Exam F5CAB1 Topic 1 Question 26 Discussion
Actual exam question for F5's F5CAB1 exam
Question #: 26
Topic #: 1
Question #: 26
Topic #: 1
For security reasons, a BIG-IP Administrator needs to specify allowable IP ranges for access to the Configuration Utility (WebUI).
The exhibit shows the User Administration section of the Configuration Utility.

The administrator could not find any setting that explicitly restricts access to the Configuration Utility.
Which one of the following is a reason for that?
The exhibit shows the User Administration section of the Configuration Utility.

The administrator could not find any setting that explicitly restricts access to the Configuration Utility.
Which one of the following is a reason for that?
Suggested Answer: A Vote an answer
The screenshot shown is from the User Administration section of the BIG-IP GUI.
This section controls:
Root and Admin passwords
SSH Access
SSH IP Allow settings
However, it does not contain any controls for restricting access to the WebUI (TMUI). BIG-IP does not provide TMUI access restrictions from this part of the GUI.
Access to the web-based Configuration Utility is controlled by the httpd allow list, configured through TMSH:
tmsh modify /sys httpd allow { <IP/subnet> }
This setting is not displayed in the User Administration panel, and in many BIG-IP versions, the
httpd allow list is only configurable from the CLI, not the GUI.
Therefore, the administrator cannot find the setting in the screen shown because:
TMUI access restriction is not located in this GUI section
It must be configured using tmsh under /sys httpd allow
This is why Option A is correct.
This section controls:
Root and Admin passwords
SSH Access
SSH IP Allow settings
However, it does not contain any controls for restricting access to the WebUI (TMUI). BIG-IP does not provide TMUI access restrictions from this part of the GUI.
Access to the web-based Configuration Utility is controlled by the httpd allow list, configured through TMSH:
tmsh modify /sys httpd allow { <IP/subnet> }
This setting is not displayed in the User Administration panel, and in many BIG-IP versions, the
httpd allow list is only configurable from the CLI, not the GUI.
Therefore, the administrator cannot find the setting in the screen shown because:
TMUI access restriction is not located in this GUI section
It must be configured using tmsh under /sys httpd allow
This is why Option A is correct.
by Elliot at Oct 01, 2026, 06:12 AM
0
0
0
10
Comments
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Report Comment
Commenting
You can sign-up / login (it's free).