Reselect: When set to Reselect, if a pool member is marked down, the BIG-IP system will immediately attempt to pick a different available pool member for any existing, active connections associated with the failed member.

Client Experience: This is used to maintain the user session by transparently moving the traffic to a healthy server without the client needing to re-establish the connection to the Virtual Server.


Question 3

A BIG-IP Administrator has a cluster of devices. What should the administrator do after creating a new Virtual Server on device 1?



Answer : D

F5 BIG-IP uses a ConfigSync mechanism to ensure that all members of a Device Service Cluster (DSC) share the same configuration.

Manual Synchronization: By default, configuration changes made on one device (the 'source') do not automatically propagate to other members.

Direction of Sync: Once a Virtual Server is created on device 1, that device's configuration is now 'newer' than the rest of the group. The administrator must initiate a synchronization from the modified device (device 1) to the Sync-Failover group.

Consistency: This ensures that if a failover occurs, device 2 (the standby) will have the exact same Virtual Server configuration and can take over traffic immediately without interruption.


Question 4

What type of Virtual Server is configured with no Pool-members, and proxies traffic to the destination IP address specified by the client device?



Answer : A

A Forwarding (IP) virtual server is unique because it does not perform load balancing in the traditional sense.

No Pool Members: Unlike a Standard virtual server, which requires a pool to direct traffic, a Forwarding (IP) virtual server typically has no pool assigned.

Destination-Based Routing: The BIG-IP system looks at the destination IP address in the original packet header sent by the client. It then consults the BIG-IP system's local routing table to determine where to send the packet.

Transparency: It acts as a high-performance router/gateway, often used to forward traffic from internal servers to the internet or across different subnets while still allowing the BIG-IP to apply features like SNAT or bandwidth controllers.

Stateful Tracking: While it forwards traffic based on the routing table, it still creates an entry in the connection table to track the flow (unless it is a Stateless virtual server).


Question 5

When using the setup utility to configure a redundant pair, you are asked to provide a "Failover Peer IP". Which address is this?



Answer : B

When establishing a redundant pair, each device must know where to send its health heartbeats and sync data.

The Peer IP: The Failover Peer IP is the IP address belonging to the other BIG-IP device in the HA pair. This is typically a34 Self-IP on a dedicated 'HA' or 'Internal' VLAN, or the Management IP.

Purpose: It identifies the destination for the 'Heartbeat' (the 'Are you alive?' check).

Setup Context: During the initial setup, you tell Device A to look for Device B at its 'Failover Peer IP,' and you tell Device B to look for Device A at its respective 'Failover Peer IP.'


Question 6

A BIG-IP Administrator configures remote authentication and needs to make sure that users can still login even when the remote authentication server is unavailable. Which action should the BIG-IP Administrator take in the remote authentication configuration to meet this requirement?



Answer : D

The BIG-IP system supports various remote authentication methods like LDAP, Active Directory, and RADIUS.

Fallback to Local: This is a specific security and availability feature within the System > Users > Authentication configuration.

Redundancy: When 'Fallback to Local' is enabled, the BIG-IP will first attempt to authenticate a user against the configured remote server. If that remote server is unreachable or fails to respond, the system will then check its internal Local User database for credentials.

Administrative Access: This is standard practice for the 'admin' or emergency accounts to ensure the system remains accessible even if the corporate directory service (e.g., AD) is offline.


Question 7

and their status/statistics]

A BIG-IP Administrator wants to add a new Self IP to the BIG-IP device. Which item should be assigned to the new Self IP being configured?



Answer : B

A Self IP is an IP address on the BIG-IP system that you associate with a specific VLAN.

VLAN Association: A Self IP cannot exist independently; it must be bound to a VLAN to define which network segment the BIG-IP can communicate with.

Layer 2 to Layer 3 Mapping: While a VLAN is associated with physical interfaces or trunks (Layer 2), the Self IP provides the Layer 3 identity for the BIG-IP on that VLAN.

Traffic Processing: Self IPs are used by the BIG-IP for health checking backend servers, acting as a default gateway for servers, and for HA heartbeat communication.


Page:    1 / 14   
Total 66 questions