Key details for this exam, checked against the published exam outline
Each question shows the correct answer and an explanation of why it is right
A user needs to generate a QKView to upload to iHealth to determine any issues with upgrading TMOS. Where can the user generate the QKView in the Configuration Utility?
Generating a QKView is a standard procedure for identifying device health and upgrade readiness42. Within the Configuration Utility, this Control Plane diagnostic tool is located under System > Support43. This utility collects configuration and state data into a single file used by the iHealth 'Upgrade Advisor' to report on known bugs or compatibility issues prior to a version change.
Administrative user accounts have been defined on the remote LDAP server and are unable to log in to the BIG-IP device. Which log file should the BIG-IP Administrator check to find the related messages?28
Comprehensive and Detailed Explanation From BIG-IP A34dministration Control Plane Administration documents: Authentication and authorization events are handled by the system's PAM (Pluggable Authentication Modules). For Control Plane security auditing, all login attempts---whether local or remote (LDAP/RADIUS/TACACS+)---and SSH-related security events are recorded in /var/log/secure. This is the primary log for troubleshooting administrative access issues
A BIG-IP Administrator needs to check the memory utilization on a BIG-IP system. Which two methods can the BIG-IP Administrator use? (Choose two.)
Reporting device status includes monitoring physical resource exhaustion, such as memory. The Control Plane provides both a command-line method via TMSH (show /sys memory) and a graphical method under Statistics > Module Statistics > Memory to report on how memory is allocated across TMM and the Linux host494949494949494949. This is essential for identifying potential 'Aggressive Mode' triggers or hardware performance bottlenecks50.
The BIG-IP Administrator suspects unauthorized SSH login attempts on the BIG-IP system.
Which log file would contain details of these attempts? (Choose one answer)
On BIG-IP systems, authentication and authorization events are logged in /var/log/secure. This includes:
Successful and failed SSH login attempts
Invalid user authentication attempts
PAM (Pluggable Authentication Module) authentication failures
Access denials related to secure services
Why the other options are incorrect:
/var/log/messages contains general system messages and service events, not detailed authentication failures.
/var/log/audit records administrative configuration changes (who changed what and when), not login attempts.
/var/log/ltm logs traffic-management (TMM) and application-related events.
Therefore, the correct log file for investigating unauthorized SSH login attempts is /var/log/secure.
A BIG-IP Administrator must determine if a Virtual Address is configured to fail over to the standby member of a device group. In which area of the Configuration Utility can this be confirmed?
To re27port the current status of high availability for specific traffic, an administrator must verify the Traffic Group association28. In the Configuration Utility, Virtual Server properties include the Virtual Address settings where the 'Traffic Group' is assigned29292929. If the Virtual Address is assigned to a floating traffic group (like traffic-group-1), it is configured to fail over to the standby member30303030.
When looking at this BIG-IP prompt: root@virtual-bigip1] Peer Time Out of Sync
What does the message indicate? (Choose one answer)
On BIG-IP systems that participate in a Device Service Cluster (DSC), each device compares the remote device's system time to its own system time. If the difference is outside the ConfigSync time threshold (commonly referenced as 3 seconds by default), BIG-IP updates the shell prompt to show ''Peer Time Out of Sync'', and ConfigSync operations may fail until time is corrected (typically by fixing NTP reachability/configuration, or in some cases adjusting the threshold). (cdn.studio.f5.com)
This message is specifically about time drift between peers in the trust domain/DSC---not basic reachability (so B is not what it means), and it does not prove which side is ''correct'' (so C is too specific). It also doesn't directly mean an NTP source is ''skewed'' (A can be a cause, but the prompt message itself indicates the peer-to-peer time mismatch condition). (cdn.studio.f5.com)
Exam domains verified against: Official F5 Networks F5CAB4 exam guide, last checked October 2026.
Execute force to standby and force to offline procedures to control device state during maintenance. Learn to report current active and standby failover state and verify device trust status in a clustered environment.
Sample question from this domain above: Q5
Locate and interpret the configured management IP address and port lockdown settings. Diagnose management interface connectivity issues and configure HTTP and SSH access controls.
Sample question from this domain above: Q4
Use the LCD panel, dashboard, and network map to assess system health and object status. Interpret high availability and device trust status through both GUI and TMSH command line.
Sample question from this domain above: Q3
Locate relevant events in /var/log/ltm, /var/log/secure, and /var/log/audit. Identify severity levels and interpret log messages to troubleshoot system events.
Execute UCS backup and restore procedures for disaster recovery. Understand what is contained in UCS files, including private keys, and how to store backups securely for long-term retention.
Create and modify local user accounts with appropriate roles and permissions. Configure remote authentication providers and manage user groups for scalable access control.
Sample question from this domain above: Q2
Verify proper configuration of DNS, NTP, SNMP, and syslog services on the BIG-IP system. Ensure time synchronization and centralized logging for operational visibility.
Sample question from this domain above: Q6
Execute configuration synchronization between devices in a Device Service Cluster. Identify when sync is necessary and interpret sync status and configuration timestamp differences.
Assess when to upgrade BIG-IP software or platform firmware based on operational requirements. Plan upgrade procedures to minimize downtime in production environments.
Sample question from this domain above: Q1
Compare active versus inactive Application Delivery Controller elements using netstat output. Determine if services are listening on expected ports and assess overall service health.
Common questions about the exam itself