What is the tmsh command to list the IP ranges that can access the management interface via SSH? (Choose one answer)
Answer : B
On BIG-IP systems, SSH access restrictions are configured under the /sys sshd object. The allow property defines the IP addresses or networks permitted to connect to the management interface using SSH.
The list command is used to display the current configuration settings.
Therefore, tmsh list /sys sshd allow correctly displays the configured allowed IP ranges.
Why the other options are incorrect:
A (show) displays runtime or statistical information, not configuration values.
C and D incorrectly reference /etc/hosts.allow; BIG-IP manages SSH access through TMSH objects, not by directly listing host files in this context.
A BIG-IP Administrator plans to resolve a non-critical issue with a BIG-IP device in 2 weeks. What Severity level should be assigned to this type of F5 support ticket?
Answer : A
F5 Support uses a specific scale to categorize the urgency of technical issues, which helps the Control Plane management team prioritize resources effectively.
Severity 1 (Critical): Used for emergency situations where a production site is completely down, or there is a critical impact on business operations with no workaround available.
Severity 2 (High): Assigned when a system is severely degraded, or a primary function is significantly impacted, but the site remains operational in a degraded state.
Severity 3 (Medium): Applicable for issues where there is a partial loss of non-critical functionality, or the system is failing intermittently but the core business is not currently impacted.
Severity 4 (Low): This is the appropriate level for non-critical issues, general 'how-to' questions, or maintenance planning. Since the administrator plans to resolve this issue in two weeks, it falls under the category of a low-priority maintenance task that does not require an immediate response from F5 support.
A node is a member of various pools and hosts different web applications. If a web application is unavailable, the BIG-IP appliance needs to mark the pool member down for that application pool. What should a BIG-IP Administrator deploy at the pool level to accomplish this?
Answer : D
Comprehensive and Detailed Explanation From BIG-IP Administration Control Plane Admi13nistration documents:
To accurately report the current status of specific web applications hosted on the same server (node), the Control Plane must use a monitor that operates at the application layer.
Application-Specific Monitoring: While a node (the IP address) might be up and responding to ICMP (ping) or TCP handshakes, a specific web service or path on that server could be failing.
Custom Send Strings: An HTTP monitor allows the administrator to define a 'Send String' to request a specific page or URI related to the application in that pool .
Receive Strings: The 'Receive String' identifies a unique value that the application must return to be considered 'Available' .
Granular Status Reporting: By deploying these monitors at the pool level, the Control Plane can mark a pool member 'Offline' for one application pool if the receive string is missing, while keeping it 'Available' in another pool where the service is still healthy.
In which of the following log files would log events pertaining to pool members being marked ''UP'' or ''DOWN'' by their Health Monitors be written? (Choose one answer)
Answer : B
On BIG-IP systems, Local Traffic Manager (LTM) is responsible for:
Pool and pool member management
Health monitor execution
Marking pool members UP or DOWN based on monitor results
Events related to health monitor status changes, including when pool members transition between UP and DOWN, are logged in /var/log/ltm.
Why the other options are incorrect:
/var/log/audit records administrative configuration changes, not runtime health status.
/var/log/secure logs authentication and authorization events.
/var/log/monitors is not a standard BIG-IP log file.
Therefore, the correct log file for pool member health monitor status events is /var/log/ltm.
New Syslog servers have been deployed in an organization. The BIG-IP Administrator must reconfigure the BIG-IP system to send log messages to these servers. In which location in the Configuration Utility can the BIG-IP Administrator make the needed configuration changes to accomplish this?
Answer : A
Managing how a BIG-IP communicates with external management services like Syslog is a core Control Plane task. The Configuration Utility organizes these settings under the 'System' menu. Specifically, to define remote logging destinations and formats, the administrator must navigate to System > Logs > Configuration to ensure the Control Plane correctly forwards system events to external collectors
A BIG-IP Administrator needs to restore an encrypted UCS archive from the command line using the TMSH utility. Which TMSH command should the BIG-IP Administrator use to accomplish this?
Answer : D
Restoring system states from backups is a fundamental Control Plane administrative task2. When a User Configuration Set (UCS) archive is created with encryption, it requires the correct passphrase to be decrypted and loaded during the restoration process.
UCS Command Structure: The tmsh load /sys ucs command is the specific utility for restoring these comprehensive configuration archives.
Encrypted Restores: If the archive was encrypted during creation, the passphrase argument must be appended to the command followed by the actual password used to encrypt the file.
Comparison with Other Options:
load /sys config file is used for loading text-based configuration files (like bigip.conf), not full UCS archives6.
The no-license flag is used when you want to restore a configuration without overwriting the existing license (common during RMA replacements), but it does not provide the mechanism for entering an encryption passphrase.
A BIG-IP Administrator discovers malicious brute-force attempts to access the BIG-IP device on the management interface via SSH. The BIG-IP Administrator needs to restrict SSH access to the management interface. Where should this be accomplished?
Answer : D
The 'Management Port' is distinct from TMM data ports. Configuration for global platform-level settings, including administrative access restrictions (IP Allow lists for SSH and HTTPS) for the management port, is found under System > Platform. This is a critical Control Plane hardening step to prevent unauthorized remote access
Here is the next batch of 10 questions from your document that are 100% related to BIG-IP