Weekend Special Limited Time 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 1b2718643m

1Y0-440 Exam Dumps - Architecting a Citrix Networking Solution

Question # 4

Scenario: Based on a discussion between a Citrix Architect and a team of Workspacelab members, the MPX Logical layout for Workspacelab has been created across three (3) sites.

The requirements captured during the design discussion held for a NetScaler design project are as follows:

  • Two (2) pairs of Citrix ADC MPX appliances deployed in the DMZ and internal network.
  • High Availability will be accessible for each Citrix ADC MPX
  • The external Citrix ADC MPX appliance will be deployed in multi-arm mode.
  • The internal Citrix ADC MPX will be deployed in single-arm mode wherein it will be connected to Cisco ACI Fabric.
  • All three (3) Workspacelab sites: Dc, NDR and DR, will have similar Citrix ADC configurations and design.

How many Citrix ADC MPX appliances should the architect deploy at each site to meet the design requirements above?

A.

2

B.

8

C.

4

D.

6

E.

10

F.

3

Full Access
Question # 5

Scenario: A Citrix Architect needs to design a hybrid XenApp and XenApp and XenDesktop environment which will include Citrix Cloud as well as resource locations in on-premises datacenter and Microsoft Azure.

Organizational details and requirements are as follows:

  • Active XenApp and XenDesktop Service subscription
  • No existing Citrix deployment
  • About 3,000 remote users are expected to regularly access the environment
  • Multi-factor authentication should be used for all external connections
  • Solution must provide load balancing for backend application servers
  • Load-balancing services must be in Location B

Click the Exhibit button to view the conceptual environment architecture.

The architect should use ________ in Location A, and should use _________ in Location B. (Choose the correct option to complete the sentence.)

A.

Citrix Gateway as a Service, no Citrix products

B.

No Citrix products, Citrix ADC (BYO)

C.

Citrix Gateway as a Service, Citrix ADC (BYO)

D.

No Citrix products, Citrix ICA Proxy (cloud-licensed)

E.

Citrix Gateway as a Service, Citrix ICA Proxy (cloud-licensed)

F.

No Citrix products; Citrix Gateway appliance

Full Access
Question # 6

Scenario: The following NetScaler environment requirements were discussed during a design meeting between a Citrix Architect and the Workspacelab team:

  • All traffic should be secured, and any traffic coming into HTTP should be redirected to HTTPS.
  • Single Sign-on should be created for Microsoft Outlook web access (OWA).
  • NetScaler should recognize Uniform Resource Identifier (URI) and close the session to NetScaler when users hit the Logoff button in Microsoft Outlook web access.
  • Users should be able to authenticate using user principal name (UPN).
  • The Layer 7 monitor should be configured to monitor the Microsoft Outlook web access servers and the monitor probes must be sent on SSL.

Which method can the architect use to redirect the user accessing https://mail.citrix.com to https://mail.citrix.com?

A.

add responder action act redirect “https://mail.citrix.com” -responseStatusCode 302 add responder policy pol HTTP.REQ.IS_VALID act

B.

add lb server test SSL 10.107.149.243.80 -persistenceType NONE -cltTimeout 180 -redirectFromPort 80 -httpsRedirectUrl https://mail.citrix.com

C.

add lb server test SSL 10.107.149.243.443 –persistenceType NONE -cltTimeout 180 -redirectFromPort 80 -httpsRedirectUrl https://mail.citrix.com

D.

add responder action act redirect “\https://\ + HTTP REQ.HOSTNAME.HTTP_URL_SAFE + HTTP.REQ.URL_PATH_AND_QUERY.HTTP_URL_SAFE\n\n” -responseStatusCode 302 add responder policy pol HTTP.REQ.IS_VALID act

Full Access
Question # 7

Scenario: A Citrix Architect needs to design a new NetScaler Gateway deployment for a customer. During the design discussions, the architect learns that the customer would like to allow external RDP connections to internal Windows machines but does NOT want client drive redirection enabled on these connections.

Where should the architect enable the options to allow the customer to complete their requirement?

A.

NetScaler Gateway global settings

B.

RDP bookmark

C.

Session policy

D.

RDP server profile

E.

Session profile

F.

RDP client profile

Full Access
Question # 8

Scenario: A Citrix Architect needs to assess an existing NetScaler Gateway deployment. During the assessment, the architect collected key requirements for VPN users, as well as the current session profile settings that are applied to those users.

Click the Exhibit button to view the information collected by the architect.

Which configurations should the architect change to meet all the stated requirements?

A.

Item 4

B.

Item 3

C.

Item 5

D.

Item 2

E.

Item 1

Full Access
Question # 9

Scenario: A Citrix Architect has deployed load balancing for SharePoint 2010 on a Citrix ADC instance. While editing the document, the architect observed the error displayed below:

Sorry, we couldn't open 'https://sharepointcs.emea.in/Shared Documents/Citrix Enhancement Request Form.doc'

After troubleshooting, the architect discovers the issue. When a user opens a document, it opens in the browser, but while editing the document, thd session is transferred from the browser to the Word application During this time, the cookies should be transferred from the browser to the Word application.

Which two configurations should the architect modify to ensure that the cookies are shared between the browser and non-browser applications? (Choose two.)

A.

Enable Persistent Cookie

B.

Disable Persistent Cookie

C.

Set HTTPOnly Cookie to NO

D.

Set the NSC_AAAC cookie with HTTPOnly Flag

E.

Set lb vserver -persistenceType COOKIEINSERT

F.

Set HTTPOnly Cookie to Yes

Full Access
Question # 10

Which two types of database deployments are supported in Citrix Application Delivery Management? (Choose two.)

A.

High Availability

B.

Multiple Server

C.

Single Server

D.

Cluster instance

E.

Cloud Services

Full Access
Question # 11

Scenario: A Citrix Architect needs to design a new NetScaler Gateway deployment to provide secure RDP access to backend Windows machines.

Click the Exhibit button to view additional requirements collected by the architect during the design discussions.

To meet the customer requirements, the architect should deploy the RDP proxy through ______ using a________ solution. (Choose the correct option to complete the sentence.)

A.

CVPN: single gateway

B.

CVPN, stateless gateway

C.

ICAProxy: single gateway

D.

ICAProxy; stateless gateway

Full Access
Question # 12

Scenario: A Citrix Architect has deployed an authentication setup for the load balancing virtual server for the SAP application. The authentication is being performed using RADIUS and LDAP. RADIUS is the first factor, and LDAP is the second factor in the authentication. The Single Sign-on with SAP application should be performed using LDAP credentials. Which session profile should be used to perform the Single Sign-on?

A.

add tm sessionAction prof -sessTimeout 30 -defaultAuthorizationAction ALLOW -SSO ON -ssoCredential PRIMARY -httpOnlyCookie NO

B.

add vpn sessionAction prof-sessTimeout 30 -defaultAuthorizationAction ALLOW -SSO ON -ssoCredential SECONDARY -httpOnlyCookie NO

C.

add vpn sessionAction prof -sessTimeout 30 -defaultAuthorizationAction ALLOW -SSO ON -ssoCredential PRIMARY -httpOnlyCookie NO

D.

add tm sessionAction prof -sessTimeout 30 -defaultAuthorizationAction ALLOW -SSO ON -ssoCredential SECONDARY -httpOnlyCookie NO

Full Access
Question # 13

Scenario: A Citrix Architect has deployed Authentication for the SharePoint server through NetScaler. In order to ensure that users are able to edit or upload documents, the architect has configured persistent cookies on the NetScaler profile.

Which action should the architect take to ensure that cookies are shared between the browser and non-browser applications?

A.

The time zone should be the same on the NetScaler, client, and SharePoint server.

B.

The SharePoint load-balancing VIP FQDN and the AAA VIP FQDN should be in the trusted site of the client browser.

C.

The Secure flag must be enabled on the cookie.

D.

The cookie type should be HttpOnly.

Full Access
Question # 14

Scenario: A Citrix Architect needs to assess an existing on-premises NetScaler deployment which includes Advanced Endpoint Analysis scans. During a previous security audit, the team discovered that certain endpoint devices were able to perform unauthorized actions despite NOT meeting pre-established criteria.

The issue was isolated to several endpoint analysis (EPA) scan settings.

Click the Exhibit button to view the endpoint security requirements and configured EPA policy settings.

Which setting is preventing the security requirements of the organization from being met?

A.

Item 6

B.

Item 7

C.

Item 1

D.

Item 3

E.

Item 5

F.

Item 2

G.

Item 4

Full Access
Question # 15

Scenario: A Citrix Architect needs to plan for a customer environment in which more than 10,000 users will need access. The networking infrastructure needs to be able to handle the expected usage.

Which business driver should be prioritized based on the customer’s requirement?

A.

Increase flexibility

B.

Enable mobile work styles

C.

Simplify management

D.

Increase Scalability

E.

Reduce Costs

F.

Increase Security

Full Access
Question # 16

Which two methods can a Citrix Architect use to create a Heat Orchestration template? (Choose two)

A.

Direct Input

B.

Configuration jobs

C.

Citrix Web App Firewall Policies

D.

File

E.

Gateway Policies

Full Access
Question # 17

Scenario: A Citrix Architect needs to deploy Single Sign-on form-based authentication through Citrix ADC for Outlook Web Access (OWA) 2013 for the users of the domain workspacelab com The Single Sign-on (SSO) must be performed based on sAMAccountName.

Which SSO action can the architect use to meet this requirement?

A.

add tm formSSOAction OWA_Form_SSO_SSOPro -actionURL "/owa" -userField username -passwdField password -ssoSuccessRule "http RES SET_COOKIE COOKIE(V,cadata\M).VALUE(\Mcadata\").LENGTH.GT(70)M -responsesize 15000000 -submrtMethod POST

B.

add tm formSSOAction OWA_Form_SSO_SSOPro -actionURL "/owa/auth.owa" -userField user -passwdField password -ssoSuccessRule "http RES SET_COOKIE COOKIEC'cadataV) VALUE(\"cadata\").LENGTH.GT(70)" -responsesize 15000000 -submrtMethod GET

C.

add tm formSSOAction OWA_Form_SSO_SSOPro -actionURL "/owa/owa.aspx" -userField usemame -passwdField password -ssoSuccessRule "http RES SET_COOKIE COOKIE(\"cadata\") VALUE(\ncadata\") LENGTH.GT(70)" -responsesize 150 -submrtMethod POST

D.

add tm formSSOAction OWA_Form_SSO_SSOPro -actionURL "/owa/auth owa" -userField usemame -passwdField password -ssoSuccessRule "http RES SET_COOKIE COOKIE(V"cadataV,)VALUE(V,cadata\") LENGTH GT(70)M -responsesize 15000000 -submrtMethod POST

Full Access
Question # 18

Scenario: A Citrix Architect has set up NetScaler MPX devices in high availability mode with version 12.0. 53.13 nc. These are placed behind a Cisco ASA 5505 Firewall is configured to block traffic using access control lists. The network address translation (NAT) is also performed on the firewall.

The following requirements were captured by the architect during the discussion held as part of the NetScaler security implementation project with the customer’s security team:

The NetScaler device:

  • Should monitor the rate of traffic either on a specific virtual entity or on the device. It should be able to mitigate the attacks from a hostile client sending a flood of requests. The NetScaler device should be able to stop the HTTP, TCP, and DNS based requests.
  • Needs to protect backend servers from overloading.
  • Needs to queue all the incoming requests on the virtual server level instead of the service level.
  • Should provide access to resources on the basis of priority.
  • Should provide protection against well-known Windows exploits, virus-infected personal computers, centrally managed automated botnets, compromised webservers, known spammers/hackers, and phishing proxies.
  • Should provide flexibility to enforce the desired level of security check inspections for the requests originating from a specific geolocation database.
  • Should block the traffic based on a pre-determined header length, URL length, and cookie length. The device should ensure that characters such as a single straight quote (*); backslash(\), and semicolon (;) are either blocked, transformed, or dropped while being sent to the backend server.

Which two security features should the architect configure to meet these requirements? (Choose two.)

A.

Pattern sets

B.

Rate limiting

C.

HTTP DDOS

D.

Data sets

E.

APPQOE

Full Access
Question # 19

Which step does a Citrix Architect need to ensure during the Define phase when following the Citrix Methodology?

A.

Testing steps were integrated.

B.

The project manager agrees with road map timelines.

C.

A phased roll out was completed.

D.

Existing networking infrastructure is ready.

E.

The redundancy deployment decision was made.

Full Access
Question # 20

Which request can a Citrix Architect utilize to create a NITRO API command to add a NetScaler appliance with NSIP address 10.102.29.60 to the cluster?

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Full Access
Question # 21

Scenario: A Citrix Architect needs to design a hybrid XenApp and XenDesktop environment which will include as well as resource locations in an on-premises datacenter and Microsoft Azure.

Organizational details and requirements are as follows:

  • Active XenApp and XenDesktop Service subscription
  • No existing NetScaler deployment
  • Minimization of additional costs
  • All users should correct directly to the resource locations containing the servers which will host HDX sessions

Click the Exhibit button to view the conceptual environment architecture.

The architect should use___________ in Location A, and should use _______________ in Location B. (Choose the correct option to complete the sentence.)

A.

No NetScaler products; NetScaler ICA Proxy (cloud-licensed)

B.

NetScaler Gateway as a Service; NetScaler ICA Proxy (cloud-licensed)

C.

NetScaler Gateway as a Service; no NetScaler products

D.

No NetScaler products; NetScaler Gateway appliance

E.

NetScaler gateway as a Service; NetScaler ADC (BYO)

Full Access
Question # 22

Scenario: The Workspacelab team has configured their Citrix ADC Management and Analytics (Citrix Application Delivery Management) environment. A Citrix Architect needs to log on to the Citrix Application Delivery Management to check the settings.

Which two authentication methods are supported to meet this requirement? (Choose two.)

A.

Certificate

B.

RADIUS

C.

TACACS

D.

Director

E.

SAML

F.

AAA

Full Access