
F5 Certified Technology Specialist, BIG-IP APM
The F5 Certified Technology Specialist, BIG-IP APM certification validates your ability to implement, troubleshoot, and maintain BIG-IP Access Policy Manager (APM) across a variety of application environments. It focuses on authentication, authorization, and accounting (AAA) resources, SAML federation, access control lists, and single sign-on. Earning this credential demonstrates that you can secure and manage access to applications using F5's TMOS-based solutions.
760 practice questions · Updated 2026-07-30
4Domains
42Objectives
224Concepts
760Questions
304 Curriculum
Every domain, objective, and concept the 304 exam measures.
- APM's role in mitigating common attack vectors
- Cookie hijacking (front-end) mitigation
- Cookie hijacking (back-end) mitigation
- Denial of Service (DoS) attack mitigation
- Common authentication attack vectors
- Cookie function in browsers
- Comparison of authentication methods
- APM tool selection for attack mitigation
- Session cookie basics in APM
- Cookie domain and host attributes
- Multi-domain cookie handling
- Endpoint inspection requirements
- Password guessing attack mitigation
- Network Access Methods
- Portal Access Methods
- Access Management Methods
- Comparison of Access Methods
- Access method selection criteria
- Network communication requirements
- Security requirements for access methods
- Reporting requirements for access methods
- Pros and cons of access methods
- Client PC security permissions impact
- Use case mapping to access methods
- APM logging architecture
- Log message structure and fields
- Interpreting APM log events
- Logging levels and their implications
- Performance impact of logging
- Security implications of logging
- APM logging verbosity levels
- Selecting verbosity level for requirements
- Performance impact of extended logging
- Security and privacy in log settings
- APM-specific profile types
- Access profile assignment to virtual servers
- Connectivity profile usage
- Rewrite profile applicability
- VDI profile configuration
- Java support profile configuration
- Access method-based profile selection
- Profile combination and interaction
- Identify non-APM specific profiles
- Determine appropriate use cases for non-APM profiles
- Compare non-APM profiles with APM profiles
- Apply non-APM profiles in virtual server configuration
- Upload SSL certificate and key
- Select SSL profile type
- Assign SSL profile to virtual server
- SNAT fundamentals for Network Access
- SNAT requirements for VoIP traffic
- SNAT requirements for Active mode FTP
- SNAT requirements for Remote Desktop to Network Access Clients
- Troubleshooting failing connections with SNAT
- SNAT pool options comparison
- SNAT and access policy integration
- AAA profile types overview
- RADIUS AAA profile characteristics
- LDAP AAA profile characteristics
- TACACS+ AAA profile characteristics
- Active Directory AAA profile characteristics
- Local AAA profile characteristics
- Comparison of AAA profile types
- SSO Profile Types Overview
- APM SSO vs. External SSO
- Form-Based SSO
- HTTP Basic SSO
- Kerberos SSO
- NTLM SSO
- SAML SSO
- OAuth/OpenID Connect SSO
- Restrictions and Limitations of SSO Profiles
- Security Implications of SSO Profiles
- APM logging facilities
- Log message structure
- Data contained in APM logs
- Correlating logs with SSO events
- AAA profile overview
- HTTP Basic authentication
- Active Directory (AD) authentication
- LDAP authentication
- RADIUS authentication
- TACACS+ authentication
- Kerberos authentication
- RSA SecurID authentication
- SAML authentication
- OCSP responder
- CRLDP (CRL Distribution Point)
- High availability options for AAA profiles
- Authentication method comparison
- HTTPS authentication setup
- SSO profile overview
- HTTP Basic SSO profile
- NTLM SSO profile
- Kerberos SSO profile
- SAML SSO profile
- Forms-based SSO profile
- SSO performance issue identification
- SSO performance tuning configurations
- SAML federation configuration
- SAML use case scenarios
- Client certificate addition
- Client certificate removal
- Machine certificate addition
- Machine certificate removal
- Portal access functionality
- App tunnel functionality
- Network access functionality
- LTM+APM functionality
- APM device clients
- Edge Client component selection
- Network Access Deployment Options
- Application Access Configuration
- Application Tunnel Protocol Restrictions
- Java Support for RDP
- Portal Access Configuration
- Custom Rewrite Options
- Access method categories
- Network access method
- Portal access method
- Application access method
- LTM+APM integration
- Requirement analysis
- Layer 4 vs Layer 7 ACLs
- Static vs Dynamic ACLs
- ACL Processing Order
- Default ACL Action
- ACL Logging Options
- Resource types with automatic ACL creation
- ACL action types
- Function of allow action
- Function of continue action
- Function of discard action
- Function of reject action
- AD group mapping overview
- AD group retrieval
- Group mapping methods
- Configuration steps
- Troubleshooting group mapping
- APM session variables overview
- Session variable types and naming conventions
- Session variable access in VPE
- Variable Assign policy item
- Session variables in iRules
- Use the iRule event policy item in the VPE
- Access Policy modifications for authentication
- Access policy flow
- Branching logic
- Loops in access policies
- Macros in access policies
- When to use macros
- How to use macros
- Endpoint check types
- Configuring AV check
- Configuring registry check
- Configuring file check
- Configuring firewall check
- Configuring process check
- Configuring machine certification check
- Adding macro checks to a policy
- Adding authentication methods
- Endpoint check types
- Policy item categories
- Branch ending types
- Dashboard overview
- Statistics tab analysis
- ACL denied report interpretation
- Correlating performance data
- Safe upgrade procedure
- OPSWAT integration
- BIG-IP WebUI monitoring facilities
- Upgrade and device addition behavior
- Failover during upgrade
- Impact of client component upgrades on end users
- Impact of high availability failover during upgrades
- Session persistence across upgrades and failover
- Minimizing end-user disruption during upgrades
- Communication and planning for upgrade maintenance
- DNS Proxy Relay service
- Component Installer service for Windows
- User Logon Credentials Access Service for Windows
- Client certificate configuration process
- Client certificate subject interpretation
- Client certificate issuer interpretation
- Access resource types examples
- HTTPWatch capture basics
- Interpreting HTTPWatch trace data
- APM-related HTTP trace patterns
- SSO methods for APM-delivered web applications
- TCPDump basics
- TCPDump syntax and options
- Interpreting TCPDump output
- SSLDump basics
- SSLDump syntax and options
- Interpreting SSLDump output
- Selecting the appropriate capture utility
- Applying captures to APM troubleshooting
- APM log file structure
- Common APM error messages
- SSO log analysis
- Rewrite log analysis
- Login failure root cause determination
- Correlating log entries across modules
- Locate error codes
- APM logging services overview
- Configure and view APM logs
- Locate core files
- Use web engine trace
- Use F5 Troubleshooting Utility
- Use SessionDump
- Use ADTest tool
- Use LDAP search
- HTTP request analysis for authentication
- Client-to-APM authentication troubleshooting
- APM-to-AAA authentication troubleshooting
- APM-to-SSO authentication troubleshooting
Ready to practice?Test your knowledge with exam-style questions or take an intelligent quiz tailored to your level.
Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for 304, so none is invented.