Exam4Training

Citrix 1Y0-241 Deploy and Manage Citrix ADC with Traffic Management Online Training

Question #1

Which feature can a Citrix Administrator use to create a consistent set of front-end SSL parameters across multiple SSL vServers?

  • A . SSL profile
  • B . SSL multiplexing
  • C . SSL bridge
  • D . SSL policy
  • E . SSL policy

Reveal Solution Hide Solution

Correct Answer: A
A

Explanation:

https://docs.citrix.com/en-us/citrix-adc/current-release/ssl/ssl-profiles.html

Question #2

In an SSL offload deployment, which policy will allow a Citrix Administrator to modify all URLs in the response body from "http://" to "https://"?

  • A . > add rewrite action Act1 replace_all "HTTP.RES.BODY(200000)" ""http://"" -pattern "https://"
    > add rewrite policy Pol1 trueAct1 NOREWRITE
  • B . > add rewrite action Act1 replace_all "HTTP.RES.BODY(200000)" ""http:"" -pattern "https://"
    > add rewrite policy Pol1 trueAct1 NOREWRITE
  • C . > add rewrite action Act1 replace_all "HTTP.RES.BODY(200000)" ""https //"" -pattern "http://"
    > add rewrite policy Pol1 trueAct1 NOREWRITE
  • D . > add rewrite action Act1 replace_all "HTTP.RES.BODY(200000)" ""https:"" -pattern "http://"
    > add rewrite policy Pol1 trueAct1 NOREWRITE

Reveal Solution Hide Solution

Correct Answer: D
Question #3

Scenario: To receive data alerts for failures, a Citrix Administrator is configuring SNMP on the Citrix ADC. The administrator is confident that the manager, alarms and SNMP traps are configured correctly. The following week, there is a Citrix ADC-related outage and the administrator does NOT receive any alerts.

What could be the reason for this alert failure?

  • A . The Citrix Web App Firewall is blocking the alerts from going out.
  • B . The community name was NOT configured in the Citrix ADC SNMP trap destination settings.
  • C . The Citrix ADC only has standard licensing.
  • D . The Citrix ADC is configured for SNMP version 1.

Reveal Solution Hide Solution

Correct Answer: B
Question #4

A Citrix Administrator needs to use a client’s IP address as the source IP address for Citrix ADC-to-server connections.

Which Citrix ADC mode can the administrator use to meet this requirement?

  • A . USNIP
  • B . Layer 2
  • C . Layer 3
  • D . USIP

Reveal Solution Hide Solution

Correct Answer: D
D

Explanation:

When you enable the USIP address mode of a NetScaler appliance, the appliance forwards each packet to the appropriate back end server with the client IP address. https://support.citrix.com/article/CTX121974

Question #5

Scenario: A Citrix Administrator currently manages a Citrix ADC environment for a growing retail company that may soon double its business volume. A Citrix ADC MPX 5901 is currently handling web and SSL transactions, but is close to full capacity. Due to the forecasted growth, the administrator needs to find a cost-effective solution.

What cost-effective recommendation can the administrator provide to management to handle the growth?

  • A . The addition of another MPX 5901 appliance
  • B . A hardware upgrade to a Citrix ADC MPX 8905
  • C . A license upgrade to a Citrix ADC MPX 5905
  • D . A hardware upgrade to a Citrix ADC SDX 15020

Reveal Solution Hide Solution

Correct Answer: B
Question #6

Scenario: The primary content switching vServer has gone down.

To troubleshoot, a Citrix Administrator has issued the following command:

> show csvserver CSV

CSV (10.1.100.100:443) C HTTPS Type: CONTENT

State: UP

Last state change was at Mon Jun 29 15:20:43 2020

Time since last state change: 1 day, 06:47:58 610

Client Idle Timeout: 180 sec

Down state flush: ENABLED

Disable Primary vServer On Down: DISABLED

Appflow logging: ENABLED

Port Rewrite: DISABLED

State Update: DISABLED

Default: Content Precedence: URL

vServer IP and Port insertion: OFF

Persistence: NONE redirect: http://www.site1.com/mysite1/maintenance

Backup: vServerCLBC2

Listen Policy: NONE

IcmpResponse: PASSIVE

RHIstate: PASSIVE

Traffic Domain: 0

Based on this output, where will the subsequent request be redirected?

  • A . http://www.site1.com/mysite1/maintenance
  • B . vServerCLB-2
  • C . Backup content switching vServer
  • D . 10.1.100.100:443

Reveal Solution Hide Solution

Correct Answer: B
B

Explanation:

https://docs.citrix.com/en-us/citrix-adc/current-release/content-switching/protecting-against-failure.html#configuring-a-redirection-url

“If a content switching virtual server is configured with both a backup virtual server and a redirect URL, the backup virtual server takes precedence over the redirect URL. A redirect URL is used when the primary and backup virtual servers are down.”

Question #7

A Citrix Administrator wants to configure independent and isolated access on a single appliance to allow three different departments to manage and isolate their own applications.

What can the administrator configure to isolate department-level administration?

  • A . Admin partitions that use dedicated VLANs
  • B . A SNIP in each partition, and bind a VLAN for the department
  • C . Policy-based routes for each department in the nsroot partition
  • D . Dedicated routes in the admin partitions for each department

Reveal Solution Hide Solution

Correct Answer: A
Question #8

set gslb vServer-GSLB-1-MIR ENABLED

What will the Citrix ADC appliance send when the above command is executed?

  • A . The Remote GSLB service as the first record in the response and adds the remaining active services as additional records
  • B . The Local GSLB service as the first record in the response and adds the remaining active services as additional records
  • C . Only the best GSLB service in the response
  • D . The best global server load balancing (GSLB) service as the first record in the response, and the remaining active services as additional records

Reveal Solution Hide Solution

Correct Answer: D
D

Explanation:

https://docs.citrix.com/en-us/citrix-adc/current-release/global-server-load-balancing/how-to/protect-setup-against-failure.html

"if you enable multiple IP responses (MIR), the Citrix ADC appliance sends the best GSLB service as the first record in the response and adds the remaining active services as extra records. "

Question #9

Which mode on a Citrix ADC can a Citrix Administrator utilize to avoid asymmetrical packet flows and multiple route/ARP lookups?

  • A . MAC-based forwarding (MBF)
  • B . Use Subnet IP (USNIP)
  • C . Layer 3
  • D . Layer 2

Reveal Solution Hide Solution

Correct Answer: C
Question #10

Scenario: A Citrix Administrator executed the following command in a global server load balancing (GSLB) environment:

set gslb site SiteB CtriggerMonitor MEPDOWN

What will be the effect of this command on the default service monitoring behavior on a remote site?

  • A . The service monitor is invoked only when Metric Exchange Protocol (MEP) has marked the service as DOWN.
  • B . The service monitor is invoked only when Metric Exchange Protocol (MEP) connectivity has been lost between Site A and Site B.
  • C . The service monitor will take precedence over Metric Exchange Protocol (MEP).
  • D . The state of the GSLB service will always be controlled by Metric Exchange Protocol (MEP).

Reveal Solution Hide Solution

Correct Answer: A

Question #11

Which four authentication types can a Citrix Administrator use for Citrix ADC authentication, authorization, and auditing (AAA) multifactor authentication? (Choose four.)

  • A . RADIUS
  • B . OAuth
  • C . FIDO2
  • D . NTLM
  • E . ADFS
  • F . LDAP
  • G . TACACS+

Reveal Solution Hide Solution

Correct Answer: A,B,C,F
Question #12

Scenario: A Citrix Administrator is managing a Citrix Gateway with a standard Platform license and remote employees in the environment. The administrator wants to increase access by 3,000 users through the Citrix Gateway using VPN access.

Which license should the administrator recommend purchasing?

  • A . Citrix ADC Burst Pack
  • B . Citrix Gateway Express
  • C . Citrix Gateway Universal
  • D . Citrix ADC Upgrade

Reveal Solution Hide Solution

Correct Answer: C
C

Explanation:

Reference: https://docs.citrix.com/en-us/citrix-gateway/current-release/citrix-gateway-licensing.html

Question #13

Which log records detailed information such as statistics, metrics, and debug information in a proprietary binary format on the Citrix ADC?

  • A . Nslog
  • B . Nsconfig
  • C . Nstrace
  • D . Syslog

Reveal Solution Hide Solution

Correct Answer: C
Question #14

Scenario: A Junior Citrix Administrator needs to create a content switching vServer on a Citrix ADC high availability (HA) pair. The NSIP addresses are 192.168.20.10 and 192.168.20.11. The junior administrator connects to NSIP address 192.168.20.10 and saves the changes.

The following day, a Senior Citrix Administrator tests the new content switching vServer, but it is NOT working. The senior administrator connects to the HA pair and discovers that everything the junior administrator configured is NOT visible.

Why has the Citrix ADC lost the newly added configurations?

  • A . The junior administrator made the changes and did NOT force a failover to save the configuration.
  • B . The junior administrator connected to the NSIP of the secondary Citrix ADC in the HA pair.
  • C . Both Citrix ADCs in the HA pair restarted overnight.
  • D . The Citrix ADC appliances have different firmware versions.

Reveal Solution Hide Solution

Correct Answer: B
B

Explanation:

"You are connected to the secondary node…" when first login to the NSIP and after saving the configuration

Question #15

A Citrix Administrator notices that the Citrix ADC is sending the IP addresses of all the active services in the DNS response.

The administrator can use the set gslb vServer<name> __________________ parameter to change this behavior.

  • A . EDR ENABLED
  • B . MIR DISABLED
  • C . MIR ENABLED
  • D . EDR DISABLED

Reveal Solution Hide Solution

Correct Answer: B
Question #16

Scenario: A Citrix Administrator configures an Access Control List (ACL) to block traffic from the IP address 10.102.29.5: add simpleacl rule1 DENY -srcIP 10.102 29.5

A week later the administrator discovers that the ACL is no longer present on the Citrix ADC.

What could be the reason for this?

  • A . The administrator did NOT run the apply ACL command.
  • B . The simple ACLs remain active for only 600 seconds.
  • C . The simple ACLs remain active for only 60 seconds.
  • D . The Citrix ADC has been restarted without saving the configurations.

Reveal Solution Hide Solution

Correct Answer: D
Question #17

Scenario: A Citrix Administrator configured Citrix ADC load balancing to send requests to one of three identical backend servers. Each server handles multiple protocols, and load

balancing is set up in round-robin mode.

The current load-balancing setup on the Citrix ADC is:

✑ One load-balancing vServer with one externally accessible VIP

✑ One service created for each protocol type

✑ One server entity for each backend resource

During business hours, the administrator wants to make changes to one backend server without affecting the other servers.

What is the most efficient way for the administrator to ensure that all traffic is routed away from the server without impeding responses from other resources?

  • A . Disable the backend service entity targeted for change.
  • B . Disable the backend server entity targeted for change.
  • C . Disable the load-balancing vServer.
  • D . Unbind the correct server entity from the load-balancing vServer.

Reveal Solution Hide Solution

Correct Answer: B
Question #18

Scenario: A Citrix Administrator needs to configure a Responder policy, so that the string “/mytraining” is added to every URL path received.

The administrator should use these commands to accomplish this:

>add responder action Redirect_Act redirect “HTTP.REQ.URL.PATH_AND_QUERY+”mytraining”” C responseStatusCode 302

>add responder policy Redirect_Pol___________Redirect_Act

>bind lb vServer lb_vsrv_www CpolicyName Redirect_Pol Cpriority 100 CgotoPriorityExpression END C type_______

(Choose the correct option to complete the set of commands.)

  • A . “(HTTP.REQ.URL.STARTSWITH(”mytraining”))”
    REQUEST
  • B . “(HTTP.REQ.URL.STARTSWITH(”mytraining”))”
    RESPONSE
  • C . “!(HTTP.REQ.URL.ENDSWITH(”mytraining”))”
    REQUEST
  • D . “!(HTTP.REQ.URL.ENDSWITH(”mytraining”))”
    RESPONSE

Reveal Solution Hide Solution

Correct Answer: C
Question #19

Scenario: A Citrix Administrator manages an environment that has a Citrix ADC high availability (HA) pair running on two MPX appliances. The administrator notices that the state of the secondary Citrix ADC is ‘Unknown’.

What is causing the secondary state to be ‘Unknown’?

  • A . The synchronization on the secondary appliance is disabled.
  • B . TCP port 22 is disabled between the primary and secondary ADCs.
  • C . The administrator made both Citrix ADCs primary.
  • D . The remote procedure call (RPC) nodes are incorrectly configured.

Reveal Solution Hide Solution

Correct Answer: D
D

Explanation:

https://docs.citrix.com/en-us/citrix-adc/current-release/system/high-availability-introduction/troubleshooting-high-availability.html

Question #20

Scenario:

POLICY 1:

add rewrite action ACT_1 corrupt_http_header Accept-Encoding

add rewrite policy POL_1 HTTP.REQ.IS_VALID ACT_1

POLICY 2:

add rewrite action ACT_2 insert_http_header Accept-Encoding “identity“ add rewrite policy POL_2 `HTTP.REQ.IS_VALID ` ACT_2

How can a Citrix Administrator successfully bind the above rewrite policies to the load-balancing vServer lb_vsrv so that POL_2 is evaluated after POL_1 is evaluated?

  • A . bind lb vServer lb_vsrv -policyName POL_1 -priority 110 -gotoPriorityExpression NEXT -type REQUEST bind lb vServer lb_vsrv -policyName POL_2 -priority 100 -gotoPriorityExpression END -type REQUEST
  • B . bind lb vServer lb_vsrv -policyName POL_1 -priority 90 -gotoPriorityExpression NEXT -type REQUEST bind lb vServer lb_vsrv -policyName POL_2 -priority 100 -gotoPriorityExpression END -type REQUEST
  • C . bind lb vServer lb_vsrv -policyName POL_1 -priority 90 -gotoPriorityExpression END -type REQUEST bind lb vServer lb_vsrv -policyName POL_2 -priority 80 -gotoPriorityExpression NEXT -type REQUEST
  • D . bind lb vServer lb_vsrv -policyName POL_1 -priority 90 -type REQUEST bind lb vServer lb_vsrv -policyName POL_2 -priority 100 -type REQUEST

Reveal Solution Hide Solution

Correct Answer: B

Question #21

Scenario: A Citrix Administrator is configuring load balancing on a Citrix ADC appliance for company web servers. The administrator needs to create a custom monitor that will look for a specific keyword response from the website, which will be used to keep services in an UP state.

Which monitor can the administrator create to meet this requirement?

  • A . An HTTP-ECV monitor with the keyword in the Special Parameters – Receive String field
  • B . An HTTP-ECV monitor with the keyword in the Basic Parameters – Receive String field
  • C . An HTTP-ECV monitor with the keyword in the Special Parameters – Receive String field, and the Reverse option enabled
  • D . An HTTP-ECV monitor with the keyword in the Basic Parameters – Send String field

Reveal Solution Hide Solution

Correct Answer: B
Question #22

Scenario: A Citrix Administrator configured a Citrix ADC active-passive, high availability (HA) pair. The HA pair failed over and customers were unable to access hosted websites. The administrator troubleshoots and discovers that the upstream router is NOT updating its ARP table.

What can the administrator configure to resolve this issue?

  • A . Independent Network Configuration (INC) mode
  • B . Route monitor
  • C . HA monitor
  • D . Virtual MAC

Reveal Solution Hide Solution

Correct Answer: D
Question #23

Scenario: A Citrix Administrator is concerned about the number of health checks the Citrix ADC is sending to backend resources. The administrator wants to find a way to remove health checks from specific bound services.

How can the administrator accomplish this?

  • A . Unbind the current monitor.
  • B . Use the no-monitor option.
  • C . Use service groups to minimize health checks.
  • D . Use reverse-condition monitoring.

Reveal Solution Hide Solution

Correct Answer: B
Question #24

Scenario: A Citrix Administrator executed the command below:

> set httpcallout httpcallout1 CcacheForSecs 120

This command changes the cache duration of the HTTP ____________ to be set to 120 seconds. (Choose the correct option to complete the sentence.)

  • A . callout response
  • B . request
  • C . callout request
  • D . response

Reveal Solution Hide Solution

Correct Answer: A
A

Explanation:

https://docs.citrix.com/en-us/citrix-adc/current-release/appexpert/http-callout/configuring-http-callouts.html

Reference: https://docs.citrix.com/en-us/citrix-adc/current-release/appexpert/http-callout/caching-http-calloutresponses.html

Question #25

A Citrix Administrator needs to protect the HTTP backend server type without actually removing the header.

Which rewrite action type can the administrator apply to the Citrix ADC configuration to accomplish this?

  • A . REPLACE
  • B . CORRUPT_HTTP_HEADER
  • C . REPLACE_HTTP_REQ
  • D . REPLACE_ALL

Reveal Solution Hide Solution

Correct Answer: A
A

Explanation:

https://docs.citrix.com/en-us/citrix-adc/current-release/appexpert/rewrite/rewrite-action-policy-examples/example-mask-http-server-type.html

Question #26

Scenario: A Citrix Administrator needs to configure persistence on a global server load balancing (GSLB) vServer to which a service is bound. Service must continue to handle requests from the client even after it is disabled manually C accepting new requests or connections only to honor persistence. After a configured period of time, no new requests or connections are directed to the service and all existing connections are closed.

To achieve these requirements, which parameter can the administrator configure while disabling the service?

  • A . Persistence threshold
  • B . Persistence time-Out
  • C . Wait time
  • D . Request threshold

Reveal Solution Hide Solution

Correct Answer: C
C

Explanation:

https://docs.citrix.com/en-us/citrix-adc/current-release/load-balancing/load-balancing-advanced-settings/graceful-shutdown.html

Question #27

To improve page-rendering time a Citrix Administrator needs to overcome the connection limitation by enabling client browsers to simultaneously download more resources.

What should the administrator enable while configuring the front end optimization (FEO) feature?

  • A . HTML comments removal
  • B . Image lazy loading
  • C . CSS import to link
  • D . Domain sharding

Reveal Solution Hide Solution

Correct Answer: D
Question #28

Scenario: A Citrix ADC is configured with Interface 1/1 and bound to VLAN 40. A Citrix Administrator executed the below command:

> bind vlan 10 Cifnum 1/1

What is the result of executing this command on the Citrix ADC?

  • A . Interface 1/1 is bound to VLAN 20, and native VLAN is 20.
  • B . Interface 1/1 is bound to VLAN 20, and native VLAN is NOT changed.
  • C . Interface 1/1 is bound to VLAN 20, and native VLAN is 40.
  • D . Interface 1/1 is bound to VLAN 20, and native VLAN is 1.

Reveal Solution Hide Solution

Correct Answer: A
A

Explanation:

https://www.citrix.com/blogs/2014/12/29/netscaler-vlans-demystified/ https://support.citrix.com/article/CTX115575

Question #29

Scenario: A Citrix Administrator installed the compression feature on the web servers. To offload the compression on the Citrix ADC, the administrator configured the Citrix ADC appliance to remove the ‘Accept Encoding’ header from all HTTP client requests. However, the administrator observes that data is NOT being compressed by the Citrix ADC, even though the ‘Accept Encoding’ header is being removed from all requests.

What could be the cause of this issue?

  • A . The rewrite policy is bound at an incorrect bind point
  • B . The servers are automatically compressing all responses
  • C . The compression policy needs to be reconfigured
  • D . Servercmp is disabled on the Citrix ADC

Reveal Solution Hide Solution

Correct Answer: C
Question #30

Scenario: A Citrix Administrator configured a responder policy as follows:

> add responder action Picture10Action redirect ""http://" + http.req.hostname + http.req.url + "/picture10.html"" -bypassSafetyCheck YES

> add responder policy Picture10Policy "http.req.url.eq("/mywebsite")" Picture10Action

> bind responder global Picture10Policy 1 END -type OVERRIDE

What will be the effect of this configuration?

  • A . The URL http://www.mywebsite.com will be overwritten with /picture10.html.
  • B . Clients accessing http://www.mywebsite.com/ will have /picture10 html appended to the URL.
  • C . Clients accessing http://www.mywebsite.com/picture10.html will be overwritten with http://www.mywebsite com/.
  • D . The file Picture10 will be downloaded to a local drive when directly accessing http://www.mywebsite.com/picture10.html.

Reveal Solution Hide Solution

Correct Answer: B

Question #31

Scenario: A Citrix Administrator created and bound multiple content switching policies. During testing, attempts to access https://cs.mycompany.com resulted in the error message below:

HTTP 503 Service Unavailable

In a Citrix ADC configuration, what can the administrator do to fix the error?

  • A . Disable the spillover redirect URL.
  • B . Bind a certificate
  • C . Enable the content switching feature
  • D . Check the priorities of the existing policies

Reveal Solution Hide Solution

Correct Answer: D
Question #32

What is the first thing a Citrix Administrator should develop when creating a server certificate for Citrix ADC to secure traffic?

  • A . A private key
  • B . A certificate revocation list (CRL)
  • C . A certificate signing request (CSR)
  • D . A certificate key-pair

Reveal Solution Hide Solution

Correct Answer: A
A

Explanation:

https://docs.citrix.com/en-us/citrix-adc/current-release/ssl/how-to-articles/create-and-use-ssl-certificates-on-a-citrix-adc-appliance.html

Question #33

A Citrix Administrator needs to block all DNS requests from subnet 10.107.149.0/24.

Which expressions can the administrator use to match the required traffic?

  • A . CLIENT.IP.SRC(10.107.149.0) && (client.UDP.DSTPORT.EQ(53) || client TCP DSTPORT.EQ(53))
  • B . CLIENT.IP.SRC IN_SUBNET(10 107.149.0/24) && client.UDP.DSTPORT.EQ(53) || client.TCP.DSTPORT.EQ(53)
  • C . CLIENT.IP.SRC(10.107.149.0) && client UDP.DSTPORT.EQ(53) || client.TCP.DSTPORT.EQ(53)
  • D . CLIENT.IP.SRC IN_SUBNET(10.107.149.0/24) && (client.UDP.DSTPORT.EQ(53) || client.TCP.DSTPORT.EQ(53))

Reveal Solution Hide Solution

Correct Answer: D
Question #34

A Citrix Administrator configured an external syslog server but is NOT seeing detailed TCP information?

What could be causing this?

  • A . Log facility is NOT configured.
  • B . TCP logging is NOT enabled.
  • C . User-defined audit log is NOT configured.
  • D . Log level is NOT enabled.

Reveal Solution Hide Solution

Correct Answer: B
B

Explanation:

https://support.citrix.com/article/CTX226058

Question #35

Scenario: A Citrix Administrator configured SNMP to send traps to an external SNMP system. When reviewing the messages, the administrator notices several entity UP and entity DOWN messages.

To what are these messages related?

  • A . Load-balancing vServers
  • B . Network interface
  • C . High availability nodes
  • D . SSL profile

Reveal Solution Hide Solution

Correct Answer: A
Question #36

To protect an environment against Hash DoS attacks, which two configurations can a Citrix Administrator use to block all post requests that are larger than 10,000 bytes? (Choose two.)

  • A . > add policy expression expr_hashdos_prevention “http.REQ.METHOD.EQ(”POST”)&& http.REQ.CONTENT_LENGTH.GT(10000)”
    > add rewrite policy drop_rewrite expr_hashdos_prevention DROP
    > bind rewrite global drop_rewrite 100 END Ctype REQ_OVERRIDE
  • B . > add policy expression expr_hashdos_prevention “http.REQ.METHOD.EQ(”POST”)&& http.REQ.CONTENT_LENGTH.GT(10000)”
    > add responder policy pol_resp_hashdos_prevention expr_hashdos_prevention DROP NOOP
    > bind responder global pol_resp_hashdos_prevention 70 END Ctype REQ_OVERRIDE
  • C . > add policy expression expr_hashdos_prevention “http.REQ.METHOD.EQ(”POST”) || http.REQ.CONTENT_LENGTH.GT(10000)”
    > add responder policy pol_resp_hashdos_prevention expr_hashdos_prevention DROP NOOP
    > bind responder global pol_resp_hashdos_prevention 70 END Ctype REQ_OVERRIDE
  • D . > add policy expression expr_hashdos_prevention “http.REQ.METHOD.EQ(”POST”) || http.REQ.CONTENT_LENGTH.GT(10000)”
    > add rewrite policy drop_rewrite expr_hashdos_prevention DROP
    > bind rewrite global drop_rewrite 70 END Ctype REQ_OVERRIDE
  • E . > add policy expression expr_hashdos_prevention “http.REQ.METHOD.EQ(”POST”) || http.REQ.CONTENT_LENGTH.GT(10000)”
    > add responder policy pol_resp_hashdos_prevention expr_hashdos_prevention DROP NOOP
    > bind responder global pol_resp_hashdos_prevention 100 END Ctype REQ_OVERRIDE
  • F . > add policy expression expr_hashdos_prevention “http.REQ.METHOD.EQ(”POST”) || http.REQ.CONTENT_LENGTH.GT(10000)”
    > add rewrite policy drop_rewrite expr_hashdos_prevention DROP
    > bind rewrite global drop_rewrite 100 END Ctype REQ_OVERRIDE

Reveal Solution Hide Solution

Correct Answer: A,B
Question #37

Users are experiencing resets from the intranet server website, which is load balanced through the Citrix ADC.

Which Citrix ADC tool can a Citrix Administrator use to troubleshoot the reset issue?

  • A . View the newnslog from the command line interface (CLI) to look for packet resets from the Citrix ADC.
  • B . Use the nslog to look for packet resets on the Citrix ADC.
  • C . Take a packet trace with nstrace and analyze with Wireshark.
  • D . Look in the event viewer for packet resets from the Citrix ADC

Reveal Solution Hide Solution

Correct Answer: C
Question #38

Scenario: While using the GUI, a Citrix ADC MPX appliance becomes unresponsive. A Citrix Administrator needs to restart the appliance and force a core dump for analysis.

What can the administrator do to accomplish this?

  • A . Turn off the appliance using the power button.
  • B . Use the reset button on the front of the appliance.
  • C . Use the NMI button on the back of the appliance.
  • D . Connect to a USB port to issue a restart command.

Reveal Solution Hide Solution

Correct Answer: C
C

Explanation:

https://support.citrix.com/article/CTX120660

Question #39

Scenario: A Citrix ADC MPX is using one of four available 10G ports. A Citrix Administrator discovers a traffic bottleneck at the Citrix ADC.

What can the administrator do to increase bandwidth on the Citrix ADC?

  • A . Purchase another Citrix ADC MPX appliance.
  • B . Plug another 10G Citrix ADC port into the router.
  • C . Add two more 10G Citrix ADC ports to the network and configure VLAN.
  • D . Add another 10G Citrix ADC port to the switch, and configure Link Aggregation Control Protocol (LACP).

Reveal Solution Hide Solution

Correct Answer: D
D

Explanation:

https://docs.citrix.com/en-us/citrix-adc/current-release/networking/interfaces/configuring-link-aggregation.html

Question #40

Scenario: A Citrix Administrator executed the command below in an active-active, global server load balancing (GSLB) setup.

set gslb parameter CldnsprobeOrder DNS PING TCP

The order to calculate the _____ for dynamic proximity will be the DNS UDP query followed by the ping and then TCP. (Choose the correct option to complete the sentence.)

  • A . Time to live (TTL)
  • B . Empty Domain Service (EDS)
  • C . Multiple IP responses (MIR)
  • D . Round-trip time (RTT)

Reveal Solution Hide Solution

Correct Answer: D
D

Explanation:

https://docs.citrix.com/en-us/citrix-adc/current-release/global-server-load-balancing/methods/dynamic-round-trip-time-method.html

Reference: https://docs.citrix.com/en-us/citrix-adc/current-release/global-server-load-balancing/methods/dynamic-round-trip-time-method.html

Question #41

Scenario: While performing a disaster recovery test, a Citrix Administrator decides to failover the Citrix ADC high availability (HA) pair appliances. The administrator notices that the failover is NOT working as expected, and the secondary Citrix ADC is NOT taking over as primary. The administrator suspects that networking issues may be causing the failure.

What could be the cause of this issue?

  • A . HA monitoring is enabled on an interface of the secondary node that shows as ENABLED, DOWN.
  • B . The Independent Network Configuration (INC) mode is enabled on the primary node.
  • C . HA monitoring is enabled on a disabled interface of the primary node.
  • D . HA heartbeats are only seen on some enabled interfaces of the secondary node.

Reveal Solution Hide Solution

Correct Answer: A
Question #42

Scenario: After deploying a Citrix ADC in production, a Citrix Administrator notices that client requests are NOT being evenly distributed among backend resources. The administrator wants to change from the default loadbalancing method to one that will help distribute the load more evenly.

Which load-balancing method would ensure that the server with the least amount of network utilization is receiving new connections?

  • A . Least connection
  • B . Least bandwidth
  • C . Least response time
  • D . Least packets

Reveal Solution Hide Solution

Correct Answer: B
B

Explanation:

https://docs.citrix.com/en-us/citrix-adc/current-release/load-balancing/load-balancing-customizing-algorithms/leastbandwidth-method.html

Question #43

Scenario: A Citrix Administrator is configuring a Citrix ADC high availability (HA) pair. The administrator needs to ensure that one Citrix ADC is UP and primary at all times to guarantee that business websites are always available.

In the event that both nodes become unavailable or fail a health check, what does the administrator need to do to ensure that the Citrix ADCs still handle web traffic?

  • A . Configure HA fail-safe mode on the primary Citrix ADC only.
  • B . Disable HA fail-safe mode on each Citrix ADC independently.
  • C . Configure HA fail-safe mode on each Citrix ADC independently.
  • D . Disable HA fail-safe mode on the primary Citrix ADC only.

Reveal Solution Hide Solution

Correct Answer: C
Question #44

A Citrix Administrator needs to bind a URL transformation policy.

Which three bind points could the administrator use? (Choose three.)

  • A . Authentication, authorization, and auditing (AAA) group
  • B . Content switching vServer
  • C . Default global
  • D . Policy label
  • E . AAA user

Reveal Solution Hide Solution

Correct Answer: C,D,E
Question #45

Scenario: A Citrix Administrator configured a global server load balancing (GSLB) setup for internal and external users using the same host name. For internal users, cvad.citrite.net should go to the Citrix StoreFront site; for external users, it should connect to the Citrix ADC Gateway VPN site.

Which feature should the administrator configure to accomplish this?

  • A . DNS Preferred Location
  • B . DNS Record
  • C . DNS View
  • D . DNS Proxy

Reveal Solution Hide Solution

Correct Answer: C
C

Explanation:

Reference: https://support.citrix.com/article/CTX130163

Exit mobile version