Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
F5

F5 Certified Technology Specialist, BIG-IP APM

304

The F5 Certified Technology Specialist, BIG-IP APM certification validates your ability to implement, troubleshoot, and maintain BIG-IP Access Policy Manager (APM) across a variety of application environments. It focuses on authentication, authorization, and accounting (AAA) resources, SAML federation, access control lists, and single sign-on. Earning this credential demonstrates that you can secure and manage access to applications using F5's TMOS-based solutions.

Exam formatProctored exam
Duration90 minutes
DeliveryPearson VUE
Passing score245
Free questions760

Content last reviewed 30 July 2026 · Up to date

The certification

What 304 proves, and what it asks of you

What this certification covers, who it is written for, and what the exam itself looks like on the day.

4domains
42objectives
224concepts
US $180exam fee
What it is

What this certification is

What it validates, who it is written for, and the experience it assumes.

About this certification

The F5 Certified Technology Specialist, BIG-IP APM certification validates the skills and understanding required for day-to-day management of application delivery networks that incorporate technologies based on the TMOS operating system. It emphasizes the implementation, troubleshooting, and maintenance of BIG-IP APM in various application environments, with special focus on different types of authentication, authorization, and accounting resources.

Candidates who earn this certification demonstrate proficiency in configuring SAML federation, defining Layer 4 and Layer 7 access control lists, applying single sign-on profiles, and understanding all access policy modes. This credential is a prerequisite for the Security Solutions Expert certification track, making it a foundational step for professionals pursuing advanced security expertise.

Who it’s for

This certification is for network and security professionals who manage application delivery networks and need to implement, troubleshoot, and maintain BIG-IP APM in a variety of application environments. It is ideal for those who work with authentication, authorization, and accounting resources, SAML federation, and access control. The minimally qualified candidate is proficient in various authentication mechanisms used to provide security and access management for different types of applications, and can configure, implement, troubleshoot, and maintain BIG-IP APM without assistance.

Recommended experience

F5 recommends that candidates have a valid F5-CA, BIG-IP certification and hands-on experience with BIG-IP APM in production environments. Experience with BIG-IP LTM and APM modules; Understanding of authentication, authorization, and accounting (AAA) resources; Familiarity with SAML federation and single sign-on concepts; Knowledge of access control lists and portal objects

The syllabus

What you’ll learn

Every domain and objective F5 measures, with the weight they carry on the exam.

The official F5 exam outline · checked 30 July 2026 · See the source

Section 1: Assess security needs and requirements to create an APM policy
  • Objective 1.01 Explain how APM mitigates common attack vectors and methodologies (e.g., cookie hijacking [front and back], DoS attack)
  • Objective 1.02 Identify which APM tool(s) should be used to mitigate a specific authentication attack
  • Objective 1.03 Explain how APM uses and manages session cookies (domain, host, multi-domain)
  • Objective 1.04 Explain the differences among access methods (e.g., network, portal, access management)
  • Objective 1.05 Determine the appropriate access method for a use case or set of requirements
  • Objective 1.06 Explain how APM interacts with commonly used applications (e.g., Microsoft Exchange, Citrix, VMware View, SharePoint)
  • Objective 1.07 Explain the differences among logging levels (e.g., performance implications, security implications, information provided)
  • Objective 1.08 Determine appropriate logging methods and verbosity levels to meet specified requirements
8 objectives · 131 free questions · 30 pages
Section 2: Configure and deploy an access profile
  • Objective 2.01 Determine the circumstances under which it is appropriate to use an APM specific profile (i.e., access, connectivity, rewrite, VDI and Java support)
  • Objective 2.02 Determine the circumstances under which it is appropriate to use a non-APM specific profile (e.g., ServerSSL, Web Acceleration, Compression)
  • Objective 2.03 Explain how to create and assign an SSL profile
  • Objective 2.04 Determine appropriate SNAT settings to meet access requirements for Network Access (e.g., VoIP, Active mode FTP, Remote Desktop to Network Access Clients)
  • Objective 2.05 Explain the characteristics (e.g., pros and cons, restrictions, security implications, HA setup) of available AAA profiles
  • Objective 2.06 Explain the characteristics (e.g., pros and cons, restrictions, security implications) of available SSO profiles
  • Objective 2.07 Explain the implications of passwordless authentication options in APM and how they affect SSO (e.g., SAML, Client certificate, NTLM-end-user)
  • Objective 2.08 Explain how to configure AAA profiles (e.g., HTTP Basic, AD, LDAP, Radius, TACACS, KERBEROS, RSA, SAML, OCSP, CRLDP)
  • Objective 2.09 Explain techniques to simultaneously configure multiple AAA profiles ( e.g., two-factor)
  • Objective 2.10 Explain how to configure SSO profiles (e.g., HTTP Basic, NTLM, KERBEROS, SAML, Forms)
  • Objective 2.11 Explain how to configure SAML use cases (e.g., IDP, SP, IDP-initiated, SP-initiated)
  • Objective 2.12 Describe how to add and remove client and machine certificates
  • Objective 2.13 Determine appropriate deployment option(s) to meet network access requirements (e.g., standalone edge client, browser components, mobile apps)
  • Objective 2.14 Explain how to configure access methods (e.g., network [SNAT vs. Routed Mode], portal [rewrite options], application, app tunnel, LTM+APM)
  • Objective 2.15 Determine appropriate access methods (e.g., network, portal, application, LTM+APM) to meet requirements
  • Objective 2.16 Explain how to configure and assign ACLs (e.g., L4, L7, static, dynamic, default action, iRule events, logging options)
  • Objective 2.17 Identify resource types for which associated ACLs are automatically created (e.g., remote desktop, portal access, application tunnels)
  • Objective 2.18 Describe the ACL action types and their functions (e.g., allow, continue, discard, reject)
  • Objective 2.19 Describe methods to map Microsoft Active Directory groups to assigned resources
  • Objective 2.20 Explain the use of APM session variables (e.g., session flow, use in iRules, variable assign policy item)
  • Objective 2.21 Explain access policy flow and logic (i.e., branching, loops, macros [when and how to use them])
  • Objective 2.22 Describe the use and configuration of endpoint checks (e.g., registry check, process check, Windows info, machine cert auth)
  • Objective 2.23 Describe customization options for an access policy (logon page, webtop, network access, language)
23 objectives · 425 free questions · 96 pages
Section 3: Maintain APM access profiles
  • Objective 3.01 Interpret device performance information (e.g., dashboard, statistics tab, ACL denied report)
  • Objective 3.02 Identify necessary software maintenance procedures to address a given condition
  • Objective 3.03 Determine how upgrades on production systems affect end users (e.g., client components and high availability failover)
3 objectives · 65 free questions · 14 pages
Section 4: Identify and resolve APM issues
  • Objective 4.01 Explain the purpose and function of client side components (e.g., DNS Proxy Relay service, Component Installer service for Windows, User Logon Credentials Access Service for Windows)
  • Objective 4.02 Interpret client and machine certificates (e.g., subject, issuer)
  • Objective 4.03 Interpret an HTTP protocol trace collected with a client side tool (e.g., HTTPWatch, Fiddler, Paros, Live Headers)
  • Objective 4.04 Explain how to use capture utilities (e.g., SSLDump and TCPDump)
  • Objective 4.05 Analyze and interpret APM-specific log files (e.g., APM, SSO, rewrite)
  • Objective 4.06 Describe the use of built-in trouble-shooting tools (e.g., web engine trace, F5 Troubleshooting Utility, SessionDump, ADTest tool, LDAP search)
  • Objective 4.07 Diagnose and resolve authentication issues (e.g., client>APM, APM>AAA, APM>SSO)
  • Objective 4.08 Diagnose and resolve client side issues related to connections, performance, and endpoint inspection
8 objectives · 139 free questions · 31 pages
On the day

The exam itself

Everything F5 publishes about sitting it, and nothing we inferred.

Prerequisites

Valid F5-CA, BIG-IP certification

Exam code304
CertificationF5 Certified Technology Specialist, BIG-IP APM
Exam formatProctored exam
Duration90 minutes
Passing score245
DeliveryPearson VUE
LanguagesEnglish
PricingUS $180
After you pass

Where this credential goes next

The path F5 lays out, how the credential is kept, and where to book.

Step-by-step path to F5 Certified Technology Specialist, BIG-IP APM

PrerequisiteValid F5-CA, BIG-IP certification
F5 Certified Technology Specialist, BIG-IP APM badgeCredential earnedF5 Certified Technology Specialist, BIG-IP APM Certification
Lifecycle status

This certification is currently active and available. F5 maintains this certification to validate current skills and industry relevance.

Exam status: ActiveMaintained by F5

Exam registration

Register for the exam through Pearson VUE, F5’s authorized testing partner.

Schedule your exam

Visit the official F5 certification page for exam policies and requirements.

View the official page
Your coach

And when you are serious, your coach Pip takes over

Your coach in the app reads what you have answered with the book closed and tells you one thing to do tonight. It will not count an answer you gave with the page open, and it will tell you when you are not ready.

See how the coach works
Before you book

Questions people ask

Is the F5 Certified Technology Specialist, BIG-IP APM certification a prerequisite for any other F5 certification?

Yes. Receiving the BIG-IP APM Specialist certification is a prerequisite for the Security Solutions Expert certification track.

What is the retake policy for Exam 304 if I fail?

After the first failed attempt, you must wait 15 days. The second failure requires a 30-day wait, the third a 45-day wait, the fourth a one-year wait, and the fifth or more a 90-day wait. Your retake count resets only when you pass the exam.

Can I reschedule or cancel my exam appointment?

Yes, but you must do so at least 48 hours before your scheduled exam time. Rescheduling within 48 hours incurs a fee. You must modify your appointment yourself; F5 Support, Pearson VUE, and Certiverse cannot process rescheduling or cancellation requests.

What identification do I need to bring to the test center?

You must bring two forms of valid, signed ID. One must be government-issued and include a photo. The name on your ID must match the name on your F5 Certified account.

Is there a practice test available for Exam 304?

Yes. F5 offers a practice test developed from the same blueprint as the live exam. It costs US $20 and can be viewed through the F5 Education Services Portal.

What job roles does the F5-CTS BIG-IP APM certification map to?

This certification is designed for professionals who manage application delivery networks and are responsible for implementing, troubleshooting, and maintaining BIG-IP APM, including security and access management for applications.

Are there any hands-on labs or performance-based questions in Exam 304?

The official exam page does not specify a hands-on lab component. The exam is proctored and delivered at Pearson VUE testing centers.

Information freshness · Content last reviewed on 2026-07-30 Up to date
Practice free questions 760 questions, free, no account needed.