What can the engineer modify in the configuration to resolve this issue?
A Citrix Engineer observes that after enabling the security checks in Learning mode only in an Application Firewall profile, the NetScaler is blocking the non-RFC compliant HTTP packets. What can the engineer modify in the configuration to resolve this issue?A . Disable Drop Invalid Requests in the HTTP Profile settings.B...
https://test.abc.com/rpc/rpcproxy.dll?
Scenario: A Citrix Engineer observes that when going through NetScaler, user connections fail and users are unable to access Exchange server. However, users can connect directly to the Exchange server. After checking the logs, the engineer finds that the POST request is blocked through the NetScaler. The log in/ var/log/ns.log...
How can the engineer resolve the issue?
Scenario: A Citrix Engineer has deployed four NetScaler MPXs with the following network configuration: -Management traffic is on VLAN 5 (NSIP). -Application and server traffic is on VLAN 10 (SNIP). The engineer added the NetScaler Management and Analytics System (NMAS) interface to VLAN 10 to deploy a NMAS High Availability...
Which parameter will the engineer add in the CLI to encrypt the credit card numbers in the logs?
Scenario: A Citrix Engineer needs to configure the Application Firewall to do a credit card check using the command-line interface (CLI) and configure the profile to obscure the credit card number. Which parameter will the engineer add in the CLI to encrypt the credit card numbers in the logs?A ....
Which protocol does NetScaler Management and Analytics System (NMAS) use when Discovery is run to locate instances?
Which protocol does NetScaler Management and Analytics System (NMAS) use when Discovery is run to locate instances?A . RIPB . TCPC . ICMPD . NITROView AnswerAnswer: C Explanation: The NetScaler MAS server sends an Internet Control Message Protocol (ICMP) ping to locate the instance. Then, it uses the instance profile...
Which setting can the engineer configure to meet this requirement?
A Citrix Engineer needs to ensure that all traffic to the virtual server is blocked if NONE of the bound Application Firewall policies are matched. Which setting can the engineer configure to meet this requirement?A . set appfw settings CundefAction APPFW_BLOCKB . set ns httpProfile nshttp_default_profile-dropInvalReqs DISABLEDC . set ns...
Which two security checks invoke sessionization? (Choose two.)
Which two security checks invoke sessionization? (Choose two.)A . CSRF Form TaggingB . Field FormatsC . Form Field ConsistencyD . HTML Cross-Site ScriptingView AnswerAnswer: A,C
What can the engineer perform to resolve the issue?
A Citrix Engineer has received the following message after setting up Application Firewall in Learning mode. August 28 6 03:14:27 <local0.info>XXX.0.0.2.08/28/2017:03:14:27 GMT VPXExtProd01 0-PPE-0: default GUI CMD_EXECUTED 1670370 0: User CitrixAdmin- Remote_ip XXX.19.XXX.XXX-Command “show appfw learningdata WebPub_vs_af_1 startURL”- Status “ERROR: Communication error with aslearn” What can the engineer perform to...
Which NetScaler Management Analytics System (NMAS) feature can the Citrix Engineer use to convert configuration tasks performed using the GUI to CLI commands?
Which NetScaler Management Analytics System (NMAS) feature can the Citrix Engineer use to convert configuration tasks performed using the GUI to CLI commands?A . Master ConfigurationB . Inbuilt TemplateC . Record-and-PlayD . Configuration TemplateView AnswerAnswer: C
Which TCP flag will the NetScaler Application Firewall module send in response to a malformed/non-RFC complaint request from a client?
Which TCP flag will the NetScaler Application Firewall module send in response to a malformed/non-RFC complaint request from a client?A . FIN+ACK packet with a window size set to 9845B . RST packet with a window size set to 9845C . RST +ACK packet with a window size set to...