Question 46
Scenario: A Citrix Architect is asked by management at the Workspacelab organization to review their existing configuration and make the necessary upgrades. The architect recommends small changes to the pre-existing Citrix ADC configuration. Currently, the Citrix ADC MPX devices are configured in a high availability pair, and the outbound traffic is load balanced between two Internet service providers (ISPs).
However, the failover is NOT happening correctly. The following requirements were discussed during the design requirement phase:
* The return traffic for a specific flow should be routed through the same path while using Link Load Balancing.
* The link should fail over even if the ISP router is up and intermediary devices to an ISP router are down.
* Traffic going through one ISP router should fail over to the secondary ISP, and the traffic should NOT flow through both routers simultaneously. What should the architect configure to meet this requirement?
However, the failover is NOT happening correctly. The following requirements were discussed during the design requirement phase:
* The return traffic for a specific flow should be routed through the same path while using Link Load Balancing.
* The link should fail over even if the ISP router is up and intermediary devices to an ISP router are down.
* Traffic going through one ISP router should fail over to the secondary ISP, and the traffic should NOT flow through both routers simultaneously. What should the architect configure to meet this requirement?
Question 47
Scenario: A Citrix Architect has met with a team of Workspacelab members for a design discussion They have captured the following requirements for the Citrix ADC design project:
The authentication must be deployed for the users from the workspacelab com and vendorlab com domains.
* The workspacelab users connecting from the internal (workspacelab) network should be authenticated using LDAP
* The workspacelab users connecting from the external network should be authenticated using LDAP and RADIUS.
* The vendorlab users should be authenticated using Active Directory Federation Service
* The user credentials must NOT be shared between workspacelab and vendorlab
* Single Sign-on must be performed between StoreFront and Citrix Gateway
* A domain drop down list must be provided if the user connects to the Citrix Gateway virtual server externally Which method must the architect utilize for user management between the two domains?
The authentication must be deployed for the users from the workspacelab com and vendorlab com domains.
* The workspacelab users connecting from the internal (workspacelab) network should be authenticated using LDAP
* The workspacelab users connecting from the external network should be authenticated using LDAP and RADIUS.
* The vendorlab users should be authenticated using Active Directory Federation Service
* The user credentials must NOT be shared between workspacelab and vendorlab
* Single Sign-on must be performed between StoreFront and Citrix Gateway
* A domain drop down list must be provided if the user connects to the Citrix Gateway virtual server externally Which method must the architect utilize for user management between the two domains?
Question 48
Scenario: A Citrix Architect has set up Citrix ADC MPX devices in high availability mode with version
12.0.53.13 nc. These are placed behind a Cisco ASA 5505 firewall. The Cisco ASA firewall is configured to block traffic using access control lists. The network address translation (NAT) is also performed on the firewall.
The following requirements were captured by the architect during the discussion held as part of the Citrix ADC security implementation project with the customers security team:
The Citrix ADC MPX device:
* should monitor the rate of traffic either on a specific virtual entity or on the device It should be able to mitigate the attacks from a hostile client sending a flood of requests. The Citrix ADC device should be able to stop the HTTP TCP. and DNS based requests
* needs to protect backend servers from overloading
* needs to queue all the incoming requests on the virtual server level instead of the service level
* should provide access to resources on the basis of priority
* should provide protection against well-known Windows exploits virus-infected personal computers, centrally managed automated botnets, compromised webservers, known spammers/hackers, and phishing proxies
* should provide flexibility to enforce the desired level of security check inspections for the requests originating from a specific geolocation database.
* should block the traffic based on a pre-determined header length. URL length and cookie length. The device should ensure that characters such as a single straight quote ('): backslash (\); and semicolon (;) are either blocked, transformed, or dropped while being sent to the backend server.
Which security feature should the architect configure to meet these requirements?
12.0.53.13 nc. These are placed behind a Cisco ASA 5505 firewall. The Cisco ASA firewall is configured to block traffic using access control lists. The network address translation (NAT) is also performed on the firewall.
The following requirements were captured by the architect during the discussion held as part of the Citrix ADC security implementation project with the customers security team:
The Citrix ADC MPX device:
* should monitor the rate of traffic either on a specific virtual entity or on the device It should be able to mitigate the attacks from a hostile client sending a flood of requests. The Citrix ADC device should be able to stop the HTTP TCP. and DNS based requests
* needs to protect backend servers from overloading
* needs to queue all the incoming requests on the virtual server level instead of the service level
* should provide access to resources on the basis of priority
* should provide protection against well-known Windows exploits virus-infected personal computers, centrally managed automated botnets, compromised webservers, known spammers/hackers, and phishing proxies
* should provide flexibility to enforce the desired level of security check inspections for the requests originating from a specific geolocation database.
* should block the traffic based on a pre-determined header length. URL length and cookie length. The device should ensure that characters such as a single straight quote ('): backslash (\); and semicolon (;) are either blocked, transformed, or dropped while being sent to the backend server.
Which security feature should the architect configure to meet these requirements?
Question 49
Which encoding type can a Citrix Architect use to encode the StyleBook content, when importing the StyleBook configuration under source attribute?
Question 50
Scenario: Based on a discussion between a Citrix Architect and a team of Workspacelab members, the MPX Logical layout for Workspacelab has been created across three (3) sites.
They captured the following requirements during the design discussion held for a NetScaler design project:
* All three (3) Workspacelab sites (DC, NDR, and DR) will have similar NetScaler configurations and design.
* Both external and internal NetScaler MPX appliances will have Global Server Load Balancing (GSLB) configured and deployed in Active/Passive mode.
* GSLB should resolve both A and AAA DNS queries.
* In the GSLB deployment, the NDR site will act as backup for the DC site, whereas the DR site will act as backup for the NDR site.
* When the external NetScaler replies to DNS traffic coming in through Cisco Firepower IPS, the replies should be sent back through the same path.
* On the internal NetScaler, both the front-end VIP and backend SNIP will be part of the same subnet.
* The external NetScaler will act as default gateway for the backend servers.
* All three (3) sites, DC, NDR, and DR, will have two (2) links to the Internet from different service providers configured in Active/Standby mode.
Which design decision must the architect make the design requirements above?
They captured the following requirements during the design discussion held for a NetScaler design project:
* All three (3) Workspacelab sites (DC, NDR, and DR) will have similar NetScaler configurations and design.
* Both external and internal NetScaler MPX appliances will have Global Server Load Balancing (GSLB) configured and deployed in Active/Passive mode.
* GSLB should resolve both A and AAA DNS queries.
* In the GSLB deployment, the NDR site will act as backup for the DC site, whereas the DR site will act as backup for the NDR site.
* When the external NetScaler replies to DNS traffic coming in through Cisco Firepower IPS, the replies should be sent back through the same path.
* On the internal NetScaler, both the front-end VIP and backend SNIP will be part of the same subnet.
* The external NetScaler will act as default gateway for the backend servers.
* All three (3) sites, DC, NDR, and DR, will have two (2) links to the Internet from different service providers configured in Active/Standby mode.
Which design decision must the architect make the design requirements above?