F5 304 Exam Overview:
| Certification Vendor: | F5 Networks |
| Exam Name: | BIG-IP APM Specialist |
| Exam Number: | 304 |
| Exam Duration: | 90 minutes |
| Certificate Validity Period: | 2 years |
| Exam Price: | USD 180 |
| Passing Score: | 245 / 350 |
| Real Exam Qty: | 80 |
| Related Certifications: | F5 Certified BIG-IP Administrator (F5-CA) F5 Certified Security Solutions Expert |
| Available Languages: | English |
| Exam Format: | Multiple-choice questions, Scenario-based items |
| Recommended Training: | Configuring BIG-IP Access Policy Manager (APM) F5 Official Exam Blueprint |
| Exam Registration: | F5 Certification Portal Pearson VUE Registration |
| Sample Questions: | F5 304 Sample Questions |
| Exam Way: | Proctored at Pearson VUE test centers; online proctoring available |
| Pre Condition: | Valid F5 Certified BIG-IP Administrator (F5-CA) certification (passed exams 101 and 201) |
| Official Syllabus URL: | https://education.f5.com/exams/big-ip-apm-specialist-304 |
F5 304 Exam Syllabus Topics:
| Section | Weight | Objectives |
|---|---|---|
| Access Services: Portal, Network and Application Access | 15% | - Application Access and resource publishing - Portal Access configuration and customization - Network Access (SSL VPN) and IP forwarding |
| Single Sign-On (SSO) and Federated Identity | 10% | - SSO methods: form-based, header-based, Kerberos - SAML, OAuth, OpenID Connect integration |
| BIG-IP APM Architecture and Functionality | 20% | - Core components and deployment models - Integration with TMOS and other BIG-IP modules - Licensing and provisioning |
| Authentication, Authorization and Accounting (AAA) | 25% | - AAA protocols: LDAP, RADIUS, TACACS+, Active Directory - Authorization policies and attribute mapping - Authentication methods: local, remote, multi-factor, certificate-based |
| Access Policy Configuration and Management | 25% | - Access Policy Editor and visual policy building - Session management, persistence and termination - Policy agents, actions, expressions and branching logic |
| Endpoint Security and Inspection | 5% | - Endpoint checks, client-side policies and remediation - Mobile device management and secure access |
F5 BIG-IP APM Specialist Sample Questions:
1. In an endpoint management system profile, what does the term "end-point compliance" refer to?
A) The process of validating that a client device meets security requirements before granting access.
B) The mechanism to synchronize user accounts between multiple endpoint management systems.
C) The ability to load-balance client requests based on their geographic location.
D) The capability to manage mobile devices and enforce security policies.
2. What is the primary purpose of configuring a Microsoft Active Directory (AD) AAA object on F5 BIG-IP APM?
A) To establish a secure communication channel between the BIG-IP APM and AD server.
B) To define access control policies for applications.
C) To facilitate single sign-on for users across multiple domains.
D) To centralize user authentication and authorization for domain-joined devices.
3. When validating connectivity to an LDAP server, which command-line tool can be used on BIG-IP APM to perform an LDAP search and retrieve information from the server?
A) ldapsearch
B) radiusd
C) adtest
D) authd
4. What is the purpose of Federated Authorization?
A) Enable single sign-on across multiple applications within the same domain.
B) Share user identity and access information across multiple domains.
C) Authenticate users using a third-party authentication service.
D) Enforce access control policies within a single domain.
5. Which of the following is a required component to deploy an iApp template successfully?
A) License for Application Firewall (AFM) module
B) External authentication server
C) SSL certificate
D) Virtual IP (VIP) address
Solutions:
| Question # 1 Answer: A | Question # 2 Answer: D | Question # 3 Answer: A | Question # 4 Answer: B | Question # 5 Answer: D |
We're so confident of our products that we provide no hassle product exchange.


By Fanny

