304 Sample Questions

304 Sample Questions & Answers

Configuring and deploying access profiles dominates the weighting, built on assessing authentication attack vectors, maintaining those profiles over time, and resolving client-side issues like certificate and session-cookie problems.

Launch the full 304 simulator →

Showing 6 of 12 free samples.

  1. Question 1Intermediate

    Assess security needs and requirements to create an APM policy · Determine the appropriate access method for a use case

    A healthcare provider mandates that any external device connecting to their internal network must have an updated antivirus software and the corporate registry key present. If these conditions are not met, the user should only be granted access to a restricted web portal. Which combination of APM components is required to enforce this policy?

    Show answer & explanation

    Correct answer: B

    To evaluate endpoint security posture (like AV status and registry keys), APM relies on the OPSWAT Endpoint Security (EPSEC) package. The Visual Policy Editor (VPE) must include Antivirus Check and Registry Check items. Based on the success or failure of these checks, the VPE branching logic can assign a Full Network Access Webtop or a restricted Portal Access Webtop.

  2. Question 2IntermediateSelect 2

    Assess security needs and requirements to create an APM policy · Explain the differences among access methods

    An organization requires remote access solutions for different user groups. Contractors need access to a specific internal web application without installing any client software. IT administrators require full Layer 3 access to manage servers. Which TWO access methods are most appropriate for these respective use cases? (Select TWO)

    Show answer & explanation

    Correct answers: A, C

    Portal Access operates as a reverse proxy (Layer 7 rewrite) and requires only a standard web browser, making it ideal for contractors who cannot install VPN client software.

    Network Access provides a full Layer 3 VPN tunnel, assigning an internal IP address to the client, which is necessary for IT administrators who need to manage servers across various ports and protocols.

  3. Question 3Beginner

    Assess security needs and requirements to create an APM policy · Explain how APM interacts with commonly used applications

    A company is integrating BIG-IP APM with their existing VMware Horizon View environment to securely proxy remote desktop connections. What role does APM play in this specific architecture?

    Show answer & explanation

    Correct answer: B

    When integrated with VMware View, BIG-IP APM replaces the need for VMware Security Servers. It acts as an authentication gateway (handling AAA, MFA, and endpoint checks) and proxies the PCoIP or Blast Extreme display protocols securely to the internal View Connection Servers.

  4. Question 4Beginner

    Assess security needs and requirements to create an APM policy · Explain the differences among logging levels

    Setting the APM access policy logging level to 'Debug' is recommended for normal production operations because it provides maximum visibility without impacting system performance.

    Show answer & explanation

    Correct answer: B

    Setting the APM logging level to 'Debug' generates a massive amount of log data for every session. Writing this data to the disk consumes significant CPU and I/O resources, which can severely impact the data plane performance of the BIG-IP. Debug logging should only be used temporarily during active troubleshooting.

  5. Question 5Intermediate

    Assess security needs and requirements to create an APM policy · Determine appropriate logging methods and verbosity levels

    A security audit reveals that sensitive user information, including passwords entered during login, is occasionally being written in plain text to the APM logs. Which action should the BIG-IP administrator take to resolve this privacy issue while still maintaining adequate troubleshooting logs?

    Show answer & explanation

    Correct answer: B

    In APM, session variables that store sensitive information (like passwords) must be designated as 'Secure'. When a variable is marked as secure, APM automatically masks its value in the logs and the session reporting interface, protecting user privacy without requiring logging to be completely disabled.

  6. Question 6Beginner

    Configure and deploy an access profile · Determine the circumstances under which it is appropriate to use an APM specific profile

    When configuring a Virtual Server to provide Network Access (VPN) using BIG-IP APM, which two profiles are absolutely mandatory for the solution to function?

    Show answer & explanation

    Correct answer: B

    To deploy Network Access (SSL VPN) or App Tunnels, the Virtual Server must have both an Access Profile (which contains the authentication and policy logic) and a Connectivity Profile (which manages the underlying tunnel setup and client settings) applied.

Ready for the real thing?

The full 304 simulator has every exam-style question, timed mode, and instant scoring.

Go to the 304 simulator →