Citrix 1Y0-341 Real Exam Questions Test Engine Dumps Training With 110 Questions
1Y0-341 Actual Questions Answers PDF 100% Cover Real Exam Questions
NEW QUESTION 39
A Citrix Engineer is considered that malicious users could exploit a web system by sending a large cookie.
Which security check can the engineer implement to address this concern?
- A. Field Formats
- B. Start URL
- C. Content-type
- D. Buffer Overflow
Answer: D
NEW QUESTION 40
Which syntax is used to write a StyleBook?
- A. JSON
- B. XML
- C. LISP
- D. YAML
Answer: D
NEW QUESTION 41
Which meta-character can be used as a wildcard to match a single character in a given position?
- A. An asterisk (*)
- B. A forward slash (/)
- C. A period (.)
- D. A dollar Sign ($)
Answer: D
NEW QUESTION 42
A Citrix Engineer has defined an HTTP Callout, hc_authorized_location, to return the value
"Authorized" if client's IP address is on a list of authorized external locations.
Which advanced expression should the engineer use in a policy for testing this condition?
- A. SYS.HTTP_CALLOUT(hc_authorized_location).EQ("Authorized")
- B. SYS.HTTP_CALLOUT(hc_authorized_location).IS_VALID
- C. SYS.HTTP_CALLOUT(hc_authorized_location).EQUALS_ANY("Authorized")
- D. SYS.HTTP_CALLOUT(hc_authorized_location).IS_TRUE
Answer: C
NEW QUESTION 43
Scenario: A Citrix Engineer has configured Application Firewall and enabled it in learning mode.
However, the Application Firewall database is reaching full capacity due to excessive requests.
What can the engineer configure to mitigate this issue?
- A. Configure Trusted Learning Clients.
- B. Increase NetScaler hard drive capacity.
- C. Configure caching policies.
- D. Enable learning only on XML based profiles.
Answer: A
NEW QUESTION 44
How can a Citrix Engineer monitor the Citrix ADC appliances to check that all SSL certificates have a key strength of at least 2048 bits from the SSL Dashboard Settings?
- A. Delete 512 and 1024 on the Enterprise Policy tab.
- B. Select 2048 and 4096 on the Enterprise Policy tab.
- C. Select 2048 on the Enterprise Policy tab.
- D. Delete 512, 1024, and 4096 on the Enterprise Policy tab.
Answer: B
Explanation:
https://docs.citrix.com/en-us/citrix-adc/current-release/ssl/faq-ssl1.html
NEW QUESTION 45
A Citrix Engineer has deployed Front-end Optimization on NetScaler. The following are the snippets of the content before and after optimization.
Before Optimization:
After Optimization:
Which optimization technique has been applied to the content?
- A. Combine CSS
- B. Inline CSS
- C. Minify CSS
- D. Linked JavaScript to inline JavaScript
Answer: A
NEW QUESTION 46
Scenario: A Citrix Engineer has established protections for web applications using Citrix Web App Firewall. One of the application owners is concerned that some negative traffic is passing through to the application servers. The owner wants confirmation that Citrix Web App Firewall is blocking negative traffic. Which CLI command can the engineer use to display statistics on a per-protection basis for the enabled protections?
- A. stat appfw policyjabel <policy_label_name>
- B. stat appfw profile <profile_name>
- C. stat appfw policy <policy_name>
- D. stat appfw signature <signature_object>
Answer: B
NEW QUESTION 47
Scenario: A Citrix Engineer is reviewing the log files for a protected application. The engineer discovers a lot of errors pertaining to invalid data being supplied by users.
Which protection can the engineer implement at the Citrix Web App Firewall to reduce these errors?
- A. Field Format
- B. Cross-Site Request Forgeries (CSRF)
- C. Form Field Consistency
- D. HTML SQL Injection
Answer: C
NEW QUESTION 48
Which Citrix Web App Firewall engine setting can a Citrix Engineer use to ensure that protections are applied in the event that an advanced policy expression cannot be evaluated as either 'True' or 'False'?
- A. Undefined profile
- B. Session Limit
- C. Default profile
- D. Entity Decoding
Answer: B
NEW QUESTION 49
Scenario: A Citrix Engineer has enabled Security insight and Web insight on NetScaler Management and Analytics System (NMAS). The engineer is NOT able to see data under the Analytics on NMAS, in spite of seeing hits on the APPFLOW policy.
Which log should the engineer check on NMAS to ensure that the information is sent from NetScaler?
- A. mps_afdecoder.log
- B. mps_afanalytics.log
- C. nstriton.log
- D. mps_perf.log
Answer: A
NEW QUESTION 50
Scenario: A Citrix Engineer needs to configure the Application Firewall to do a credit card check using the command-line interface (CLI) and configure the profile to obscure the credit card number. Which parameter will the engineer add in the CLI to encrypt the credit card numbers in the logs?
- A. -creditCardXOut ON
- B. doSecureCreditCardLogging ON
- C. creditCardAction BLOCK
- D. -creditCardMaxAllowed
Answer: B
NEW QUESTION 51
Scenario: A Citrix Engineer wants to protect a web application using Citrix Web App Firewall. After the Web App Firewall policy is bound to the virtual server, the engineer notices that Citrix Web App Firewall is NOT blocking bad requests from clients. Which tool can help the engineer view the traffic that is passing to and from the client?
- A. nstrace
- B. nsconmsg
- C. aaad.debug
- D. syslog
Answer: A
NEW QUESTION 52
Which setting in the Cookie Consistency protection feature does a Citrix Engineer need to configure to ensure that all a cookie is sent using TLS only?
- A. Encrypt Server Cookies > Encrypt Session Only
- B. Encrypt Server Cookies > Encrypt All
- C. Flags to Add in Cookies > Secure
- D. Proxy Server Cookies > Session Only
Answer: C
Explanation:
https://docs.citrix.com/en-us/citrix-adc/current-release/application-firewall/cookie- protection/cookie-consistency-check.html
NEW QUESTION 53
A Citrix Engineer needs to create an Citrix Web App Firewall Profile. Which statement is applicable when using Signatures for creating an Citrix Web App Firewall Profile?
- A. Only external format Signatures can be used.
- B. No Custom Signatures can be used.
- C. The Default Signatures are bound to the profile.
- D. No Signatures are bound to the profile.
Answer: D
NEW QUESTION 54
Which action can be used to place the rule on the relaxation list without being deployed and ensuring that the rule is NOT learned again?
- A. Skip
- B. Deploy
- C. Delete
- D. Edit& Deploy
Answer: A
NEW QUESTION 55
A Citrix Engineer observes that after enabling the security checks in Learning mode only in an Application Firewall profile, the NetScaler is blocking the non-RFC compliant HTTP packets. What can the engineer modify in the configuration to resolve this issue?
- A. Set Default profile in application firewall settings as APPFW_BYPASS.
- B. Disable Drop Invalid Requests in the HTTP Profile settings.
- C. Set Undefined Action in application firewall settings as APPFW_BYPASS.
- D. Enable Drop Invalid Requests in the HTTP Profile settings.
Answer: A
NEW QUESTION 56
......
TestSimulate 1Y0-341 Exam Practice Test Questions : https://www.testsimulate.com/1Y0-341-study-materials.html