Question No : 1

Scenario: A Citrix Administrator entered the command-line interface commands below to prevent IP address from accessing the NetScaler on port 80.
add simpleacl rule1 DENY -srclP -TTL 600
add simpleacl rule2 DENY -srclP -destPort 80
add ns acl rule1 DENY -srclP -priority 10
add ns acl rule2 DENY -srclP -priority 100
apply ns acls
Which Access Control List (ACL) will the NetScaler use to deny the IP address?
A. add ns acl rule1 DENY -srclP -priority 10
B. add simpleacl rule1 DENY -srclP -TTL 600
C. add simpleacl rule2 DENY -srclP -destPort 80
D. add ns acl rule2 DENY -srclP -priority 100
Answer: B

Question No : 2

Scenario: A Citrix Administrator needs to integrate LDAP for NetScaler system administration using the current Active Directory groups. The administrator created the group on the NetScaler exactly matching the group name in LDAP.
What can the administrator add next to complete the configuration of the LDAP?
A. Users to the group on the NetScaler
B. An AAA action to the group
C. A command policy to the group to specify the permission level
D. A nested group to the new group
Answer: A

Question No : 3

Scenario: A Citrix Administrator needs to configure a NetScaler Gateway virtual server in order to meet the security requirements of the organization. The administrator needs to configure timeouts for end-user sessions, to be triggered by the following behaviors:
*Inactivity for at least 15 minutes
*No keyboard or mouse activity for at least 15 minutes
Which two timeout settings can the administrator configure to meet the requirements? (Choose two.)
A. Client Idle Time-out set to 15
B. Forced Time-out set to 15
C. Client Idle Time-out set to 900
D. Session Time-out set to 15
E. Session Time-out set to 900
F. Forced Time-out set to 900
Answer: BD

Question No : 4

Which type of entity can a Citrix Administrator configure lo support the use of an SSL rewrite policy?
A. Global server load balancing virtual server
B. Content Switching virtual server
C. SSL load balancing virtual server
D. SSL_Bridge load balancing virtual server
Answer: C

Question No : 5

Which two components need to be configured for SmartAccess? (Choose two.)
A. Configuration logging
B. XenDesktop policies
C. XML Trust
D. StoreFront server groups
Answer: CD

Question No : 6

Which three NetScaler features can a Citrix Administrator use for default syntax policies? (Choose three.)
B. Rewrite
C. Integrated caching
D. Protection
E. Responder
Answer: ACE

Question No : 7

Scenario: A Citrix Administrator suspects an attack on a load-balancing virtual server. The administrator needs to restrict access to the load-balancing virtual server ( for 10 minutes.
Which Access Control List (ACL) will help to accomplish this requirement?
A. add ns acl rule1 DENY -destIP -TTL 600000
B. add simpleacl rule1 DENY -srcIP -TTL 600
C. add ns acI rule1 DENY -destIP -TTL 600
D. add simpleacl rule1 DENY -srcIP -TTL 600000
Answer: C

Question No : 8

Which two features can a Citrix Administrator use to allow secure external access to a sensitive company web server that is load-balanced by the NetScaler? (Choose two.)
A. ICA proxy
B. Integrated caching
C. Application Firewall
D. AppFlow
Answer: AE

Question No : 9

Scenario: A Citrix Administrator has a NetScaler SDX appliance with several instances configured. The administrator needs one instance with two interfaces connected to forward packets that are NOT destined for its MAC address. Hence, the administrator has enabled Layer 2 mode. After enabling Layer 2 mode, the administrator found the interface status going up and down.
What can the administrator perform to resolve this issue?
A. Disable Layer 2 mode on a NetScaler instance.
B. Enable MAC-based Forwarding mode.
C. Enable tagging on all interfaces.
D. Enable Layer 3 mode along with Layer 2 mode.
Answer: C

Question No : 10

Scenario: A Citrix Administrator needs to add 10 new servers to an existing server farm. The new servers are configured to serve the same applications and connections and are twice the capacity of the existing servers. The administrator wants to ensure that they are being fully utilized. Currently in the environment, the default load-balancing method is being used.
To ensure that only the 10 new servers are receiving twice the connections of the old servers without changing the load balancing to the rest of the environment, the administrator needs to add a weight of ___________to the services attached to the__________servers. (Choose the correct option to complete the sentence.)
A. 2; new
B. 2; old
C. 50; old
D. 50; new
Answer: CD

Question No : 11

Scenario: A NetScaler appliance is having intermittent issues. A Citrix Administrator is unable to identify the root cause and fix them. The administrator opened a Support ticket and the engineer assigned to the case requested all the logs and configuration information from the NetScaler.
Which technical support tool can the administrator use to gather all the information on the NetScaler to send to the Support Engineer?
A. Generate Support File
B. Batch Configuration
C. Start New Trace
D. Get Back Trace
Answer: C

Question No : 12

Scenario: A user is attempting to access a web server, which is load-balanced by the NetScaler using HTTPS. The user received the following message:
SSL/TLS error: You have not chosen to trust "Certificate Authority" the issuer of the server's security certificate.
What can a Citrix Administrator do to prevent users from viewing this message?
A. Ensure that the intermediate Certificate is linked to the Server Certificate.
B. Ensure that the user has the Server Certificate installed.
C. Ensure that the intermediate Certificate is linked to the Root Certificate.
D. Ensure that the user has the Certificate's Public key.
Answer: C

Question No : 13

Scenario: A Citrix Administrator is managing a NetScaler SDX running eight NetScaler instances. The administrator first needs to upgrade the firmware on the instances. However, the administrator is concerned that it needs to be done all at once.
What upgrading flexibility does SDX provide in this scenario?
A. The NetScaler instance can be upgraded at the SDX management level, allowing all instances to be upgraded at once.
B. The NetScaler instances have to be upgraded at the same time.
C. The NetScaler instance can be upgraded on an individual basis, allowing, all instances to run different firmware versions.
D. It is NOT possible to upgrade the NetScaler instances to different firmware versions.
Answer: D

Question No : 14

Scenario: A Citrix Administrator was notified that all contractor user IDs will start with the prefix "con" Currently SmartControl is used to restrict access to peripherals.
Which expression can the administrator use to accomplish this requirement?
Answer: A

Question No : 15

Scenario: Users belong to three Authentication, Authorization and Auditing (AAA) groups: Corporate, Finance and Software.
show aaa groups:
> show aaa group
1. GroupName: Corporate
2. GroupName: Finance
3. GroupName: Software
> show aaa group Corporate
GroupName: Corporate
Weight: 0
Authorization Policy: pol_1, Type: Classic, Priority: 0
> add authorization policy pol_1 ns_true ALLOW
> bind aaa group Corporate -policy pol_1
The user is being denied resources while aaad.debug shows:
Group 'corporate' being extracted for user User1
Why is the user being denied access?
A. The Authorization policy is NOT configured property.
B. The group attribute is NOT configured in the LDAP policy.
C. AAA group names are NOT the same as those in Active Directory.
D. LDAP Base DN is incorrect.
Answer: C
