Citrix 1Y0-350 NetScaler 10 Essentials and Networking Exam Set 3

Scenario: An engineer has configured an SSL virtual server and has bound a service group of type HTTP containing several servers. The service group is UP but the virtual server is in a DOWN state. The engineer has verified that the SSL feature is enabled. What should the engineer do to ensure that the virtual server shows as UP?


Options are :

  • Add a monitor that checks for HTTP.
  • Bind an SSL certificate to the virtual server
  • Configure the service group to use port 443.
  • Change the service group to type SSL.
  • Change the monitor for a larger time out period.

Answer : Bind an SSL certificate to the virtual server

Scenario: The network engineer has created a monitor and bound it to a service group containing four web servers to verify that the web application responds. During routine maintenance one of the web servers is shut down; however, the server state remains UP and user requests are still attempting to communicate with the server. What could be causing this problem?


Options are :

  • The server has been disabled.
  • Health monitoring is disabled for the service group.
  • The monitor is not bound at the correct bind point.
  • The NetScaler configuration has not been saved since before the monitor was bound.

Answer : Health monitoring is disabled for the service group.

Citrix 1Y0-350 NetScaler 10 Essentials and Networking Exam Set 4

A company has two sites that host six cache web servers that are used to promote sales information. Which feature on the NetScaler should an engineer enable to provide faster application performance and also provide additional capacity if the demand increases for one site?


Options are :

  • Load balancing
  • Content switching
  • Responder Policy
  • Integrated Cache

Answer : Load balancing

What should a network engineer configure to set high availability for a load balanced virtual server?


Options are :

  • Load balancing services
  • A backup virtual server
  • Session persistence
  • Load balancing policies

Answer : A backup virtual server

Scenario: An engineer has three subnets configured on a NetScaler appliance. The engineer must only allow a certain group of users to access a virtual server on the appliance. The IT Manager requires that all rules are flexible and can be easily modified for ease of administration. How could the engineer allow certain groups to access the virtual server while still being able to modify the setting in the future?


Options are :

  • Create an Extended ACL.
  • Add a Host Route to the virtual server.
  • Disable USNIP Mode.
  • Add a Simple ACL.

Answer : Create an Extended ACL.

1Y0-200 Managing Citrix XenDesktop 7 Solutions Exam Set 1

Scenario: A network engineer needs to generate a certificate on the NetScaler appliance. The environment requires a private key with 4096-bit encryption. To generate a new SSL certificate from a NetScaler Appliance, the engineer must first create __________. (Choose the correct option to complete the sentence.)


Options are :

  • RSA key
  • DSA key
  • Diffie-Hellman key
  • CSR

Answer : RSA key

Scenario: A network engineer needs to provide web server administrators with access to monitoring and reporting after changing the default root password during the initial setup of the NetScaler. The engineer needs to ensure that the web server administrators can perform this task. What should the engineer do in order to ensure that the administrators are able to log on to the NetScaler?


Options are :

  • Create an authentication policy.
  • Create a group.
  • Create user accounts.
  • Create an authorization policy.

Answer : Create user accounts.

1Y0-200 Managing Citrix XenDesktop 7 Solutions Exam Set 2

A NetScaler engineer would like to present different web pages to a user based on the device and browser type from which they are connecting. Which responder policy could assist with this requirement?


Options are :

  • HTTP.RES.BODY(1024)
  • HTTP.RES.URL.PATH
  • HTTP.REQ.HEADER("User-Agent")
  • HTTP.REQ.Host("Host")

Answer : HTTP.RES.BODY(1024)

Scenario: A company is using Citrix NetScaler VPX for publishing internal resources using Citrix Access Gateway with Smart Access. Since the number of users has increased the company wants to migrate from Citrix NetScaler VPX to Citrix NetScaler MPX. The engineer is running a parallel installation of the Citrix NetScaler MPX and now needs to transfer the Citrix Access Gateway Universal Licenses from a Citrix NetScaler VPX to a Citrix NetScaler MPX platform. How should the engineer transfer the Citrix Access Gateway Universal License files from the VPX to the MPX?


Options are :

  • Logon to www.MyCitrix.com, return the Citrix Access Gateway Universal License file(s), reallocate the Citrix Access Gateway Universal License file using the hostname of the Citrix NetScaler MPX.
  • Backup the /nsconfig directory from the Citrix NetScaler VPX using SCP, restore the /nsconfig directory to the Citrix NetScaler MPX using SCP.
  • Download the Access Gateway Universal License file(s) from the Citrix NetScaler VPX using SCP. Upload the Access Gateway Universal License file(s) to the Citrix NetScaler MPX using SCP.
  • Logon to www.MyCitrix.com, return the Citrix Access Gateway Universal License file(s), reallocate the Citrix Access Gateway Universal License file using the MAC Address of the Citrix NetScaler MPX.

Answer : Logon to www.MyCitrix.com, return the Citrix Access Gateway Universal License file(s), reallocate the Citrix Access Gateway Universal License file using the hostname of the Citrix NetScaler MPX.

Scenario: A virtual server named New_Server has been disabled to perform an emergency upgrade; however requests from clients are NOT being redirected to the maintenance page. The redirected URL configuration is: >set cs vserver Website_main -lbvserver New_Server -backupVserver Backup_Server - redirectURL http://www.mydomain.com/maintenance - soMethod Connection -soThreshold 1000 - soPersistence enabled Why are requests from clients NOT being redirected to the maintenance page?


Options are :

  • The backup virtual server is unavailable.
  • The spillover persistence has been activated.
  • The backup virtual server takes precedence over the redirect URL.
  • It has not been linked to content switching policies.

Answer : The backup virtual server takes precedence over the redirect URL.

1Y0-200 Managing Citrix XenDesktop 7 Solutions Exam Set 3

Scenario: A network engineer has modified the configuration of a content-switching virtual server, Website_main, because a second content-switching server that is capable of handling more connections has been added to the NetScaler implementation. Both servers will remain in operation. The engineer made the following configuration changes: >set cs vserver Website_main -lbvserver New_Server -backupVserver Old_Server -redirectURL http://www.mydomain.com/maintenance -soMethod Connection -soThreshold 1000 Why did the engineer enable the spillover option?


Options are :

  • To handle the extra connections using the old server without dropping them
  • To handle incoming connections in case the new server is unavailable
  • To redirect the extra connections to the Maintenance website when it is needed
  • To handle incoming connections while the server reaches its limit of connections

Answer : To handle the extra connections using the old server without dropping them

Scenario: A network engineer gets an error message when using the configuration utility to import a PKCS#12 certificate that contains a dollar sign ($), a backquote (`), or an escape (\) character password. In order to address this error, the network engineer could prefix it with __________. (Choose the correct option to complete the sentence.)


Options are :

  • an escape character (\)
  • a dollar sign character ($)
  • a backquote character (`)
  • a double quotation character (")

Answer : an escape character (\)

Scenario: A network engineer has configured GSLB for a multisite environment. All GSLB services show as UP with an UP MEP status. The engineer has observed that DNS queries are directed to the SNIP of the NetScaler; however, no DNS response is being received. How can the engineer resolve this issue?


Options are :

  • Create a load balancing virtual server for DNS.
  • Add an ADNS service on the SNIP.
  • Select the “Send all “active” service IPs’ in response (MIR)” option.
  • Change the DNS delegation to the NSIP.

Answer : Add an ADNS service on the SNIP.

1Y0-200 Managing Citrix XenDesktop 7 Solutions Practice Exam Set 1

Which step is required to ensure that SSL traffic is passed through the NetScaler to backend services without processing SSL on the NetScaler appliance?


Options are :

  • Create a service group of type SSL.
  • Bind an SSL certificate to the virtual server.
  • Bind an SSL certificate to a service group.
  • Create a service group of type HTTP.
  • Create a service group of type SSL_BRIDGE.

Answer : Create a service group of type SSL_BRIDGE.

A public SSL certificate on a virtual server is about to expire and the NetScaler engineer needs to renew the certificate before it expires. Which step must the engineer take to renew the SSL Certificate?


Options are :

  • Recreate the Private Keys
  • Update the existing certificate
  • Execute CRL Management
  • Generate a new CSR

Answer : Update the existing certificate

A network engineer has enabled USIP and USNIP and set a unique IP address as the source IP using the proxyIP parameter on an INAT policy. Which is the correct order of precedence for the IP addresses?


Options are :

  • USIP-unique IP-USNIP-MIP-Error
  • Unique IP-USIP-MIP-Error
  • USIP-Unique IP-MIP-USNIP-Error
  • USIP-USNIP-MIP-Unique IP-Error

Answer : USIP-unique IP-USNIP-MIP-Error

1Y0-200 Managing Citrix XenDesktop 7 Solutions Practice Exam Set 2

A network engineer is investigating issues and suspects that a new server that has been recently added to the environment has the same IP address as a virtual server that is configured on the NetScaler. Which command could the engineer run to check the logs that will contain such details?


Options are :

  • nsconmsg -K newnslog -d stats
  • nsconmsg -K /var/nslog/newnslog -s ConMon=x -d oldconmsg
  • nsconmsg -K /var/nslog/newnslog -s ConLb=1 -d oldconmsg
  • nsconmsg -K /var/nslog/newnslog -d consmsg

Answer : nsconmsg -K /var/nslog/newnslog -d consmsg

Scenario: An engineer has configured a virtual server that users access using HTTP port 80. The web application also uses TCP port 81 and 8080 for non-user access. The engineer would like to prevent users from connecting to web servers if any of the ports go down. How should the engineer set this configuration to ensure service availability?


Options are :

  • Create monitors for ports 81 and 8080, and bind to the service or service group.
  • Lower the server timeout value.
  • Create additional virtual servers for ports 81 and 8080.
  • Increase the monitor threshold.

Answer : Lower the server timeout value.

Scenario: GSLB has been configured for use within a multisite environment. The MEP status is reported as down on all GSLB appliances. The appliances have been configured for unsecured MEP exchange. Which port must the network engineer ensure is open between the NetScaler appliances?


Options are :

  • UDP 3012
  • UDP 3011
  • TCP 3011
  • TCP 3012

Answer : TCP 3011

1Y0-200 Managing Citrix XenDesktop 7 Solutions Practice Exam Set 3

Scenario: A network engineer created an SSL virtual server and enabled smart card on it. The engineer tried browsing to the server and noticed the back-end system could NOT see the users certificates. What could be causing this issue?


Options are :

  • The SSL virtual server cannot use smart card authentication.
  • The network engineer forgot to enable the SSL policy allowing smart card forwarding on the SSL virtual server.
  • The network engineer has not set smart card to mandatory.
  • The SSL virtual server cannot forward a client certificate.
  • The network engineer has not enabled SNI on the virtual server.

Answer : The SSL virtual server cannot forward a client certificate.

Scenario: An engineer configures two NetScaler appliances in a high availability (HA) pair. As part of a monthly health check, the engineer attempts to log on to the second node of the HA pair and is unable to access the management IP Address. The engineer logs on to the first NetScaler node and verifies that HA is working and operational. What does the engineer need to do to resolve this problem?


Options are :

  • Create an ACL to allow access to the NSIP of the second node.
  • Ensure that HA Route Monitors have been configured for the second node.
  • Add a SNIP for the Management IP Address of the second node.
  • Change the NSRoot password back to default then log on to the second node.

Answer : Create an ACL to allow access to the NSIP of the second node.

Scenario: The network engineer is unable to access a specific SSL site through the NetScaler. While reviewing traces on the NetScaler, the network engineer noticed "Handshake" failures from the server. These handshake failures could be the result of the virtual server __________. (Choose the correct option to complete the sentence.)


Options are :

  • only allowing TLS
  • not allowing correct ciphers
  • not allowing SSLv3
  • not allowing SSLv3

Answer : not allowing SSLv3

1Y0-200 Managing Citrix XenDesktop 7 Solutions Practice Exam Set 4

Scenario: A user browses to a page and is presented with a warning that he is trying to enter a web site with an untrusted certificate. The network engineer had added the correct certificate to the SSL virtual server. What could be the cause of this issue?


Options are :

  • The certificate has expired and needs to be renewed.
  • The CA certificate has not been added to the SSL virtual server.
  • TLS is disabled on the virtual server.
  • The certificate is not linked to the intermediate CA.

Answer : The certificate is not linked to the intermediate CA.

An environment network has: - High bandwidth - Low packet loss - High Round-Trip Time (RTT) Which TCP profile should an engineer configure for the environment described?


Options are :

  • Nstcp_default_tcp_lfp
  • Nstcp_default_tcp_lan
  • Nstcp_default_tcp_lnp
  • Nstcp_default_profile

Answer : Nstcp_default_tcp_lfp

Scenario: A network engineer needs to add an NTP server to a NetScaler appliance. The NTP service is configured on 10.10.1.49. Which command should the network engineer use within the command-line interface to add in an NTP server for time synchronization


Options are :

  • add ntp server 10.10.1.49
  • add service NTP 10.10.1.49 TCP 123
  • add service NTP 10.10.1.49 UDP 123
  • add server NTP 10.10.1.49

Answer : add ntp server 10.10.1.49

1Y0-200 Managing Citrix XenDesktop 7 Solutions Practice Test Set 1

Scenario: An engineer implementing a NetScaler is tasked with creating a new VLAN, named VLAN 2, and adding it to the current interfaces. A new IP address of 10.102.29.54 with a network mask of 255.255.255.0 must be configured for VLAN 2. Which commands could the engineer use to achieve this configuration in the command-line interface prior to binding VLAN 2?


Options are :

  • add ns ip 10.102.29.54 255.255.255.0 add vlan 2
  • add ns ip 10.102.29.54 255.255.255.0 -type SNIP set ns ip 10.102.29.54 255.255.255.0 -vrID 2
  • set vlan 2 -aliasName VLAN2 add ns ip 10.102.29.54 255.255.255.0
  • add ns ip 10.102.29.54 255.255.255.0 -vrID 2

Answer : add ns ip 10.102.29.54 255.255.255.0 add vlan 2

Scenario: A network engineer has created two selectors to use to populate a cache group in integrated caching. One selector, "Hit," will determine what to add to the group. Theother, "Inval", will select what should be invalidated. Which command should the engineer run to create the cache group?


Options are :

  • add cache contentgroup CacheGroup1 -hitParams Hit -invalParam Inval
  • add cache contentgroup CacheGroup1 -hitSelector Hit -invalSelector Inval
  • set cache contentgroup CacheGroup1 -hitSelector Hit - invalSelector Inval -type HTTP
  • set cache contentgroup CacheGroup1 - hitParams Hit -invalParam Inval -type HTTP

Answer : add cache contentgroup CacheGroup1 -hitSelector Hit -invalSelector Inval

1Y0-200 Managing Citrix XenDesktop 7 Solutions Practice Test Set 2

The disk is full on a NetScaler appliance but NO alerts were generated by the SNMP traps. What is the likely cause of this failed alert?


Options are :

  • EdgeSight monitoring is not configured.
  • Auditing is not enabled.
  • The threshold was not set for the alarm.
  • Health monitoring has not been enabled.

Answer : The threshold was not set for the alarm.

Which NetScaler feature could be used to stall policy processing to retrieve information from an external server?


Options are :

  • HTTP callout
  • AppExpert template
  • EdgeSight monitoring
  • Responder

Answer : HTTP callout

Scenario: A network engineer has bound a service group containing four web servers to a virtual server. The virtual server is UP but users report that they are unable to access the virtual server. In order to troubleshoot this issue, the engineer should use telnet from __________. (Choose the correct option to complete the sentence.)


Options are :

  • the NetScaler shell to one of the web servers
  • a PC to the subnet IP address
  • a PC to the mapped IP address
  • a PC to the virtual IP address

Answer : a PC to the virtual IP address

1Y0-200 Managing Citrix XenDesktop 7 Solutions Practice Test Set 3

Comment / Suggestion Section
Point our Mistakes and Post Your Suggestions