Deploy and Manage Citrix ADC 13 with Citrix Gateway Free Sample Questions

20 free sample questions265 in the full practice test

Try simulator

1Y0-231 Sample Questions

  1. Question 1

    A Citrix Administrator wants to customize the look of the landing page presented to users during the authentication process on Citrix ADC.

    Which nFactor component should the administrator modify in this scenario?

    Answer and explanation

    Correct answer: A

    Logon Schema is the correct nFactor component for customizing the authentication landing page appearance and user interface elements during the Citrix ADC authentication process. Logon Schemas define the visual presentation, form fields, layout, and branding elements that users see when authenticating. Pass-through factors handle authentication flow without user interaction, Next factors define subsequent authentication steps in multi-factor scenarios, and NoAuth policies bypass authentication entirely rather than customizing the presentation interface.

  2. Question 2

    A Citrix Network Engineer informs a Citrix Administrator that a data interface used by Citrix ADC SDX is being saturated.

    Which action could the administrator take to address this bandwidth concern?

    Answer and explanation

    Correct answer: C

    Configure LACP on the SDX for the data interface is the correct solution for addressing bandwidth saturation on Citrix ADC SDX data interfaces. Link Aggregation Control Protocol (LACP) combines multiple physical interfaces into a single logical channel, increasing available bandwidth and providing redundancy. Adding interfaces to individual VPX instances would not address the underlying SDX infrastructure bottleneck, configuring LACP on management interfaces does not improve data plane capacity, and failover interface sets provide redundancy but not additional bandwidth.

  3. Question 3

    Scenario: A Citrix Administrator is configuring a new authentication, authorization, and auditing (AAA) virtual server, and the status is DOWN. The administrator makes the below configurations:

    add lb vserver lb_vsrv_www HTTP 10.107.149.229 80 -persistenceType NONE -cltTimeout 180 -authn401 ON -authnVsName SAML_SP
    bind lb vserver lb_vsrv_www_ssl Red_srv
    bind lb vserver lb_vsrv_www_ssl Blue_srv
    add authentication vserver SAML_SP SSL 10.107.149.230 443 -AuthenticationDomain citrix.lab

    What should the administrator bind to the virtual server SAML_SP to complete the installation and change the status to UP?

    Answer and explanation

    Correct answer: C

    An AAA policy is required to bring the AAA virtual server to UP status and enable authentication functionality. AAA virtual servers require bound authentication policies (such as LDAP, RADIUS, or SAML policies) to properly authenticate users and transition from DOWN to UP status. SSL certificates are used for secure communication but not required for basic AAA functionality, services are bound to load balancing virtual servers rather than AAA virtual servers, and while LDAP could work, the question asks generically for what is needed, making AAA policy the most complete answer.

  4. Question 4

    Scenario: A Citrix ADC MPX is using one of four available 10G ports. A Citrix Administrator discovers a traffic bottleneck at the Citrix ADC.

    What can the administrator do to increase bandwidth on the Citrix ADC?

    Answer and explanation

    Correct answer: B

    Adding another 10G port to the switch and configure LACP is the optimal solution for increasing bandwidth on the Citrix ADC MPX when experiencing traffic bottlenecks. Link Aggregation Control Protocol (LACP) allows multiple physical interfaces to operate as a single logical interface, effectively doubling or multiplying available bandwidth while providing redundancy. Configuring VLANs does not increase bandwidth, purchasing another appliance would be costly and complex for a simple bandwidth issue, and plugging into a router may not address the bottleneck at the switch level.

  5. Question 5

    What can the administrator configure to accomplish this?

    Answer and explanation

    Correct answer: A

    SmartControl is the correct Citrix Gateway feature for implementing granular application access control and selective application publishing based on user credentials, device compliance, and security policies. SmartControl policies allow administrators to control which applications users can access based on authentication status, device certificates, endpoint analysis results, and other contextual factors. Extended ACLs provide network-level access control but not application-specific control, and AppFlow is used for monitoring and analytics rather than access control.

  6. Question 6

    Scenario: After deploying a Citrix ADC in production, a Citrix Administrator notices that client requests are NOT being evenly distributed among backend resources. The administrator wants to change from the default load-balancing method to one that will help distribute the load more evenly.

    Which load-balancing method would ensure that the server with the least amount of network utilization is receiving new connections?

    Answer and explanation

    Correct answer: B

    Least bandwidth is the optimal load-balancing method for ensuring more even distribution of client requests based on current server utilization and available capacity. This method directs new connections to the server currently handling the least amount of bandwidth, helping to balance the load more evenly across backend resources. Least response time may still create uneven distribution if servers have different processing capabilities, least connection only considers connection count not actual workload, and least packets does not account for varying packet sizes or processing requirements.

  7. Question 7

    Which authentication type can a Citrix Administrator use to enable Citrix ADC authentication, authorization, and auditing (AAA) dual-factor authentication from a user’s mobile device app?

    Answer and explanation

    Correct answer: A

    LDAP authentication serves as the primary authentication factor in Citrix ADC AAA dual-factor authentication scenarios, typically combined with mobile device-based second factors like RADIUS OTP or native authenticator apps. LDAP validates user credentials against Active Directory or other directory services as the first factor, then the system can prompt for mobile device-based authentication as the second factor. LOCAL authentication stores credentials locally on the ADC rather than integrating with mobile devices, TACACS+ is primarily for network device management, and SAML is for federated single sign-on rather than dual-factor mobile authentication.

  8. Question 8

    Multiple answers

    A Citrix Administrator needs to integrate an existing certification-based authentication policy into an existing Citrix Gateway virtual server.

    Which three steps can the administrator take to accomplish this? (Choose three.)

    Answer and explanation

    Correct answers: D, E

    Server clustering is the appropriate high availability method for ensuring continuous service when backend servers fail in a load-balanced environment. Server clustering provides automatic failover between servers and maintains service continuity when individual servers become unavailable. High availability pairs are used for Citrix ADC appliances themselves rather than backend servers, load balancing distributes traffic but does not provide failover capabilities by itself, and SSL bridging is a traffic handling method rather than a high availability solution.

    HTTP redirect policy with URL rewriting is the correct method for redirecting client requests from HTTP to HTTPS while maintaining proper URL structure and query parameters. This ensures secure communication by automatically redirecting insecure HTTP requests to their secure HTTPS equivalents. Content switching policies route traffic based on content rather than performing redirects, SSL bridging handles SSL termination and re-encryption but does not perform HTTP-to-HTTPS redirection, and authentication policies handle user authentication rather than protocol redirection.

  9. Question 9

    Scenario: A Citrix Administrator configures an access control list (ACL) to block traffic from the IP address 10.102.29.5:

    add simpleacl rulel DENY -srclP 10.102.29.5

    A week later, the administrator discovers that the ACL is no longer present on the Citrix ADC.

    What could be the reason for this?

    Answer and explanation

    Correct answer: A

    The administrator did not run the apply ACL command, which is required to save simple ACL configurations to the Citrix ADC persistent configuration. Simple ACLs are temporary by default and only exist in running memory until explicitly applied using the 'apply simpleacl' command to make them persistent across reboots. Simple ACLs do not have automatic timeout periods of 60 or 600 seconds, and configuration loss due to restart would affect all configurations, not just ACLs.

  10. Question 10

    Which Citrix Gateway feature should a Citrix Administrator configure to allow traffic for specific iOS applications only?

    Answer and explanation

    Correct answer: B

    Per app VPN tunnel is the specific Citrix Gateway feature designed to allow traffic routing for designated iOS applications only, providing granular application-level VPN access control. This feature integrates with iOS MDM policies to selectively tunnel specific applications through the Citrix Gateway while allowing other traffic to flow directly. Full SSL VPN tunnel routes all traffic, Split DNS only affects name resolution, and SmartControl for iOS provides broader access control but not application-specific tunneling functionality.

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 265 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon