F5 304 Exam Overview:
| Certification Vendor: | F5 Networks |
|---|---|
| Exam Name: | BIG-IP APM Specialist |
| Exam Number: | 304 |
| Passing Score: | 245 / 350 |
| Exam Price: | USD 180 |
| Certificate Validity Period: | 2 years |
| Real Exam Qty: | 80 |
| Related Certifications: | F5 Certified Security Solutions Expert F5 Certified BIG-IP Administrator (F5-CA) |
| Exam Duration: | 90 minutes |
| Exam Format: | Scenario-based items, Multiple-choice questions |
| Available Languages: | English |
| Recommended Training: | Configuring BIG-IP Access Policy Manager (APM) F5 Official Exam Blueprint |
| Exam Registration: | F5 Certification Portal Pearson VUE Registration |
| Sample Questions: | F5 304 Sample Questions |
| Exam Way: | Proctored at Pearson VUE test centers; online proctoring available |
| Pre Condition: | Valid F5 Certified BIG-IP Administrator (F5-CA) certification (passed exams 101 and 201) |
| Official Syllabus URL: | https://education.f5.com/exams/big-ip-apm-specialist-304 |
F5 304 Exam Syllabus Topics:
| Section | Weight | Objectives |
|---|---|---|
| Topic 1: Endpoint Security and Inspection | 5% | - Endpoint checks, client-side policies and remediation - Mobile device management and secure access |
| Topic 2: Single Sign-On (SSO) and Federated Identity | 10% | - SAML, OAuth, OpenID Connect integration - SSO methods: form-based, header-based, Kerberos |
| Topic 3: Authentication, Authorization and Accounting (AAA) | 25% | - AAA protocols: LDAP, RADIUS, TACACS+, Active Directory - Authentication methods: local, remote, multi-factor, certificate-based - Authorization policies and attribute mapping |
| Topic 4: Access Policy Configuration and Management | 25% | - Policy agents, actions, expressions and branching logic - Session management, persistence and termination - Access Policy Editor and visual policy building |
| Topic 5: Access Services: Portal, Network and Application Access | 15% | - Portal Access configuration and customization - Application Access and resource publishing - Network Access (SSL VPN) and IP forwarding |
| Topic 6: BIG-IP APM Architecture and Functionality | 20% | - Core components and deployment models - Licensing and provisioning - Integration with TMOS and other BIG-IP modules |
F5 BIG-IP APM Specialist Sample Questions:
Question 1
What should be analyzed and correlated when troubleshooting a failure in BIG-IP APM to determine the root cause?
A. TCPdump data, APM log, and client-side error messages
B. EPSEC status codes, session timeouts, and access policy configurations
C. Session reports, session variables, and application response times
D. BIG-IP system logs, SSL handshake details, and virtual server configurations
Question 2
When integrating BIG-IP APM with an external vendor IdP, what is the purpose of the "Entity ID" or "Entity Identifier" used in the configuration?
A. It uniquely identifies the IdP and helps establish trust between SP and IdP.
B. It uniquely identifies the user within the IdP's user database.
C. It specifies the network address of the IdP's authentication service.
D. It contains the user's authentication credentials for SSO.
Question 3
When would you need to use a Layer 4 ACL in BIG-IP APM instead of a Layer 7 ACL?
A. When configuring IP Intelligence for GeoIP-based access controls
B. When inspecting application data and URL patterns
C. When filtering traffic based on source IP addresses only
D. When enforcing access policies based on user roles and groups
Question 4
When configuring a Kerberos SSO object, what is the primary requirement for the Service Principal Name (SPN)?
A. The SPN must contain the IP address of the Kerberos Key Distribution Center (KDC).
B. The SPN must be globally unique across all domains.
C. The SPN must be registered in Active Directory's Service Principal Name list.
D. The SPN must include the user's password for secure authentication.
Question 5
The Visual Policy Editor (VPE) in F5 BIG-IP APM is used for:
A. Creating and modifying access policies.
B. Configuring IP addresses and VLANs.
C. Monitoring real-time network traffic.
D. Installing and updating SSL certificates.
Solutions:
| Question 1 Answer: A | Question 2 Answer: A | Question 3 Answer: C | Question 4 Answer: C | Question 5 Answer: A |

We're so confident of our products that we provide no hassle product exchange.


By Joyce


