304
BIG-IP APM Specialist (304)
Parte de F5 Certified Technology Specialist, BIG-IP APM
Computer-based, multiple-choice; delivered at Pearson VUE test centers (English). Credential awarded: F5 Certified Technology Specialist, APM. Prerequisite: F5 Certified BIG-IP Administrator (F5-CA); the catalog lists the BIG-IP APM Specialist certification as a prerequisite for the Security Solutions Expert track.
Material de estudo independente, construído a partir do blueprint público da prova. Sem afiliação, autorização ou endosso da F5. Os objetivos são transcritos e mapeados à mão, então esta página pode conter erros ou estar defasada em relação ao material atual do fabricante: objetivos, versões, numeração e disponibilidade mudam sem aviso. Trate o portal de certificação da própria F5 como a fonte da verdade e confira nele antes de agendar qualquer coisa.
Section 1: AUTHENTICATION, AUTHORIZATION, AND ACCOUNTING (AAA), SINGLE SIGN-ON (SSO), FEDERATED AUTHORIZATION, MOBILE DEVICE MANAGEMENT (MDM)
1.01 Explain how to configure different types of AAA methods
O que saber:- Configure AAA objects
- Microsoft Active Directory, LDAP, Radius, RSA SecurID, TACACS, (Kerberos/NTLM, Client Cert auth), end-point management system profile
1.02 Demonstrate knowledge of the network requirements for each authentication service type
O que saber:- Demonstrate ability to test and validate connectivity to each authentication service (adtest output, ldapsearch output)
1.03 Explain how to configure SSO objects
O que saber:- Determine specific SSO object requirements (e.g. Kerberos SPN requirements)
- Determine when to choose one type of SSO over another
Neste site: Métodos SSO do APM: Um Objeto Ruim Pode Apagar a Sessão Inteira, Kerberos e SPNEGO: Como o SSO Silencioso de Desktop Realmente FuncionaFerramentas: f5-apm-sso-explainer1.04 Explain how to configure SAML as an SP and/or IdP
O que saber:- Integrate BIG-IP APM Service Provider (SP) with external vendor IdP (e.g. PING, Okta, SaaS, etc.) Configure Single Logout (SLO)
Neste site: F5 BIG-IP APM como SAML Proxy: Modos SP e IdP, SAML 2.0: Como Funciona o SSO no Navegador, Bindings SAML e iniciação por SP vs IdP, Dentro de uma Asserção SAML: Sujeito, Condições e AudiênciaFerramentas: saml-decoder
Section 2: NETWORK AND APPLICATION ACCESS
2.01 Explain how to configure SSL VPN manually or using a wizard
O que saber:- Determine which option is appropriate to use: Network access, Portal access, Web Application access (APM/LTM Mode)
- Choose appropriate Webtop type: Full, Network Access, Portal Access
2.02 Explain how to configure Network Access Profiles
O que saber:- Configure profile settings (e.g. Connectivity profile options, Edge Client Options and updates, SNAT)
- Configure App Optimization
2.03 Explain how to configure portal access
O que saber:- Determine the appropriate level of patching
- Evaluate global ACL order
- Configure Resource Items
2.04 Explain how to configure application access
O que saber:- Configure Remote Desktop access (e.g. Launching applications, Custom Parameters)
- Deploy Citrix Bundle
- Configure App Tunnels
2.05 Explain how to configure Web Access Management (LTM-APM Mode)
O que saber:- Configure pool and virtual server
- Determine when to use Web Access Management
Section 3: VISUAL POLICY EDITOR
3.01 Explain how to configure authentication and logon objects in VPE
O que saber:- Configure an auth and/or query object (e.g. Determine group membership, Configure required attributes)
- Add appropriate logon page type
Ferramentas: f5-apm-session-variable-reference3.02 Explain how to configure resource/custom variables
O que saber:- Set up SSO credential mapping
- Assign Webtops dynamically
- Configure variable assignment
Neste site: Variáveis de Sessão: Onde o APM Guarda Tudo Que Aprendeu, Métodos SSO do APM: Um Objeto Ruim Pode Apagar a Sessão InteiraFerramentas: f5-apm-session-variable-reference3.03 Explain how to configure VPE flow with multiple branches and objects
O que saber:- Determine policy ending types (allow, deny, redirect)
- Use a message box to display a variable in a VPE
- Assign custom session variables
Ferramentas: f5-apm-session-variable-reference3.04 Explain how to configure and apply macros
O que saber:- Use a macro to combine multiple VPE objects
- Demonstrate an understanding of differences in creating a macro versus an access policy
Section 4: DEPLOY AND MAINTAIN iAPPS
4.01 Determine when to use an iApp
O que saber:- Import and deploy supported iApp templates
- Determine the min/max BIG-IP module versions supported by a specific iApp template
- Determine which BIG-IP modules are required to deploy a specific iApp template
4.02 Apply procedural concepts to maintain iApps
O que saber:- Reconfigure a deployed iApp to update objects
- Identify iApp used to deploy an object
4.03 Determine appropriate applications for enabling/disabling strict updates
O que saber:- Make manual changes to a deployed application service
- Demonstrate an understanding of the impact of disabling strict updates
Section 5: ADMINISTRATING AND TROUBLESHOOTING BIG-IP APM
5.01 Apply procedural concepts to manage and maintain access profiles
O que saber:- Determine proper use of profile scope (e.g. profile, virtual server, global)
- Tune policy settings (e.g. multiple concurrent users, limit active sessions per IP address)
5.02 Perform basic customizations of the U/I
O que saber:- Apply corporate branding (i.e. adding a logo, footer, logon form)
- Add additional languages for browser localization
5.03 Demonstrate an understanding of how High Availability applies to BIG-IP APM (with respect to end users, policy sync, device fail-over)
O que saber:- Demonstrate an understanding of the limitation of two units per HA pair and traffic group
- Configure Access Policy Sync (e.g. Configuring local objects vs global, validate access policy sync)
5.04 Explain provisioning/licensing for BIG-IP APM
O que saber:- Update an existing license for BIG-IP APM
- Consider CCU utilization for different types of access policy deployments
Neste site: Anatomia de um arquivo de licença do BIG-IP, Recuperando um BIG-IP que não carrega a config após uma atualizaçãoFerramentas: f5-bigip-license-explainer5.05 Apply procedural concepts to gather relevant data
O que saber:- Gather data from relevant BIG-IP tools (e.g. session reports, session variables, tcpdump, ssldump, sessiondump, APM log)
- Add debug logic to APM iRules
- Configure Debug logging
5.06 Determine root cause
O que saber:- Compare expected vs actual behaviors based on problem description
- Analyze and correlate all collected data (client/BIG-IP/serverside) to understand where a failure occurred
- Determine cause of EPSEC failures
Section 6: SECURITY
6.01 Explain how BIG-IP APM mitigates common attack vectors and methodologies
O que saber:- Demonstrate an understanding of how the BIG-IP solution mitigates common security risks (e.g., cookiehijacking, DoS attacks)
- Determine which features of the BIG-IP device mitigate common DoS attacks
- Deploy GeoIP and IP intelligence in the VPE to protect resources
Ferramentas: f5-dos-vector-explainer6.02 Determine which BIG-IP APM features should be used to mitigate a specific authentication attack
O que saber:- Configure logging
- Configure objects needed to deploy MFA
- Configure SNMP traps
Ferramentas: totp-hotp6.03 Apply procedural concepts to manage user sessions
O que saber:- Identify user session details
- Demonstrate an understanding of BIG-IP APM session cookies
Ferramentas: f5-apm-session-variable-reference6.04 Identify use cases of Secure Web Gateway (SWG)
O que saber:- Compare transparent vs explicit proxy deployments
- Determine the purpose of SWG
6.05 Describe access policy timeouts as related to security
O que saber:- Describe the differences between inactivity timeout, access policy timeout, and maximum session timeout
6.06 Explain how to configure and manage ACLs
O que saber:- Explain how ACLs are deployed by default when creating a policy
- Explain when a layer 4 or layer 7 ACL would be needed
6.07 Demonstrate an understanding of network security requirements for application access
O que saber:- Demonstrate an understanding of TCP/UDP ports required for application services
6.08 Apply procedural concepts to implement EPSEC
O que saber:- Configure client-side checks (e.g. anti-virus, firewall, registry)
- Update and install EPSEC software
Fontes públicas, usadas de boa-fé
Estes guias são materiais de estudo independentes, montados a partir de conteúdo publicamente disponível: blueprints de exame publicados, documentação oficial de produto e catálogos de treinamento dos fabricantes. Nomes de produtos, códigos de exame e marcas pertencem a seus titulares e são usados apenas para identificar o assunto ensinado. Este site não é afiliado a nenhum fabricante aqui citado nem endossado por ele. Se você detém direitos sobre material publicado nesta página e entende que ele deve ser removido ou corrigido, envie a URL exata e uma breve nota sobre o problema pela página de contato; os pedidos são analisados com rapidez e boa-fé. Ler o aviso legal completo →