F5 302 BIG-IP DNS Specialist exam guide covering the four blueprint sections and GSLB

How the BIG-IP DNS Specialist Exam Tests Real GSLB Work

Four sections, and not one percentage between them. F5 publishes the blueprint for the BIG-IP DNS Specialist exam as Design and Architect, Implement, Test and Troubleshoot, and Operations and Support, then stops. There is no weighting table, no domain worth thirty percent, nothing that tells you which quarter of the paper decides the result.

That silence is useful once you read it correctly. It means no section can be treated as filler and none can be revised into a corner. Eighty questions in ninety minutes, scored out of 350 with 245 to pass, drawn from four bodies of work that a real BIG-IP DNS administrator does in sequence: scope the environment, build it, prove it, then keep it alive. This walkthrough takes the blueprint section by section and explains what each one is actually asking you to have done.

What Does the BIG-IP DNS Specialist Exam Actually Cover?

The BIG-IP DNS Specialist exam covers four sections: Design and Architect, Implement, Test and Troubleshoot, and Operations and Support. Passing exam 302 awards the F5 Certified Technology Specialist, BIG-IP DNS credential. The paper spans requirement gathering, global server load balancing configuration, DNS Express and DNS Cache, packet level diagnosis, and the backup, monitoring and upgrade work that follows a deployment.

Read as a set, those four names describe a lifecycle rather than a syllabus. The first section is the conversation with a customer before anything is built. The second is the build. The third is what happens when the build misbehaves. The fourth is everything after handover. F5 has chosen to test the whole arc rather than only the configuration screens, and that choice shapes every objective underneath.

It also sets the audience. This is not an introductory DNS paper. It assumes you already know what a zone transfer is and moves straight to whether you can predict the performance cost of enabling DNSSEC on a topology load balanced pool. F5 sells the credential as evidence that someone can deliver intelligent DNS and global server load balancing across multiple data centres, and the objectives are written at that level throughout.

What Are the F5 302 Exam Details?

Exam 302 runs for 90 minutes, carries 80 questions, and is scored out of 350 with a passing score of 245. It costs 180 US dollars and is booked through Pearson VUE. F5 delivers it as a test centre proctored exam, and passing it awards the F5 Certified Technology Specialist, BIG-IP DNS certification.

FieldValue
Exam nameF5 Certified Technology Specialist, BIG-IP DNS
Exam code302
Number of questions80
Duration90 minutes
Passing score245 out of 350
Price180 US dollars
SchedulingPearson VUE, test centre proctored

Eighty questions in ninety minutes leaves roughly sixty seven seconds per item. That is not a paper you reason your way through from first principles. Scenario questions in this exam typically hand you a configuration and a symptom and expect you to recognise the shape of the fault immediately, which is a recall speed problem as much as a knowledge problem.

The scoring scale matters too. A mark of 245 out of 350 is exactly 70 percent of the scale, but F5 reports a scaled score rather than a raw count, so you cannot translate it into a fixed number of correct answers in advance. Working out how many you can afford to lose is wasted effort. Rehearsing against F5 302 practice questions under a timer is a better use of the same hour, because it exposes the sections where your recall is slow rather than absent.

One structural detail is worth knowing before you plan a path. On its official 302 exam page F5 lists this certification as a prerequisite for the Cloud Solutions Expert tracks, so 302 is not a terminal badge. It is a gate into the expert tier for anyone heading that way.

Why Does F5 Publish No Weightings for This Exam?

F5 publishes the 302 blueprint as four named sections with objectives underneath and no percentage attached to any of them. Every other detail is stated openly, including the item count, the duration and the exact pass mark, so the absence is deliberate rather than an oversight. Preparation has to be planned without knowing which section carries the most marks.

The four sections of the F5 302 BIG-IP DNS Specialist blueprint shown as a left to right flow

The practical consequence is that the usual weighting strategy does not work here. On a Cisco or CompTIA paper you can look at a thirty percent domain and decide where the study hours go. On 302 there is no such signal, so the only defensible plan is to cover all four sections to a working depth and let the objective count act as a rough proxy for volume.

By that proxy the four sections are unusually even. Design and Architect carries four objective groups, Implement carries four, Test and Troubleshoot carries four, and Operations and Support carries four. The sub-points run to roughly forty across the whole blueprint, distributed without any obvious concentration. An even blueprint is consistent with an even paper, and until F5 says otherwise that is the safest assumption to prepare against.

There is a second reading, and it is the more useful one. The four sections are not independent topics. You cannot troubleshoot iQuery without having configured self IPs, and you cannot predict upgrade impact without understanding sync groups. The lack of weightings quietly signals that the exam treats the four as one continuous body of work.

What Does the Design and Architect Section Ask For?

Design and Architect asks you to turn a customer situation into a BIG-IP DNS deployment decision. Its four objective groups cover identifying customer requirements and constraints, evaluating an existing DNS environment, choosing a deployment and integration strategy, and determining performance requirements. Almost none of it involves touching a configuration screen.

The requirements objective is explicit that you must recognise the functionality and limitations of the DNS protocol, naming hierarchy and roles as examples, and work out what to ask a customer about high availability, security and management. This is the one place in the blueprint where protocol fundamentals are tested directly, and the protocol itself is defined in RFC 1035, which remains the reference for record types, message format and the resolution path.

Evaluating the existing environment brings in something exams rarely test: change control. The objective asks you to identify the change control procedure related to integrating BIG-IP DNS into an existing environment, alongside scoping the scale of the requirement and recognising limitations imposed by the incumbent DNS provider. That is a consulting skill sitting inside a technical blueprint.

The feature recognition objective is the one to drill

Buried in the deployment strategy objective is a single sub-point that names more product features than any other line in the blueprint. Given a customer environment, requirements and constraints, you are expected to recognise the use case for DNS Express, ZoneRunner, DNS64, DNSSEC, DNS Cache, various load balancing algorithms, persistence and health monitors. Eight features, one question stem, and the skill under test is matching each to the situation it solves.

Performance closes the section. You are asked to relate the characteristics of virtual edition against physical hardware to a use case, to use topology load balancing to improve user experience, and to predict the performance implications of key features. DNSSEC is named as an example, and its signing and validation cost is real: the standard is set out in ICANN’s DNSSEC overview, which explains why validation adds work to every response rather than a one off cost at configuration time.

How Much of the Exam Is Really GSLB?

Global server load balancing is the centre of the Implement section and reaches into all three of the others. Two of the four Implement objectives are GSLB specific, covering pool and virtual server selection tiers, load balancing methods and topology parameters, and a third covers the network conditions GSLB needs before it will work at all. In practice GSLB is the through line of the paper.

The selection tier objective is precise and is worth memorising in its exact shape. You are asked to differentiate between, and decide when to use, the two tiers of GSLB pool selection and the three tiers of virtual server selection. Two and three, not two and two. Candidates who half remember this arrive at a scenario question and pick a plausible wrong answer, because the fallback behaviour at each tier is what the question is really testing.

Load balancing methods are grouped by F5 into static, dynamic and fallback, and the objective asks you to recognise the functionality of each rather than to recite the list. That distinction matters. A question is more likely to describe a traffic outcome and ask which method produced it than to ask what round robin means. F5’s own global server load balancing glossary is the shortest correct summary of the model the exam assumes.

Topology load balancing appears twice, once here as configuration parameters and once in Design as a tool for optimising user experience. Anything the blueprint names twice is worth treating as core, and topology is the clearest example in the 302 objectives.

Which Non-GSLB DNS Components Are Examinable?

The blueprint carries a dedicated objective titled identify configuration options for non-GSLB DNS components, and it names three things: determining the listener IP and protocol, configuring DNS Express, and configuring DNS Cache. These are the parts of BIG-IP DNS that answer queries directly rather than steering clients between data centres, and they are examined separately from GSLB.

F5 302 comparison of GSLB client steering against the DNS services that answer queries directly

Listener configuration is the hinge. Until a listener exists on the right IP with the right protocol, no other DNS feature on the box does anything, which is why the objective leads with it. Candidates who only ever built GSLB in a lab frequently skip listeners entirely, because a wide IP configured through a wizard hides the step.

DNS Express and DNS Cache solve different problems and are easy to confuse under time pressure. DNS Express holds authoritative zone data in memory after a zone transfer so the BIG-IP answers rather than proxies. DNS Cache stores resolved answers so repeat lookups do not travel upstream. One is about being authoritative, the other about being fast for recursion, and a scenario question will describe the symptom rather than name the feature.

The wider configuration of these services is documented in F5’s BIG-IP DNS services documentation, which walks the implementations in the same order the blueprint lists them.

The TMOS objective is quietly a prerequisite

Sitting alongside these is the objective on TMOS and sync groups: creating the correct self IP configuration, routes and settings for iQuery communication, ensuring NTP operates on all sync group members, and creating logging profiles for DNS requests and responses. None of that is DNS work in the ordinary sense. It is the platform plumbing that makes a sync group function, and every later troubleshooting objective assumes you can do it.

NTP is the sleeper item. Sync group members that disagree about the time produce iQuery failures that look like network faults, and the blueprint names NTP explicitly rather than leaving it to be inferred.

Why Does a Whole Section Go to Test and Troubleshoot?

Test and Troubleshoot is one of four sections in a blueprint with no weightings, so on an even reading it is worth as much as building the solution. Its four objectives cover choosing the right diagnostic tool, diagnosing BIG-IP DNS issues, analysing system logs and statistics, and applying a configuration change to resolve what the analysis found. It is the only section that names specific command line tools.

Three tools appear by name. You are expected to use openssl to review trusted certificate information, tcpdump to capture and analyse DNS and iQuery traffic on the appropriate VLAN and IP, and dig or nslookup to verify DNS configuration and operation. The VLAN and IP qualifier on the tcpdump objective is not decorative. Capturing on the wrong interface is the single most common reason a candidate cannot explain what a sync group is doing.

Virtual server flapping appears twice, once as a diagnosis objective and once as a remediation objective, where the fix is described as applying a configuration change such as a monitor or prober adjustment. That pairing tells you the exam expects a full loop: observe the flap, find the cause, choose the correct object to change. Recognising the symptom without knowing which knob to turn will not score.

Log analysis is broken into three specific outcomes: verifying pool status from log entries, using statistical data to pinpoint query response time problems, and reading the appropriate log to confirm zone transfer operation. Three different logs, three different questions, and the skill is knowing which one answers which.

What Does Operations and Support Expect You to Have Done Before?

Operations and Support tests the work that happens after a BIG-IP DNS deployment goes live: configuration backup, configuration restoration, monitoring, and software upgrades. Its objectives are written as procedures rather than concepts, and several of them are difficult to answer correctly unless you have performed the task at least once on a real or virtual appliance.

Backup is tested twice over, through the graphical interface and through TMSH commands, followed by verifying the archive was created and moving it to remote storage. Knowing that a UCS archive exists is not enough. The objective wants the steps in both interfaces, which is a deliberate check that you have done it rather than read about it.

Restoration is the harder half and carries the most specific sub-point in the whole blueprint. You must recognise the special requirements for restoring configuration data to a BIG-IP DNS RMA unit, compare configuration objects between a new device and an existing sync group member, and determine when and how to restore the master encryption keys for TSIG and DNSSEC. Those keys are the detail that separates a restore that works from one that leaves a device silently unable to sign or validate.

Monitoring covers SNMP polling and the use of DNS statistics and analytics, and the upgrade objective asks for three things: recognising that a licence must be reactivated before an upgrade, predicting the end user impact of upgrading a sync group member while it is offline, and validating operation after the upgrade completes. The middle one is a scenario question waiting to happen, because the answer depends on how the remaining members handle the load.

If you sat 303 or another specialist paper recently, the operational shape here will feel familiar, and our walkthrough of the F5 303 ASM specialist exam shows how the same lifecycle structure repeats across the specialist tier.

How Should You Prepare for the F5 302 Exam?

Preparation for the BIG-IP DNS Specialist exam works best in the order the blueprint is written, because each section depends on the one before it. Build the platform, build GSLB on top of it, break it deliberately, then practise the operational tasks. Reading the objectives is not enough on its own, since several of them are written as actions performed in two different interfaces.

  1. Read the four blueprint sections end to end before studying any of them, so you know which objectives repeat across sections and which appear only once.
  2. Build a two device lab with correct self IPs, routes and NTP, and confirm iQuery is established between them before configuring anything DNS related.
  3. Configure GSLB with wide IPs, pools and virtual servers, then work through the two tiers of pool selection and the three tiers of virtual server selection until the fallback behaviour is predictable.
  4. Add the non-GSLB components separately, configuring a listener, then DNS Express against a real zone transfer, then DNS Cache, so the difference between them stays clear.
  5. Break each piece on purpose and diagnose it with tcpdump, dig and the relevant log, because the troubleshooting objectives expect the full loop from symptom to configuration change.
  6. Practise the operational tasks last, creating archives in both the interface and TMSH, and rehearsing a restore including the TSIG and DNSSEC master keys.

Time the rehearsal from the start rather than at the end. At roughly sixty seven seconds a question there is no recovery from slow recall, and candidates who only add a timer in the final week discover the problem too late to fix it. Our older F5 302 study tools page collects the practice material for that rehearsal in one place.

Frequently Asked Questions

How many questions are on the F5 302 exam?

Eighty questions in 90 minutes. That works out at roughly sixty seven seconds per item, so recall speed matters as much as depth on this paper.

What is the passing score for the BIG-IP DNS Specialist exam?

245 out of 350. F5 reports a scaled score rather than a raw count of correct answers, so there is no fixed number of questions you can afford to lose.

How much does exam 302 cost?

180 US dollars, booked through Pearson VUE. F5 delivers 302 as a test centre proctored exam.

Which certification do you get for passing 302?

F5 Certified Technology Specialist, BIG-IP DNS. F5 also lists this certification as a prerequisite for its Cloud Solutions Expert tracks, so it opens the expert tier rather than closing a path.

How is the 302 blueprint weighted?

It is not. F5 publishes four sections, Design and Architect, Implement, Test and Troubleshoot, and Operations and Support, with no percentage attached to any of them. The objective counts are even across the four, which is the closest thing to a weighting signal available.

Is GSLB the main topic of the exam?

It is the largest single theme but not the whole paper. Two Implement objectives are GSLB specific and a third covers the network conditions GSLB depends on, while a separate objective covers non-GSLB components including listeners, DNS Express and DNS Cache.

What is the difference between DNS Express and DNS Cache on the exam?

DNS Express holds authoritative zone data in memory after a zone transfer so the BIG-IP answers queries itself. DNS Cache stores previously resolved answers so repeat lookups do not go upstream. Scenario questions describe the symptom rather than naming the feature.

Which command line tools does the exam name?

Three: openssl for reviewing trusted certificate information, tcpdump for capturing DNS and iQuery traffic on the correct VLAN and IP, and dig or nslookup for verifying configuration and operation.

Does the exam cover DNSSEC?

Yes, in two places. It is named among the features you must match to a use case in the design section, and its performance implications are a separate sub-point. Restoring DNSSEC master encryption keys also appears in the operations section.

How much experience does F5 expect before 302?

F5 does not state a prerequisite exam on the 302 exam page, but describes the programme as progressive, with higher certifications building on the skills demonstrated by earlier ones. The objectives assume working familiarity with TMOS platform configuration rather than teaching it.

Conclusion

The BIG-IP DNS Specialist exam is built as a lifecycle rather than a topic list. Design, implement, troubleshoot, operate: four sections, no published weightings, and roughly forty sub-points spread evenly across them. Eighty questions, 90 minutes, 245 out of 350 to pass, at 180 US dollars through Pearson VUE.

Prepare it in the order F5 wrote it. Get the platform and iQuery right before touching GSLB, keep the selection tiers straight at two and three, treat listeners and DNS Express as separate skills from wide IP configuration, and rehearse the backup and restore steps in both interfaces rather than reading them. Then put a timer on everything, because at sixty seven seconds a question the exam tests how fast you recognise a fault as much as whether you can fix one.

Rating: 0 / 5 (0 votes)