A Citrix Architect can execute a configuration job using a DeployMasterConfiguration template on a NetScaler_________deployed_________. (Choose the correct option to complete sentence.)
A. CPX; as part of a high availability pair
B. CPX; as a stand alone device
C. SDX; with less than 6 partitions and dedicated management interface
D. MPX; as part of the cluster but Cluster IP is NOT configured
E. SDX; with no partitions as a stand alone device
Scenario: A Citrix Architect has set up NetScaler MPX devices in high availability mode with version 12.0.
53.13 nc. These are placed behind a Cisco ASA 5505 Firewall is configured to block traffic using access control lists. The network address translation (NAT) is also performed on the firewall.
The following requirements were captured by the architect during the discussion held as part of the NetScaler security implementation project with the customer's security team:
The NetScaler device:
1.
Should monitor the rate of traffic either on a specific virtual entity or on the device. It should be able to mitigate the attacks from a hostile client sending a flood of requests. The NetScaler device should be able to stop the HTTP, TCP, and DNS based requests.
2.
Needs to protect backend servers from overloading.
3.
Needs to queue all the incoming requests on the virtual server level instead of the service level.
4.
Should provide access to resources on the basis of priority.
5.
Should provide protection against well-known Windows exploits, virus-infected personal computers, centrally managed automated botnets, compromised webservers, known spammers/hackers, and phishing
proxies.
6.
Should provide flexibility to enforce the desired level of security check inspections for the requests originating from a specific geolocation database.
7.
Should block the traffic based on a pre-determined header length, URL length, and cookie length. The device should ensure that characters such as a single straight quote (*); backslash(\), and semicolon (;) are either blocked, transformed, or dropped while being sent to the backend server.
Which two security features should the architect configure to meet these requirements? (Choose two.)
A. Pattern sets
B. Rate limiting
C. HTTP DDOS
D. Data sets
E. APPQOE
Scenario: A Citrix Architect needs to assess an existing on-premises NetScaler deployment which includes Advanced Endpoint Analysis scans. During a previous security audit, the team discovered that certain endpoint devices were able to perform unauthorized actions despite NOT meeting pre-established criteria.
The issue was isolated to several endpoint analysis (EPA) scan settings.
Click the Exhibit button to view the endpoint security requirements and configured EPA policy settings.

Which setting is preventing the security requirements of the organization from being met?
A. Item 6
B. Item 7
C. Item 1
D. Item 3
E. Item 5
F. Item 2
G. Item 4
Scenario: A Citrix Architect needs to deploy a load balancing for an application server on the NetScaler. The authentication must be performed on the NetScaler. After the authentication, the Single Sign-on with the application servers must be performed using Kerberos impersonation.
Which three authentication methods can the Architect utilize to gather the credentials from the user in this scenario? (Choose three.)
A. SAML
B. OTP
C. TACACS
D. WEBAUTH
E. LDAP
A Citrix Architect needs to configure advanced features of NetScaler by using StyleBooks as a resource in the Heat service.
What is the correct sequence of tasks to be completed for configuring NetScaler using the Heat stack?
A. 1. Install NetScaler Bundle for OpenStack
2.
Deploy the Heat stack
3.
Register OpenStack with NMAS
4.
Add NetScaler instances (Optional)
5.
Prepare the HOT by using the NetScaler heat resources and NetScaler Network Resource
6.
Create service packages (Add OpenStack tenants)
B. 1. Install NetScaler Bundle for OpenStack
2.
Register OpenStack with NMAS
3.
Add NetScaler instances (Optional)
4.
Create service packages (Add OpenStack tenants)
5.
Prepare the HOT by using the NetScaler heat resources and NetScaler Network Resource
6.
Deploy the Heat stack
C. 1. Install NetScaler Bundle for OpenStack
2.
Add NetScaler instances (Optional)
3.
Create service packages (Add OpenStack tenants)
4.
Prepare the HOT by using the NetScaler heat resources and NetScaler Network Resource
5.
Register OpenStack with NMAS
6.
Deploy the Heat stack
D. 1. Install NetScaler Bundle for OpenStack
2.
Prepare the HOT by using the NetScaler heat resources and NetScaler Network Resource
3.
Register OpenStack with NMAS
4.
Deploy the Heat stack
5.
Add NetScaler instances (Optional)
6.
Create service packages (Add OpenStack tenants)
Which session parameter does the default authorization setting control when authentication, authorization, and auditing profiles are configured?
A. Determines the default logging level
B. Determines whether the NetScaler appliance will allow or deny access to content for which there is no specific authorization policy
C. Determines the default period after which the user is automatically disconnected and must authenticate again to access the intranet
D. Determines whether the NetScaler appliance will log users onto all web applications automatically after they authenticate or will pass users to the web application logon page to authenticate for each application.
E. Controls are amount of time the users can be idle before they are automatically disconnected.
Which four load-balancing methods support NetScaler Virtual Server-Level Slow Start? (Choose four.)
A. URLHash
B. Least response time
C. Least Packets
D. Least Connection
E. Token
F. Least bandwidth
G. SRCIPSRCPORTHash
Scenario: A Citrix Architect needs to assess an existing NetScaler configuration. The customer recently found that members of certain administrator groups were receiving permissions on the production NetScaler appliances that do NOT align with the designed security requirements.
Click the Exhibit button to view the configured command policies for the production NetScaler deployment.

To align the command policy configuration with the security requirements of the organization, the _______ for ______should change. (Choose the correct option to complete the sentence.)
A. command spec; item 3
B. priority; Item 5
C. action; Item 1
D. priority; Item 2
E. action; Item 4
F. command spec; Item 6
Scenario: A Citrix Architect needs to assess an existing NetScaler configuration. The customer recently found that certain user groups were receiving access to an internal web server with an authorization configuration that does NOT align with the designed security requirements.
Click the Exhibit button view the configured authorization settings for the web server.

Which item should the architect change or remove to align the authorization configuration with the security requirements of the organization?
A. Item 1
B. Item 3
C. Item 4
D. Item 5
E. Item 2
Scenario: Based on a discussion between a Citrix Architect and team of Workspacelab has been created across three (3) sites.
They captured the following requirements during the design discussion held for NetScaler design projects:
1.
All three (3) Workspacelab sites (DC, NDR, and DR) will have similar NetScaler configuration and design.
2.
Both external and internal NetScaler MPX appliances will have Global Server Load balancing (GSLB) configured and deployed in Active/Passive mode.
3.
GSLB should resolve both A and AAA DNS queries.
4.
In the GSLB deployment, the NDR site will act as backup for the DC site. whereas the DR site will act as backup for the NDR site.
5.
When the external NetScaler replies to DNS traffic coming in through Cisco Firepower IPS, the replies should be sent back through the same path.
6.
On the internal NetScaler, both front-end VIP and back-end SNIP will be part of the same subnet.
7.
USIP is configured on the DMZ NetScaler appliances.
8.
The external NetScaler will act default gateway for back-end servers.
9.
All three (3) sites (DC, NDR, and DR) will have two (2) links to the Internet from different service providers configured in Active/Standby mode.
Which design decision must the architect make to meet the design requirements above?
A. Interface 0/1 must be used for DNS traffic.
B. The SNIP of the external NetScaler must be configured as default gateway on the back-end servers.
C. ADNS service must be used with IPv6 address.
D. Policy-Based Route with next hop as CISCO IPS must be configured on the external NetScaler.