1Y0-341 Practice Test Questions Updated 110 Questions
Citrix 1Y0-341 Dumps - Secret To Pass in First Attempt
For more info visit:
How to book the Citrix ADC Advanced Concepts - Security, Management and Optimization
These are the following steps for registering for the 1Y0-341 exam.
Step 1: Visit to Pearson VUE Exam Registration Step 2: Signup/Login to Pearson VUE account Step 3: Search for Citrix 1Y0-341 Exam Step 4: Select Date, time and confirm with the payment method
NEW QUESTION 29
Scenario: A Citrix Engineer created the policies in the attached exhibit.
Click the Exhibit button to view the list of policies.
HTTP Request:
GET /resetpassword.htm HTTP/1.1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:64.0) Gecko/20100101 Firefox/64.0 Host: www.citrix.com Accept-Language: en-us Accept-Encoding: gzip, deflate Connection: Keep-Alive Which profile will be applied to the above HTTP request?
- A. Profile_A
- B. Profile_D
- C. Profile_B
- D. Profile_C
Answer: C
NEW QUESTION 30
Which data populates the Events Dashboard?
- A. SNMP trap messages
- B. API calls
- C. AppFlow IPFIX records
- D. Syslog messages
Answer: D
NEW QUESTION 31
Which aspect of NetScaler Management and Analytics System (NMAS) can be used to monitor end- to-end ICA traffic flowing through a NetScaler ADC?
- A. Gateway Insight
- B. Security Insight
- C. Web Insight
- D. HDX Insight
Answer: D
NEW QUESTION 32
A Citrix Engineer needs to ensure that all traffic to the virtual server is blocked if NONE of the bound Application Firewall policies are matched.
Which setting can the engineer configure to meet this requirement?
- A. set ns httpProfienshttp_default_profile dropInvalReqs ENABLED
- B. set ns httpProfilenshttp_default_profile-dropInvalReqs DISABLED
- C. set appfw settings undefAction APPFW_BLOCK
- D. set appfw settings defaultProfile APPFW_BLOCK
Answer: D
NEW QUESTION 33
Scenario: A Citrix Engineer must enable a cookie consistency security check and ensure that all the session cookies get encrypted during the transaction. The engineer needs to ensure that none of the persistent coolies are encrypted and decrypted and decrypt any encrypted cookies during the transaction. Which cookie consistency security feature will the engineer configure in the following configuration to achieve the desired results?
add appfw profile Test123 startURLAction none- denyURLAction none- cookieConsistencyAction log - cookieTransforms ON cookieEncryptionecryptSessionOnly addCookieFlagshttpOnly - crossSiteScriptingAction none- SQLInjectionAction log stats SQLInjectionTransfrormSpecialChars ON- SQLInjectionCheckSQLWildChars ON fieldFormatAction none bufferOverflowAction none - responseContentType "application/octet- stream"- XMLSQLInjectionAction none XMLXSSAction none- XMLWSIAction none- XMLValidationAction none
- A. Configure Encrypt Server cookies to "Encrypt Session Only"
- B. Configure Encrypt Server cookies to "Encrypt All"
- C. Configure Encrypt Server cookies to "None"
- D. Configure Encrypt Server cookies to "Encrypt only"
Answer: C
NEW QUESTION 34
A Citrix Engineer has configured SQL Injection security check to block all special characters. Which two requests will be blocked after enabling this check? (Choose two.)
- A. Citrix OR 1=1
- B. Citrix; Sqltest
- C. 175// OR 1//=1//
- D. 175' OR `1'= `1'
- E. Citrix" OR "1"="1
Answer: B,C
NEW QUESTION 35
Scenario: A Citrix Engineer needs to configure an Application Firewall policy for an online shopping website called "mycompany.com". As a security measure, the shopping cart application is hosted on a separate directory "/mycart" on the backend server. The engineer configured a profile to secure the connections to this shopping cart and now needs to ensure that this profile is allied to all incoming connections to the shopping cart.
Which policy expression will accomplish this requirement?
- A. http.req.header ("url").contains ("/mycart") || http.req.url.contains ("mycompany.com")
- B. http.req.header ("url").contains ("/mycart") && http:req.url.contains ("mycompy.com")
- C. http.req.url.contains("/mycart") || http:req.url.hostname.eq("mycompany.com")
- D. http.req.url.contains("/mycart") & http:req.url.hostname.eq("mycompany.com")
Answer: D
NEW QUESTION 36
Which build-in TCP profile can a Citrix Engineer assign to a virtual server to improve performance for users who access an application from a remote office over an ATM connection?
- A. nstcp_default_tcp_lan
- B. nstcp_default_tcp_lfp
- C. nstcp_default_tcp_interactive_stream
- D. nstcp_default_tcp_lnp
Answer: C
NEW QUESTION 37
Scenario: A Citrix Engineer wants to protect a web application using Citrix Web App Firewall.
After the Web App Firewall policy afweb_protect is bound to the virtual server, the engineer notices that Citrix Web App Firewall is NOT properly displaying the page.
A positive number for the Policy Hits counter for afweb_protect, tells the engineer the number of times Citrix Web App Firewall ___________. (Choose the correct option to complete the sentence.)
- A. forwarded users to the Redirect URL specified in the profile assigned to afweb_protect
- B. blocked traffic for web applications assigned the afweb_protect policy
- C. received a request that matched the policy expression for afweb_protect
- D. logged a request matching the expression defined in the afweb_protect policy
Answer: D
NEW QUESTION 38
Scenario: A Citrix Engineer observes that when going through NetScaler, user connections fail and users are unable to access Exchange server. However, users can connect directly to the Exchange server. After checking the logs, the engineer finds that the POST request is blocked through the NetScaler.
The log in/ var/log/ns.log is as follows:
Jul 20 11:00: 38 <local0.info>x.x.x. 1 07/20/2017:11:00:38 GMT ns 0-PPE-0:APPFW AF_400_RESP
29362 0: x.x.x.1 439800-PPEO- urlwdummy
https://test.abc.com/rpc/rpcproxy.dll?mail.sfmta.com:6004 Bad request headers. Content-length exceeds post body limit <blocked> Which parameter can the engineer modify to resolve the issue while maintaining security?
- A. Add an Application Firewall policy with the expression "HTTP.REQ.METHOD.EQ(\ "POST"\)" with APPFW_BYPASS profile bound.
- B. Increase the Maximum Header Length under nshttp_default_profile.
- C. Increase the POST body limit under common settings in Application Firewall profile settings.
- D. Increase the POST body limit using the HTTP profile.
Answer: C
NEW QUESTION 39
Scenario: A Citrix Engineer has deployed four NetScaler MPXs with the following network configuration:
- Management traffic is on VLAN 5 (NSIP).
- Application and server traffic is on VLAN 10 (SNIP).
The engineer added the NetScaler Management and Analytics System (NMAS) interface to VLAN
10 to deploy a NMAS High Availability (HA) pair to manage and monitor the applications and virtual servers. After doing so, the engineer is NOT able to see the NetScaler or applications that need to be managed.
How can the engineer resolve the issue?
- A. Move the NMAS interface to VLAN 5
- B. Configure VLAN 5 as NSVLAN 5
- C. Configure VLAN 5 as NSSYNC VLAN
- D. Bind SNIP to VLAN 5
Answer: B
NEW QUESTION 40
Scenario: A Citrix Engineer configures Citrix Web App Firewall to protect an application. Users report that they are NOT able to log on. The engineer enables a Start URL relaxation for the path //login.aspx.
What is the effect of the Start URL relaxation on the application?
- A. Access to the path /login.aspx is blocked.
- B. Access to the path /login.aspx is unblocked.
- C. External users are blocked from the path /login.aspx.
Internal users are permitted to the path /login.aspx. - D. Non-administrative users are blocked from the path /login.aspx
Administrative users are permitted to the path /login.aspx.
Answer: B
Explanation:
Explanation/Reference:
NEW QUESTION 41
The NetScaler processes HTTP/2 web client connections to the backend web servers by _________.
(Choose the correct option to complete the sentence.)
- A. Dropping HTTP/2 requests as it is NOT supported by web servers.
- B. Passing- through all HTTP/2 traffic to the web servers.
- C. Converting HTTP/2 to HTTP 0.9 and forwarding the packets to the web servers.
- D. Converting the HTTP/2 headers to HTTP/1.1 headers and forwarding them to the web servers.
Answer: D
NEW QUESTION 42
A Citrix Engineer observes the following event in the ns.log:
Aug 3 11:55:58 <local0.info> 10.248.64.10 08/03/2015:15:55:58 GMT ATL0NS01 0-PPE-1: default APPFW APPFW_STARTURL 406856 0: 10.248.13.13 11152-PPE1 LG+hd4LkcYiOyQVWvOTsCtSyiv00001 SPI Disallow illegal URL: https://training.citrix.com/login <blocked> Which Application Firewall profile has blocked the URL?
- A. APPFW_STARTURL
- B. SPI Disallow illegal URL
- C. ATL0NS01
- D. SPI
Answer: C
NEW QUESTION 43
Which protection ensures that links to sensitive pages can only be reached from within an application?
- A. Deny URL
- B. URL Closure
- C. Form Field Consistency Check
- D. Buffer Overflow Check
Answer: A
Explanation:
https://docs.citrix.com/en-us/citrix-adc/current-release/application-firewall/url-protections/denyurl- check.html
NEW QUESTION 44
Scenario: A Citrix Engineer has configured Security Insight on NetScaler Management and Analytics System (NMAS) with Firmware version 12.0.41.16 to monitor the Application Firewall. The NetScaler ADC is running version 12.0.51.24 using Enterprise License with Application Firewall only License. However, after enabling Security insight, the engineer is NOT able to see any data under security insight.
What is causing this issue?
- A. NetScaler should have a Platinum license.
- B. NetScaler should have a Standard License.
- C. NMAS should be on Platinum license.
- D. The NMAS version should be higher or equivalent to the NetScaler version.
Answer: D
NEW QUESTION 45
Which Citrix Application Delivery Management (ADM) feature can a Citrix Engineer use to narrow a list of Citrix ADC devices based on pre-defined criteria?
- A. Agent
- B. Instance Groups
- C. Tags
- D. Configuration Template
- E. AutoScale Groups
Answer: C
NEW QUESTION 46
A Citrix Engineer observes that when the application firewall policy is bound to the virtual server, some of the webpages are NOT loading correctly.
Which log file can the engineer use to view the application firewall-related logs in the native format?
- A. /var/log/iprep.log
- B. /var/log/ns.log
- C. /var/nslog/newnslog
- D. /var/nslog/ns.log
Answer: B
NEW QUESTION 47
Which action ensures that content is retrieved from the server of origin?
- A. NOCACHE
- B. CACHE
- C. MAY_CACHE
- D. MAY_NOCACHE
Answer: A
NEW QUESTION 48
Scenario: A Citrix Engineer is implementing Integrated Caching to increase performance of a web application. The Application Engineer replaces a small logo on the main page with a new one. Later on, when the engineer attempts to access the page, the old logo is displayed. Which enabled setting in the Content Group would cause this to happen?
- A. Do not cache - if size exceeds 500 KB
- B. Do not cache - if hits are less than 1
- C. Ignore browser's reload request
- D. Expire content after 60 seconds
Answer: C
NEW QUESTION 49
A Citrix Engineer has determined that users are able to access random URLs on a web site through bookmarks and by manually typing in the URLs to skip the pages required to reach that part of the website. Which two checks can the engineer enable to prevent this attack? (Choose two.)
- A. Start URL
- B. Deny URL
- C. HTML Cross-site scripting
- D. Buffer overflow
- E. Form Field Consistency
Answer: A,D
NEW QUESTION 50
......
Citrix 1Y0-341 Exam Dumps [2022] Practice Valid Exam Dumps Question: https://www.exam4pdf.com/1Y0-341-dumps-torrent.html
1Y0-341 Dumps - Grab Out For [NEW-2022] Citrix Exam: https://drive.google.com/open?id=1dbfedWBfX2uOtpjwFsSUbDg5LN0kSMt8

