Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
F5

F5 Certified Technology Specialist, BIG-IP APM

304

The F5 Certified Technology Specialist, BIG-IP APM certification validates your ability to implement, troubleshoot, and maintain BIG-IP Access Policy Manager (APM) across a variety of application environments. It focuses on authentication, authorization, and accounting (AAA) resources, SAML federation, access control lists, and single sign-on. Earning this credential demonstrates that you can secure and manage access to applications using F5's TMOS-based solutions.

760 practice questions · Updated 2026-07-30

4Domains
42Objectives
224Concepts
760Questions

304 Curriculum

Every domain, objective, and concept the 304 exam measures.

  1. Common authentication attack vectors
  2. Cookie function in browsers
  3. Comparison of authentication methods
  4. APM tool selection for attack mitigation
  1. Session cookie basics in APM
  2. Cookie domain and host attributes
  3. Multi-domain cookie handling
  4. Endpoint inspection requirements
  5. Password guessing attack mitigation
  1. Network Access Methods
  2. Portal Access Methods
  3. Access Management Methods
  4. Comparison of Access Methods
  1. Access method selection criteria
  2. Network communication requirements
  3. Security requirements for access methods
  4. Reporting requirements for access methods
  5. Pros and cons of access methods
  6. Client PC security permissions impact
  7. Use case mapping to access methods
  1. APM and VDI Integration
  2. Access Modes Comparison
  3. Deployment Configurations for Common Applications
  1. APM logging architecture
  2. Log message structure and fields
  3. Interpreting APM log events
  4. Logging levels and their implications
  5. Performance impact of logging
  6. Security implications of logging
  1. APM logging verbosity levels
  2. Selecting verbosity level for requirements
  3. Performance impact of extended logging
  4. Security and privacy in log settings

  1. APM-specific profile types
  2. Access profile assignment to virtual servers
  3. Connectivity profile usage
  4. Rewrite profile applicability
  5. VDI profile configuration
  6. Java support profile configuration
  7. Access method-based profile selection
  8. Profile combination and interaction
  1. Identify non-APM specific profiles
  2. Determine appropriate use cases for non-APM profiles
  3. Compare non-APM profiles with APM profiles
  4. Apply non-APM profiles in virtual server configuration
  1. Upload SSL certificate and key
  2. Select SSL profile type
  3. Assign SSL profile to virtual server
  1. SNAT fundamentals for Network Access
  2. SNAT requirements for VoIP traffic
  3. SNAT requirements for Active mode FTP
  4. SNAT requirements for Remote Desktop to Network Access Clients
  5. Troubleshooting failing connections with SNAT
  6. SNAT pool options comparison
  7. SNAT and access policy integration
  1. AAA profile types overview
  2. RADIUS AAA profile characteristics
  3. LDAP AAA profile characteristics
  4. TACACS+ AAA profile characteristics
  5. Active Directory AAA profile characteristics
  6. Local AAA profile characteristics
  7. Comparison of AAA profile types
  1. SSO Profile Types Overview
  2. APM SSO vs. External SSO
  3. Form-Based SSO
  4. HTTP Basic SSO
  5. Kerberos SSO
  6. NTLM SSO
  7. SAML SSO
  8. OAuth/OpenID Connect SSO
  9. Restrictions and Limitations of SSO Profiles
  10. Security Implications of SSO Profiles
  1. APM logging facilities
  2. Log message structure
  3. Data contained in APM logs
  4. Correlating logs with SSO events
  1. AAA profile overview
  2. HTTP Basic authentication
  3. Active Directory (AD) authentication
  4. LDAP authentication
  5. RADIUS authentication
  6. TACACS+ authentication
  7. Kerberos authentication
  8. RSA SecurID authentication
  9. SAML authentication
  10. OCSP responder
  11. CRLDP (CRL Distribution Point)
  1. High availability options for AAA profiles
  2. Authentication method comparison
  3. HTTPS authentication setup
  1. SSO profile overview
  2. HTTP Basic SSO profile
  3. NTLM SSO profile
  4. Kerberos SSO profile
  5. SAML SSO profile
  6. Forms-based SSO profile
  7. SSO performance issue identification
  8. SSO performance tuning configurations
  1. SAML federation configuration
  2. SAML use case scenarios
  1. Client certificate addition
  2. Client certificate removal
  3. Machine certificate addition
  4. Machine certificate removal
  1. Portal access functionality
  2. App tunnel functionality
  3. Network access functionality
  4. LTM+APM functionality
  5. APM device clients
  6. Edge Client component selection
  1. Network Access Deployment Options
  2. Application Access Configuration
  3. Application Tunnel Protocol Restrictions
  4. Java Support for RDP
  5. Portal Access Configuration
  6. Custom Rewrite Options
  1. Access method categories
  2. Network access method
  3. Portal access method
  4. Application access method
  5. LTM+APM integration
  6. Requirement analysis
  1. Layer 4 vs Layer 7 ACLs
  2. Static vs Dynamic ACLs
  3. ACL Processing Order
  4. Default ACL Action
  5. ACL Logging Options
  1. ACL action types
  2. Function of allow action
  3. Function of continue action
  4. Function of discard action
  5. Function of reject action
  1. AD group mapping overview
  2. AD group retrieval
  3. Group mapping methods
  4. Configuration steps
  5. Troubleshooting group mapping
  1. APM session variables overview
  2. Session variable types and naming conventions
  3. Session variable access in VPE
  4. Variable Assign policy item
  5. Session variables in iRules
  6. Use the iRule event policy item in the VPE
  7. Access Policy modifications for authentication
  1. Access policy flow
  2. Branching logic
  3. Loops in access policies
  4. Macros in access policies
  5. When to use macros
  6. How to use macros
  1. Endpoint check types
  2. Configuring AV check
  3. Configuring registry check
  4. Configuring file check
  5. Configuring firewall check
  6. Configuring process check
  7. Configuring machine certification check
  8. Adding macro checks to a policy
  9. Adding authentication methods
  1. Endpoint check types
  2. Policy item categories
  3. Branch ending types

  1. Dashboard overview
  2. Statistics tab analysis
  3. ACL denied report interpretation
  4. Correlating performance data
  1. Safe upgrade procedure
  2. OPSWAT integration
  3. BIG-IP WebUI monitoring facilities
  4. Upgrade and device addition behavior
  5. Failover during upgrade
  1. Impact of client component upgrades on end users
  2. Impact of high availability failover during upgrades
  3. Session persistence across upgrades and failover
  4. Minimizing end-user disruption during upgrades
  5. Communication and planning for upgrade maintenance

  1. DNS Proxy Relay service
  2. Component Installer service for Windows
  3. User Logon Credentials Access Service for Windows
  1. Client certificate configuration process
  2. Client certificate subject interpretation
  3. Client certificate issuer interpretation
  4. Access resource types examples
  1. HTTPWatch capture basics
  2. Interpreting HTTPWatch trace data
  3. APM-related HTTP trace patterns
  4. SSO methods for APM-delivered web applications
  1. TCPDump basics
  2. TCPDump syntax and options
  3. Interpreting TCPDump output
  4. SSLDump basics
  5. SSLDump syntax and options
  6. Interpreting SSLDump output
  7. Selecting the appropriate capture utility
  8. Applying captures to APM troubleshooting
  1. APM log file structure
  2. Common APM error messages
  3. SSO log analysis
  4. Rewrite log analysis
  5. Login failure root cause determination
  6. Correlating log entries across modules
  1. HTTP request analysis for authentication
  2. Client-to-APM authentication troubleshooting
  3. APM-to-AAA authentication troubleshooting
  4. APM-to-SSO authentication troubleshooting
Ready to practice?Test your knowledge with exam-style questions or take an intelligent quiz tailored to your level.

Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for 304, so none is invented.