1Y0-250 Implementing Citrix NetScaler 10 for App and Desktop Solutions Practice Exam Section 1: Assessing infrastructure needs for the NetScaler implementation 1.1 Task Description: Verify the objectives of the NetScaler implementation Testing Aspect: What 1. Scenario: An administrator is planning to implement a remote access solution with the following requirements: 400 users can access published applications only 50 users can access XenDesktop virtual desktops only What should the administrator configure to meet the requirements? a. Session Reliability b. Workspace control c. A Web Interface site d. Two-factor authentication Answer: c. Explanation: A Web Interface deployment involves the interaction of three network components: One or more server farms, a web server, and a user device with a web browser and a Citrix client. A group of servers that are managed as a single entity and operate together to serve resources to users are collectively known as a server farm. A server farm is composed of a
number of servers all running either XenApp or XenDesktop, but not a mixture of both. Using a Web Interface site, users can log on to a server farm and receive a customized list of resources published for their individual user name. Source: Technologies > Web Interface > Web Interface 5.4 > Web Interface Administration > Web Interface Components http://support.citrix.com/proddocs/topic/web-interface-impington/wiweb-interface-components-gransden.html Section 2: Designing the NetScaler implementation 2.1 Task Description: Develop the implementation plan Testing Aspect: What (things to consider) 2. An administrator is planning a NetScaler deployment and is considering the requirements for syslog messages to be forwarded to an external syslog service. Which port should the administrator ensure is open on the firewall between the NetScaler appliance and syslog server? a. 23 b. 162 c. 514 d. 1433 Answer: c.
Explanation: Syslog events generated by the NetScaler appliances can be monitored in the NetScaler Insight Center inventory if the NetScaler Insight Center virtual appliance is configured to redirect all syslog messages to the syslog servers. To monitor syslog events, a dedicated syslog server must exist. A syslog server is an external server that displays the log events generated by NetScaler Insight Center. When designating a syslog server, the port at which the system sends and receives data when the operation is performed is port 514 by default. Port 514 should be open on the firewall between the NetScaler appliance and syslog server. Source: NetScaler > NetScaler Insight Center > NetScaler Insight Center 10.1 > Troubleshooting and Diagnostics > Monitoring Syslog Events http://support.citrix.com/proddocs/topic/ni-10-1-map/ni-troubleshootsyslog-intro.html Section 3: Building the solution to enable remote access 3.1 Task Description: Obtain and install licenses Testing Aspect: How 3. Scenario: A company purchased a NetScaler appliance. An administrator is in the process of installing a Platform license. What information does the administrator need to obtain the license? a. Host name b. The license code c. NetScaler IP address d. NetScaler DNS Name
Answer: a. Explanation: Obtain Platform or Universal license files from Citrix after installing NetScaler Gateway. Log on to the Citrix web site to access available licenses and generate a license file. After the license file is generated, download it to a computer. When the license file is on the computer, upload it to NetScaler Gateway. Before obtaining license files, configure the host name of the appliance by using the Setup Wizard and then restart the appliance. Source: NetScaler Gateway > NetScaler Gateway 10.1 > Licensing > Obtaining Your Platform or Universal License Files http://support.citrix.com/proddocs/topic/netscaler-gateway-101/nglicense-obtain-tsk.html Section 4: Securing the NetScaler (i.e. enabling compliance, SSL VPN, etc.) 4.1 Task Description: Consider the compliance and security capabilities that are native to NetScaler Testing Aspect: When 4. Scenario: A user connected through the Access Gateway SSL VPN to the corporate LAN using a hotel WIFI connection. Security policies state that users should NOT be able to browse local Internet resources. Which setting should an administrator configure to comply with the security policies?
a. Disable Split Tunneling. b. Change client default gateway address. c. Create a DHCP pool on the Access Gateway. d. Add an IP address range to the Domain/IP Conflict list. Answer: a. Explanation: When split tunneling is not enabled, the Access Gateway Plugin captures all network traffic originating from a user device and sends the traffic through the VPN tunnel to Access Gateway, which can have an authorization policy that does not allow users to browse local Internet resources. Source: NetScaler Gateway > Access Gateway 10 > Connect Users > Configuring Connections for the Access Gateway Plug-in > Configuring Split Tunneling http://support.citrix.com/proddocs/topic/access-gateway-10/agee-agplugin-split-tunneling-tsk.html Section 5: Integrating with Citrix, Microsoft and 3rd-party technologies 5.1 Task Description: Configure Secure Ticket Authority (STA) when configuring NetScaler for integration with XenDesktop/XenApp Testing Aspect: How 5. Scenario: A company uses a NetScaler appliance for secure remote access to XenApp hosted resources. The following components exist in the environment:
STAs - XenApp1.example.local, XenApp2.example.local Access Gateway virtual server - remote.example.com XenApp2 will be decommissioned and removed as an STA. Using the command line interface, which command should an administrator use to remove XenApp2 from Access Gateway? a. rm server XenApp2.example.local b. rm service XenApp2.example.local c. unbind vpn vserver remote.example.com -staserver http://remote.example.com d. unbind vpn vserver remote.example.com -staserver http://xenapp2.example.local/scripts/ctxsta.dll Answer: d. Explanation: To remove an STA vserver from Access Gateway, use the command: unbind vpn vserver <name> -staserver <URL> Source: Citrix NetScaler Command Reference Guide - Release 10, Pages 1309 and 1310 http://support.citrix.com/article/ctx132384 Section 6: Configuring Disaster Recovery (i.e. for NetScaler appliance, server/service and datacenter failures) 6.3 Task Description: Configure high availability
Testing Aspect: How 6. Scenario: A company has a NetScaler appliance in their main datacenter. Due to a recent merger, the company is required to purchase another NetScaler appliance and provide high availability (HA). An administrator will use the small datacenter as disaster recovery site that is located in a different physical location and has a different subnet than main datacenter. Which action should the administrator take to configure the NetScaler appliances? a. Setup a NetScaler Cluster with both NetScaler nodes. b. Configure VMAC addresses for both NetScaler nodes. c. Ensure that INC mode is enabled during the creation of the HA Pair. d. Change the NSIP of the second NetScaler appliance to be on the same subnet as the first NetScaler appliance. Answer: c. Explanation: When in INC mode, route monitors are neither propagated by nodes nor exchanged during synchronization but they are active on both the primary and secondary nodes. Also, each NetScaler appliance displays the state of the route monitor as DOWN if the corresponding route entry is not present in the internal routing table. Source: NetScaler > NetScaler 10 > System > High Availability > Configuring Route Monitors http://support.citrix.com/proddocs/topic/ns-system-10-map/ns-nw-hacnfgrng-route-mntrs-con.html
Section 7: Customizing Traffic in a NetScaler implementation 7.1 Task Description: Configure Responder, Rewrite, or URL transform Testing Aspect: How (Consider the when) 7. Scenario: Once a month, an administrator makes changes to the content of a company's website and must ensure that all users can access a temporary backup website while making the changes. Using NetScaler, which configuration should the administrator employ? a. Set a Redirect URL and disable the web site virtual server. b. Create a Rewrite Policy and bind it to the web site virtual server. c. Create a Responder Policy and bind it to the web site virtual server. d. Configure a URL Transformation policy and bind it to the web site virtual server. Answer: a. Explanation: When redirecting client requests to an alternative URL, NetScaler redirects HTTP or HTTPS client requests when the push virtual server is down or disabled. This URL can be a local or a remote link. Redirects can be absolute URLs or relative URLs. The domain specified in the redirect URL must not be the same as the domain specified in the domain name argument of a content switching policy. If the same domain is specified in both arguments, the request is redirected continuously to the same unavailable virtual server in the NetScaler appliance, and the user cannot get the requested content.
Source: NetScaler > NetScaler 10.1 > Traffic Management > NetScaler Web 2.0 Push > Customizing the NetScaler Web 2.0 Push Configuration > Redirecting Client Requests to an Alternative URL http://support.citrix.com/proddocs/topic/netscaler-traffic-management- 10-1-map/ns-web-push-redirct-client-req-altrntv-url-tsk.html Section 8: Setting up auditing, monitoring and reporting for the NetScaler implementation 8.1 Task Description: Determine what needs to be monitored (services/servers) Testing Aspect: Where [method] to send what [services/sercers/etc] monitoring information 8. Scenario: A company added a new datacenter to their network. An administrator installed a NetScaler appliance and has concerns with the overall power condition in the datacenter. The administrator should configure to receive notification of a device failure in the datacenter. (Choose the correct option to complete the sentence.) a. SNMP b. Syslog c. Route Monitors d. Failover Interface Set Answer: a.
Explanation: The Simple Network Management Protocol (SNMP) network management application, running on an external computer, queries the SNMP agent on the NetScaler. The agent searches the management information base (MIB) for data requested by the network management application and sends the data to the application. SNMP monitoring uses traps messages and alarms. SNMP traps messages are asynchronous events that the agent generates to signal abnormal conditions, which are indicated by alarms. Source: NetScaler > NetScaler 10 > Getting Started with Citrix NetScaler > Configuring System Management Settings > Configuring SNMP http://support.citrix.com/proddocs/topic/netscaler-getting-started-map- 10/ns-gen-config-snmp-intro.html Section 9: Troubleshooting issues on NetScaler 9.1 Task Description: Debug Authentication, Authorization and Accounting (AAA) Testing Aspect: How 9. Scenario: A company uses a custom SSH monitoring software to execute commands on a NetScaler appliance. For security reasons, an administrator created a dedicated local user account and assigned the user to the operator command policy. The monitoring software generates the following error message during some operations: ERROR: Not authorized to execute this command Which log file can be used to find the denied commands?
a. ns.log b. auth.log c. ntpd.log d. wicmd.log Answer: a. Explanation: NetScaler keeps track of the interfaces through which operations are executed. View the information in the ns.log file, located in the /var/log/ directory. Source: NetScaler > NetScaler 10.5 > Release Notes > NetScaler 10.5 (Main) Release Notes http://support.citrix.com/proddocs/topic/ns-rn-main-release-10-5- map/netscaler-10-5-rn.html 9.13 Task Description: Troubleshooting the NetScaler start up, possibly including web portal page (modification/customizing) Testing Aspect: Where 10. Scenario: An administrator applied the Receiver Theme to the Logon Page on a NetScaler. One morning after a few weeks had passed, users reported that the Logon Page had changed. The administrator decided to rebuild the configuration. In which directory should the administrator launch the command: tar -xvzf receivertheme.tar.gz? a. /var/netscaler/gui/vpns/receivertheme b. /var/netscaler/gui/customization/receivertheme
c. /var/netscaler/vpns/customization/receivertheme d. /var/netscaler/gui/vpns/customization/receivertheme Answer: d. Explanation: The administrator should make an SSH connection to NetScaler. Type shell. Type cd /var/netscaler/gui/vpns/customization/receivertheme. Type tar xvzf receivertheme.tar.gz. Source: Citrix Discussions - Apply the Citrix Receiver theme to the AGEE logon page - How? http://discussions.citrix.com/topic/305441-apply-the-citrix-receiver-themeto-the-agee-logon-page-how