Scenario: A Citrix Engineer configures Citrix Web App Firewall to protect an application. Users report that they are NOT able to log on. The engineer enables a Start URL relaxation for the path //login.aspx.
What is the effect of the Start URL relaxation on the application?
A. Access to the path /login.aspx is unblocked.
B. Access to the path /login.aspx is blocked.
C. External users are blocked from the path /login.aspx. Internal users are permitted to the path / login.aspx.
D. Non-administrative users are blocked from the path /login.aspx Administrative users are permitted to the path /login.aspx.
Which Citrix Web App Firewall profile setting can a Citrix Engineer implement to remove non-essential content from web files to improve response time?
A. Strip HTML Comments
B. Exclude Uploaded Files from Security Checks
C. Enable Form Tagging
D. Exempt Closure URLs from Security Checks
Scenario: A Citrix Engineer is implementing Citrix Web App Firewall to protect a new web application. The engineer has created a profile, configured the relaxation rules, and applied signature protections. Additionally, the engineer has assigned the profile to a policy and bound the policy to the application.
What is the next step for the engineer in protecting the web application?
A. Update the global default Citrix Wed App Firewall profile with the new signature file.
B. Enable the Signature Auto-Update feature.
C. Enable logging on key protections.
D. Test the web application protections with a group of trusted users.
Scenario: A Citrix Engineer wants to protect a web application using Citrix Web App Firewall. After the Web App Firewall policy is bound to the virtual server, the engineer notices that Citrix Web App Firewall is NOT blocking bad requests from clients. Which tool can help the engineer view the traffic that is passing to and from the client?
A. nstrace
B. nsconmsg
C. syslog
D. aaad.debug
Which protection is applied on a server response from a protected application?
A. Cross-Site Request Forgeries (CSRF)
B. Form Field Consistency
C. HTML Cross-Site Scripting (XSS) D. Safe Object
A Citrix Engineer reviews the App Dashboard and notices that three of the monitored applications have an App Score of less than 50.
The engineer can interpret the App Score as a metric of application. (Choose the correct option to complete the sentence.)
A. security, with a lower score indicating better security
B. performance and availability, with a higher score indicating better health
C. performance and availability, with a lower score indicating better health
D. security, with a higher score indicating better security
Scenario: A Citrix Engineer notices that a web page takes a long time to display. Upon further investigation, the engineer determines that the requested page is referencing 48 other elements for download.
Which Front End Optimization technique can the engineer enable on the Citrix ADC to improve time-todisplay?
A. Shrink to Attributes
B. Remove comments from HTML
C. Domain Sharding
D. Move to Head Tag
Scenario: A Citrix Engineer used Learning to establish the HTML SQL Injection relaxations for a critical web application. The engineer now wishes to begin working on the protections for a different web application. The name of the Web App Profile is appfw_prof_customercare.
Which CLI command can the engineer use to empty the Learn database?
A. set appfw learningsettings appfw_prof_customercare -SQLInjectionMinThreshold 0
B. set appfw learningsettings appfw_prof_customercare -startURLMinThreshold 0
C. reset appfw learningdata
D. export appfw learningdata appfw_prof_customercare
Which Citrix Application Delivery Management (ADtv1) Analytics page allows a Citrix Engineer to monitor Citrix Virtual Apps and Desktop traffic?
A. Web Insight
B. WAN Insight
C. HDX Insight
D. Gateway Insight