Skip to content

1Y0-231 Deploy and Manage Citrix ADC 13 with Citrix Gateway Practice Questions

Prepare for 1Y0-231 with more than an answer.

265 questions in the full set20 sample questionsUpdated Sep 16, 2021
Exam fee
$200 USD
Level
Associate
Valid for
3 years
Domains covered on the exam 14
  1. Authentication and Authorization14%
  2. Managing Client Connections10%
  3. Integration for Citrix Virtual Apps and Desktop Solutions8%
  4. Troubleshooting8%
  5. Load Balancing8%
  6. Basic Networking8%
  7. SSL Offload6%
  8. Securing the Citrix ADC6%
  9. High Availability6%
  10. AppExpert6%
  11. Citrix Gateway5%
  12. Getting Started5%
  13. Citrix ADC Platforms5%
  14. Customizing Citrix Gateway5%
  1. 1

    Scenario: A Citrix Administrator deployed a Citrix ADC in one-arm mode. Currently, the VLANs 20, 30, and 40 are tagged on the interface with the option of ‘tagall’.

    What is true regarding the VLANs, when ‘tagall’ is enabled on the interface?

    Show answer details

    Correct answer: C

    Health monitoring (monitors) are the correct feature for automatically checking the status and availability of backend servers to ensure traffic is only sent to healthy, responsive servers. Health monitors perform regular checks using various protocols (HTTP, TCP, ping) to verify server functionality and remove failed servers from load balancing rotation. Load balancing distributes traffic but does not check server health, persistence ensures client affinity to specific servers, and SSL bridging handles encryption processing rather than server health verification.

  2. 2

    Scenario: A Citrix Administrator needs to create local, limited-privilege user accounts for other administrators. The other administrators will require only:

    • The ability to enable and disable services and servers
    • Read-only access

    Which built-in command policy permission level can the administrator use?

    Show answer details

    Correct answer: B

    Operator is the correct built-in command policy for administrators who need the ability to enable/disable services and servers while maintaining read-only access to other configurations. The Operator command policy provides specific permissions for service and server state management operations while restricting access to configuration modifications, SSL certificate management, and system-level changes. This role is designed specifically for operational staff who need to perform routine maintenance tasks without full administrative privileges. Read-only policies prevent any modifications including service state changes, while Superuser and Network policies provide broader permissions beyond the limited requirements specified for these departmental administrators.

  3. 3

    Scenario: A Citrix Administrator is managing a Citrix Gateway with a standard platform license and remote employees in the environment. The administrator wants to increase access by 3,000 users through the Citrix Gateway using VPN access.

    Which license should the administrator recommend purchasing?

    Show answer details

    Correct answer: C

    Citrix Gateway Universal license is required to support large-scale VPN access for 3,000 additional users beyond the standard platform license limitations. Universal licenses provide higher concurrent user limits and advanced VPN functionality needed for enterprise-scale remote access deployments. Gateway Express has lower user limits, ADC Upgrade affects appliance features but not Gateway user capacity, and Burst Pack provides temporary scaling but not permanent capacity increases.

  4. 4

    In a single-hop deployment, a Citrix Administrator needs to use a client’s IP address as the source IP address for Citrix ADC-to-server connections.

    Which Citrix ADC mode can the administrator use to meet this requirement?

    Show answer details

    Correct answer: A

    USIP (Use Source IP) mode enables the Citrix ADC to preserve the client's original IP address as the source IP when connecting to backend servers in single-hop deployments. This is essential for applications requiring client IP visibility for logging, security policies, or geographic restrictions. USNIP (Use Subnet IP) uses ADC's own subnet IP, Layer 2 mode operates at data link level without IP modification, and Layer 3 mode uses routing but does not preserve client source IP.

  5. 5

    A Citrix ADC is configured in two-arm mode. A SNIP (192.168.10.20) on VLAN 10 is used to communicate with backend servers on the 192.168.10.0/24 network. The administrator has enabled Management Access on this SNIP. However, administrators on the management network (172.16.1.0/24) cannot access the ADC's management interface via the SNIP's IP address. A firewall between the networks allows all traffic. What is the most likely reason for this failure?

    graph TD subgraph Mgmt_Network ["Management Network (172.16.1.0/24)"] AdminPC[Admin PC] end subgraph Server_Network ["Server Network (192.168.10.0/24)"] Server1[Server 1] Server2[Server 2] end subgraph ADC NSIP[NSIP 10.0.0.5] SNIP[SNIP 192.168.10.20] end AdminPC -->|Attempt Mgmt| SNIP SNIP --x|No Route Back| AdminPC SNIP -->|Server Traffic| Server1

    Show answer details

    Correct answer: B

    When a management request hits the SNIP from the 172.16.1.0/24 network, the ADC needs to send the reply back. Since the source of the request is not on the SNIP's directly connected subnet (192.168.10.0/24), the ADC must have a route in its routing table that directs traffic for 172.16.1.0/24 to the appropriate gateway on VLAN 10. Without this route, the return traffic will be dropped or sent out the default gateway, which may not be correct, causing the connection to fail.

  6. 6

    A Citrix Administrator wants to customize the look of the landing page presented to users during the authentication process on Citrix ADC.

    Which nFactor component should the administrator modify in this scenario?

    Show answer details

    Correct answer: A

    Logon Schema is the correct nFactor component for customizing the authentication landing page appearance and user interface elements during the Citrix ADC authentication process. Logon Schemas define the visual presentation, form fields, layout, and branding elements that users see when authenticating. Pass-through factors handle authentication flow without user interaction, Next factors define subsequent authentication steps in multi-factor scenarios, and NoAuth policies bypass authentication entirely rather than customizing the presentation interface.

  7. 7

    A Citrix Network Engineer informs a Citrix Administrator that a data interface used by Citrix ADC SDX is being saturated.

    Which action could the administrator take to address this bandwidth concern?

    Show answer details

    Correct answer: C

    Configure LACP on the SDX for the data interface is the correct solution for addressing bandwidth saturation on Citrix ADC SDX data interfaces. Link Aggregation Control Protocol (LACP) combines multiple physical interfaces into a single logical channel, increasing available bandwidth and providing redundancy. Adding interfaces to individual VPX instances would not address the underlying SDX infrastructure bottleneck, configuring LACP on management interfaces does not improve data plane capacity, and failover interface sets provide redundancy but not additional bandwidth.

  8. 8

    Scenario: A Citrix Administrator is configuring a new authentication, authorization, and auditing (AAA) virtual server, and the status is DOWN. The administrator makes the below configurations:

    add lb vserver lb_vsrv_www HTTP 10.107.149.229 80 -persistenceType NONE -cltTimeout 180 -authn401 ON -authnVsName SAML_SP
    bind lb vserver lb_vsrv_www_ssl Red_srv
    bind lb vserver lb_vsrv_www_ssl Blue_srv
    add authentication vserver SAML_SP SSL 10.107.149.230 443 -AuthenticationDomain citrix.lab

    What should the administrator bind to the virtual server SAML_SP to complete the installation and change the status to UP?

    Show answer details

    Correct answer: C

    An AAA policy is required to bring the AAA virtual server to UP status and enable authentication functionality. AAA virtual servers require bound authentication policies (such as LDAP, RADIUS, or SAML policies) to properly authenticate users and transition from DOWN to UP status. SSL certificates are used for secure communication but not required for basic AAA functionality, services are bound to load balancing virtual servers rather than AAA virtual servers, and while LDAP could work, the question asks generically for what is needed, making AAA policy the most complete answer.

  9. 9

    Scenario: A Citrix ADC MPX is using one of four available 10G ports. A Citrix Administrator discovers a traffic bottleneck at the Citrix ADC.

    What can the administrator do to increase bandwidth on the Citrix ADC?

    Show answer details

    Correct answer: B

    Adding another 10G port to the switch and configure LACP is the optimal solution for increasing bandwidth on the Citrix ADC MPX when experiencing traffic bottlenecks. Link Aggregation Control Protocol (LACP) allows multiple physical interfaces to operate as a single logical interface, effectively doubling or multiplying available bandwidth while providing redundancy. Configuring VLANs does not increase bandwidth, purchasing another appliance would be costly and complex for a simple bandwidth issue, and plugging into a router may not address the bottleneck at the switch level.

  10. 10

    What can the administrator configure to accomplish this?

    Show answer details

    Correct answer: A

    SmartControl is the correct Citrix Gateway feature for implementing granular application access control and selective application publishing based on user credentials, device compliance, and security policies. SmartControl policies allow administrators to control which applications users can access based on authentication status, device certificates, endpoint analysis results, and other contextual factors. Extended ACLs provide network-level access control but not application-specific control, and AppFlow is used for monitoring and analytics rather than access control.

Create an account to continue.