Question: 21

Scenario: An administrator is creating a NetScaler Gateway virtual server for mobile devices only. The administrator must include two-factor authentication.
Which two steps must the administrator take to configure two-factor authentication for this environment? (Choose two.)

A. Bind the RSA policy first.
B. Bind the LDAP policy first.
C. Create an authentication policy.
D. Create a pre-authentication policy.

Answer: A, C

Question: 22

Scenario: An administrator implemented RADIUS with NetScaler Gateway as a two-factor authentication solution for a XenDesktop implementation. A planned outage is scheduled in wake of a software upgrade on the RADIUS infrastructure. During the outage, the administrator needs to disable the two-factor authentication on NetScaler Gateway to enable users’ continued access to published applications.
Which action could the administrator take to meet the needs of the scenario without affecting the connected users?

A. Delete the RADIUS authentication policy.
B. Set the RADIUS policy to be secondary authentication.
C. Disable authentication on the NetScaler Gateway virtual server.
D. Unbind the RADIUS authentication policy from the NetScaler Gateway virtual server.

Answer: D

Question: 23

What is required to configure a NetScaler Gateway cluster?

A. Striped IP addresses
B. Strict option is enabled
C. Sticky option is enabled
D. Enterprise or Platinum license

Answer: C

Question: 24

Scenario: A Citrix Administrator is upgrading a high availability pair to
NetScaler 10.5. After upgrading the secondary appliance, the administrator
forces a failover to test the new firmware, but the show ha node command
shows the sync state and propagation as disabled.
Why are the settings showing as disabled?

A. The appliances did NOT properly failover.
B. The NSIPs are no longer able to communicate.
C. The settings are automatically disabled until the other appliance is upgraded.
D. The upgrade process failed to run to completion on the secondary appliance.

Answer: C

Question: 25

An administrator created a service for a Web Interface server that is encrypted by an SSL certificate.
Which command should the administrator run at the command-line interface to create a monitor that will check the Web Interface by logging on to it with a test user’s credentials?

A. add lb monitor mon-WebInterface CITRIX-WI-EXTENDED -sitePath “/Citrix/XenApp” -userName user -domain DomainName -password [email protected] -encrypted
B. add lb monitor mon-WebInterface CITRIX-WI-EXTENDED -sitePath “/Citrix/XenApp” -userName user -domain DomainName -password [email protected] -secure YES
C. add lb monitor mon-WebInterface CITRIX-WI-EXTENDED -sitePath “/Citrix/XenApp” -userName user -domain DomainName -password [email protected] -destPort 443
D. add lb monitor mon-WebInterface CITRIX-WI-EXTENDED -sitePath “/Citrix/XenApp” -userName user -domain DomainName -password [email protected] -encrypted -secure YES

Answer: B

Question: 26

Scenario: An administrator configured a NetScaler Gateway session policy named spol_ICAP. The administrator needs to bind the policy to ensure that it is evaluated only when users of the ICAP security group log on to the NetScaler Gateway virtual server named vsrv_AGEE.
Which command should the administrator run at the command-line interface to meet the needs of the scenario?

A. bind vpn vserver vsrv_AGEE ICAP
B. bind aaa group ICAP -policy spol_ICAP
C. bind aaa group ICAP -policy spol_ICAP -global OFF
D. bind vpn vserver vsrv_AGEE -policy spol_ICAP -priority 1

Answer: B

