1Y0-440 Exam Question 11
What are three potential risks when examining the disaster recovery plan and implementation for a company?
(Choose three)
(Choose three)
1Y0-440 Exam Question 12
Scenario: A Citrix Architect and a team of Workspacelab members have met for a design discussion about the NetScaler Design Project. They captured the following requirements:
* Two pairs of NetScaler MPX appliances will be deployed in the DMZ network and the internal network.
* High availability will be accessible between the pair of NetScaler MPX appliances in the DMZ network.
* Multi-factor authentication must be configured for the NetScaler Gateway virtual server.
* The NetScaler Gateway virtual server is integrated with XenApp/XenDesktop environment.
* Load balancing must be deployed for the users from the workspacelab.com and vendorlab.com domains.
* The logon page must show the workspacelab logo.
* Certificate verification must be performed to identify and extract the username.
* The client certificate must have UserPrincipalName as a subject.
* All the managed workstations for the workspace users must have a client identifications certificate installed on it.
* The workspacelab users connecting from a managed workstation with a client certificate on it should be authenticated using LDAP.
* The workspacelab users connecting from a workstation without a client certificate should be authenticated using LDAP and RADIUS.
* The vendorlab users should be authenticated using Active Directory Federation Service.
* The user credentials must NOT be shared between workspacelab and vendorlab.
* Single Sign-on must be performed between StoreFront and NetScaler Gateway.
* A domain drop down list must be provided if the user connects to the NetScaler Gateway virtual server externally.
* The domain of the user connecting externally must be identified using the domain selected from the domain drop down list.
On performing the deployment, the architect observes that users are always prompted with two-factor authentication when trying to assess externally from an unmanaged workstation.
Click the exhibit button to view the configuration.

What should the architect do to correct this configuration?
* Two pairs of NetScaler MPX appliances will be deployed in the DMZ network and the internal network.
* High availability will be accessible between the pair of NetScaler MPX appliances in the DMZ network.
* Multi-factor authentication must be configured for the NetScaler Gateway virtual server.
* The NetScaler Gateway virtual server is integrated with XenApp/XenDesktop environment.
* Load balancing must be deployed for the users from the workspacelab.com and vendorlab.com domains.
* The logon page must show the workspacelab logo.
* Certificate verification must be performed to identify and extract the username.
* The client certificate must have UserPrincipalName as a subject.
* All the managed workstations for the workspace users must have a client identifications certificate installed on it.
* The workspacelab users connecting from a managed workstation with a client certificate on it should be authenticated using LDAP.
* The workspacelab users connecting from a workstation without a client certificate should be authenticated using LDAP and RADIUS.
* The vendorlab users should be authenticated using Active Directory Federation Service.
* The user credentials must NOT be shared between workspacelab and vendorlab.
* Single Sign-on must be performed between StoreFront and NetScaler Gateway.
* A domain drop down list must be provided if the user connects to the NetScaler Gateway virtual server externally.
* The domain of the user connecting externally must be identified using the domain selected from the domain drop down list.
On performing the deployment, the architect observes that users are always prompted with two-factor authentication when trying to assess externally from an unmanaged workstation.
Click the exhibit button to view the configuration.

What should the architect do to correct this configuration?
1Y0-440 Exam Question 13
Scenario: A Citrix Architect needs to assess an existing on-premises NetScaler deployment which includes Advanced Endpoint Analysis scans. During a previous security audit, the team discovered that certain endpoint devices were able to perform unauthorized actions despite NOT meeting pre-established criteria.
The issue was isolated to several endpoint analysis (EPA) scan settings.
Click the Exhibit button to view the endpoint security requirements and configured EPA policy settings.

Which setting is preventing the security requirements of the organization from being met?
The issue was isolated to several endpoint analysis (EPA) scan settings.
Click the Exhibit button to view the endpoint security requirements and configured EPA policy settings.

Which setting is preventing the security requirements of the organization from being met?
1Y0-440 Exam Question 14
Scenario: A Citrix Architect needs to conduct a capabilities assessment for an organization that wants to create a new Citrix ADC deployment. One of the organization's core business drivers is to ensure that key applications are always available to users.
Which capabilities must the architect verify to assess if the requirement is feasible with the current infrastructure?
Which capabilities must the architect verify to assess if the requirement is feasible with the current infrastructure?
1Y0-440 Exam Question 15
Scenario: A Citrix Architect needs to configure a full VPN session profile to meet the following requirements:
* Users should be able to send the traffic only for the allowed networks through the VPN tunnel.
* Only the DNS requests ending with the configured DNS suffix workspacelab.com must be sent to NetScaler Gateway.
* If the DNS query does NOT contain a domain name, then DNS requests must be sent to NetScaler gateway.
Which settings will meet these requirements?
* Users should be able to send the traffic only for the allowed networks through the VPN tunnel.
* Only the DNS requests ending with the configured DNS suffix workspacelab.com must be sent to NetScaler Gateway.
* If the DNS query does NOT contain a domain name, then DNS requests must be sent to NetScaler gateway.
Which settings will meet these requirements?