A Citrix Engineer observes that the servers hosting a critical application are crashing on a regular basis. Which protection could the engineer implement on a Citrix Web App Firewall in front of the application?

A. Buffer Overflow Check
B. HTML Cross-Site Scripting (XSS)
C. Start URL
D. HTML SQL Injection

Correct Answer: A


Which Citrix Application Delivery Management (ADM) Analytics page allows a Citrix Engineer to monitor web application traffic?

A. Web Insight
B. WAN Insight
C. HDX Insight
D. Gateway Insight

Correct Answer: A

Reference: https://docs.citrix.com/en-us/citrix-application-delivery-management- service/analytics/hdxinsight.html


Which Citrix Application Delivery Management (ADM) Analytics page allows a Citrix Engineer to monitor the metrics of the optimization techniques and congestion control strategies used in Citrix ADC appliances?

A. Gateway Insight
B. TCP Insight
C. HDX Insight
D. Web Insight

Correct Answer: B

Reference: https://docs.citrix.com/en-us/tech-zone/design/reference-architectures/citrix-adm.html


Scenario: A Citrix Engineer has established protections for web applications using Citrix Web App Firewall. One of the application owners is concerned that some negative traffic is passing through to the application servers. The owner wants confirmation that Citrix Web App Firewall is blocking negative traffic. Which CLI command can the engineer use to display statistics on a per-protection basis for the enabled protections?

A. stat appfw policyjabel
B. stat appfw policy
C. stat appfw profile
D. stat appfw signature

Correct Answer: C


Scenario: A Citrix Engineer needs to ensure that the flow of traffic to a web application does NOT overwhelm the server.
After thorough testing, the engineer determines that the application can handle a maximum of 3,000 requests per minute. The engineer builds a limit identifier, rl_maxrequests, to enforce this limitation.
Which advanced expression can the engineer write in the Responder policy to invoke rate-limiting?

A. SYS.CHECK_LIMIT(“rl_maxrequests”)
B. SYS.CHECK_LIMIT(“rl_maxrequests”).CONTAINS(“Busy”)
C. SYS.CHECK_LIMIT(“rl_maxrequests”).IS_VALID
D. SYS.CHECK_LIMIT(“rl_maxrequests”).GE(3000)

Correct Answer: B

Reference: https://support.citrix.com/article/CTX134009


Which Front End Optimization technique overcomes the parallel download limitation of web browsers?

A. Domain Sharding
B. Minify
C. Extend Page Cache
D. Lazy Load

Correct Answer: A

Reference: https://docs.citrix.com/en-us/citrix-adc/current-release/optimization/front-end- optimization.html


Scenario: A Citrix Engineer needs to limit Front End Optimization (FEO) on a web application to mobile users with mobile devices. The engineer decides to create and bind an FEO policy.
Which advanced expression should the engineer use in the FEO policy?


Correct Answer: A


A Citrix Engineer needs to create a configuration job to clone a configuration from an existing Citrix ADC to a new Citrix ADC.
Which configuration source can the engineer use to accomplish this?

A. Master Configuration
B. Inbuilt Template
C. Instance
D. Configuration Template

Correct Answer: C

Reference: https://docs.citrix.com/en-us/citrix-application-delivery-management-software/current-release/stylebooks/migrate-citirx-adc-application-configuration-using-stylebooks.html


Scenario: A Citrix Engineer is notified that improper requests are reacting the web application. While investigating, the engineer notices that the Citrix Web App Firewall policy has zero hits.
What are two possible causes for this within the Citrix Web App Firewall policy? (Choose two.)

A. The expression is incorrect.
B. It has been assigned an Advanced HTML profile.
C. It is NOT bound to the virtual server.
D. It has been assigned the built-in APPFW_RESET profile.

Correct Answer: AC


How can a Citrix Engineer monitor the Citrix ADC appliances to check that all SSL certificates have a key strength of at least 2048 bits from the SSL Dashboard Settings?

A. Delete 512, 1024, and 4096 on the Enterprise Policy tab.
B. Delete 512 and 1024 on the Enterprise Policy tab.
C. Select 2048 and 4096 on the Enterprise Policy tab.
D. Select 2048 on the Enterprise Policy tab.

Correct Answer: D

Reference: https://docs.citrix.com/en-us/citrix-adc/current-release/ssl/faq-ssl1.html


What can a Citrix Engineer implement to protect against the accidental disclosure of personally identifiable information(PII)?

A. Form Field Consistency
B. HTML Cross-Site Scripting
C. Safe Object
D. Cookie Consistency

Correct Answer: C

Reference: https://docs.citrix.com/en-us/citrix-adc/current-release/application-firewall/form-protections/ form-field-consistency-check.html


Which protection ensures that links to sensitive pages can only be reached from within an application?

A. Form Field Consistency Check
B. Buffer Overflow Check
C. URL Closure
D. Deny URL

Correct Answer: C

Reference: https://docs.citrix.com/en-us/citrix-adc/current-release/application-firewall/url-protections/ denyurl-check.html


Which setting in the Cookie Consistency protection feature does a Citrix Engineer need to configure to ensure that all a cookie is sent using TLS only?

A. Encrypt Server Cookies > Encrypt All
B. Flags to Add in Cookies > Secure
C. Encrypt Server Cookies > Encrypt Session Only
D. Proxy Server Cookies > Session Only

Correct Answer: B

Reference: https://docs.citrix.com/en-us/citrix-adc/current-release/application-firewall/cookie-protection/ cookie-consistency-check.html


