April 12, 2019

Which media-character can be used as an escape character and also can qualify a Meta-Character as literal when used before any character?

  • A. A backslash (\)
  • B. A pipe (|)
  • C. A dollar sign ($)
  • D. A forward slash (/)

Answer: A

A Citrix Engineer needs to prevent an attack against insecure operating-system or web-server software. The attack can cause the system to crash or behave unpredictably when it receives a data string that is larger than it can handle.
Which security check on the Application Firewall can the engineer enable to prevent such attacks?

  • A. Start URL
  • B. Deny URL
  • C. Buffer Overflow
  • D. Field Format

Answer: C

Which method is used by NetScaler Management and Analytics System (NMAS) to gather licensing information from NetScaler?

  • A. CFLOW
  • C. NITRO

Answer: C

A Citrix Engineer is considered that malicious users could exploit a web system by sending a large cookie. Which security check can the engineer implement to address this concern?

  • A. Field Formats
  • B. Content-type
  • C. Buffer Overflow
  • D. Start URL

Answer: C

Scenario: A Citrix Engineer configures the Application Firewall for protecting a sensitive website. The security team captures traffic between a client and the website and notes the following cookie:
The security team is concerned that the cookie name is a risk, as it can be easily determined that the NetScaler is protecting the website.
Where can the engineer change the cookie name?

  • A. Application Firewall Policy
  • B. Application Firewall Engine Settings
  • C. Application Firewall Default Signatures
  • D. Application Firewall Profile

Answer: D

Which requirement must be addressed to implement the IP Reputation feature on a NetScaler MPX appliance?

  • A. The NetScaler appliance must be able to connect to api.bcti.brightcloud.com on port 443.
  • B. The NetScaler appliance must be able to connect to wiprep-rtu.s3-us-west-2.amazonaws.com on port 80.
  • C. The NetScaler appliance must be able to connect to api.bcss.brightcloud.com on port 80.
  • D. The NetScaler appliance must be able to connect to wiprep-rtu.s3-us-west-2.amazonaws.com on port 443.

Answer: A

Scenario: A Citrix Engineer has deployed four NetScaler MPXs with the following network configuration:
-Management traffic is on VLAN 5 (NSIP).
-Application and server traffic is on VLAN 10 (SNIP).
The engineer added the NetScaler Management and Analytics System (NMAS) interface to VLAN 10 to deploy a NMAS High Availability (HA) pair to manage and monitor the applications and virtual servers. After doing so, the engineer is NOT able to see the NetScaler or applications that need to be managed.
How can the engineer resolve the issue?

  • A. Configure VLAN 5 as NSVLAN 5
  • B. Move the NMAS interface to VLAN 5
  • C. Configure VLAN 5 as NSSYNC VLAN
  • D. Bind SNIP to VLAN 5

Answer: A

Scenario: A Citrix Engineer is assigned applications using Role-based Access Control (RBAC) in NetScaler Management and Analytics Systems (NMAS). In the NMAS, the engineer can see all virtual servers under Web Insight > Applications, but is unable to access them.
What could be the cause of this behavior?

  • A. The RBAC is NOT supported for Orchestration.
  • B. The RBAC is NOT supported at the application level.
  • C. The Access Control policy is NOT configured on the NetScaler.
  • D. The Access Control policy name on NetScaler and NetScaler MAS should match.

Answer: B

Scenario: A Citrix Engineer has configured an IP Reputation policy and Profile in Application Firewall.
However, the engineer is NOT able to see any hits on the policy during testing.
Which logs can the engineer check to ensure that IP Reputation is configured correctly?

  • A. websocketd.log
  • B. snmpd.log
  • C. iprep.log
  • D. httpaccess.log

Answer: C

A Citrix Engineer needs to ensure that clients always receive a fresh answer from the integrated cache for positive responses (response of 200).
Which two settings can the engineer configure to make sure that clients receive a fresh response when it is needed? (Choose two.)

  • A. –flashCache NO
  • B. - pollEveryTime YES
  • C. –prefetch YES
  • D. –quickAbortSize

Answer: AB

Scenario: A Citrix Engineer configures an Application Firewall HTML SQL Injection Check and sets it to BLOCK and to use SQLSplCharANDKeyword as the SQL injection type. The engineer checks the logs and finds that nothing is being blocked.
What can be the cause of the Application Firewall failing to block the attack?

  • A. The request contains SQL Wildcard Characters.
  • B. The request neither contains SQL Special Characters nor keywords.
  • C. The request only contains SQL Special Characters.
  • D. The request only contains SQL keywords.

Answer: B

A Citrix Engineer has configured NetScaler Web Logging on a Linux client machine. The engineer needs to verify if the log.conf file has been configured correctly and that there are NO syntax errors.
Which command can the engineer use to accomplish this?

  • A. nswl -verify –f/ns/etc/log.conf
  • B. nswl -verify –f/usr/local/netscaler/etc/log.conf
  • C. nswl –verify –f/usr/local/netscaler/bin/log.conf
  • D. nswl –verify –f/ns/bin/log.conf

Answer: B

Scenario: A Citrix Engineer has configured NetScaler Management and Analytics System (NMAS) with the default settings. In this configuration, the total number of virtual servers is lower than the number of installed virtual server licenses.
Which type of virtual server will NOT be automatically licensed by the NMAS on discovered instances?

  • A. Non-addressable virtual server
  • B. Load Balancing virtual server
  • C. SSL Offload virtual server
  • D. Content Switching virtual server

Answer: A

A Citrix Engineer needs to configure an Application Firewall policy. According to company policies, the engineer needs to ensure that all the requests made to the website are originating from North America.
Which policy expressions will help the engineer accomplish the requirement?

  • A. CLIENT.IP.SRC.MATCHES_LOCATION (“North America.US.*.*.*.*”)
  • B. CLIENT.IP.SRC.MATCHES_LOCATION (“North America.US.*.*.*.*”). NOT
  • C. CLIENT.IP.DST.MATCHES (“North America.US.*.*.*.*”)
  • D. CLIENT.IP.SRC.MATCHES (“North America.US.*.*.*.*”)

Answer: A

A Citrix Engineer needs to set the rate at which connections are proxied from the NetScaler to the server. Which values should the engineer configure for Surge Protection?

  • A. UDP Threshold and Start Port
  • B. Grant Quota and Buffer Size
  • C. TCP Threshold and Reset Threshold
  • D. Base Threshold and Throttle

Answer: D

Scenario: A Citrix Engineer is configuring a Buffer Overflow Security Check. When configuring the options, the engineer notices that the Learn Mode is unavailable.
Why is the Learn Mode unavailable in this configuration?

  • A. The NetScaler License is at Enterprise.
  • B. The Application Firewall database is at 20 MB.
  • C. The Application Firewall feature is disabled.
  • D. The Learn Mode is NOT available for Buffer Overflow.

Answer: A

In PCRE, the only characters assumed to be literals are (Choose the correct option to complete the sentence.)

  • A. A-Z
  • B. a-z, A-Z
  • C. a-z, A-Z, 0-9
  • D. 0-9

Answer: B

The NetScaler logging client server can be installed and configured to store the log for . (Choose the correct option to complete the sentence.)

  • A. HTTP and HTTPS active connections on the NetScaler
  • B. HTTP and HTTPS requests processed by the NetScaler
  • C. statistics of the HTTP and HTTPS web sites load balanced on NetScaler
  • D. status of all the HTTP and HTTPS backend web servers

Answer: B

