Citrix ADC & Gateway Configuration Flashcards
7 cards from real CCA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Citrix ADC & Gateway Configuration flashcards as text
What is the primary purpose of the Content Switching feature in Citrix ADC?
Answer: Routing client requests to different backend server pools based on URL, host header, or other content attributes
Content Switching directs incoming requests to different load-balancing virtual servers (and their associated server pools) based on traffic attributes such as URL path, host header, or HTTP method.
Which authentication protocol is most commonly integrated with Citrix Gateway to enable RADIUS-based multi-factor authentication?
Answer: RADIUS
RADIUS is the standard protocol used to integrate Citrix Gateway with MFA solutions such as RSA SecurID, Duo, and Google Authenticator, allowing a second authentication factor to be required.
What does GSLB stand for in the context of Citrix ADC, and what is its primary use case?
Answer: Global Server Load Balancing — distributing traffic across geographically dispersed data centers
GSLB (Global Server Load Balancing) uses DNS-based load balancing to direct client requests to the most appropriate data center based on factors such as proximity, load, or health.
In Citrix ADC, what distinguishes a Service Group from individual Services?
Answer: Service Groups allow members to be added or removed dynamically without modifying the virtual server binding
Service Groups simplify management by allowing administrators to add, remove, or autoscale backend servers within the group without needing to rebind each Service individually to the virtual server.
What is the function of a Session Policy and its associated Session Profile in Citrix Gateway?
Answer: To define per-user or per-group session parameters such as idle timeout, split tunneling, and client choices
Session Policies evaluate conditions (e.g., user group membership or client endpoint) and apply Session Profiles that define settings like idle timeout, split tunneling mode, and whether Citrix Workspace app or clientless access is used.
Which Citrix ADC capability can rate-limit client connections or requests per second to help mitigate application-layer (Layer 7) DDoS attacks?
Answer: Rate Limiting (AppQoE or Surge Protection)
Citrix ADC Rate Limiting and Surge Protection features allow administrators to cap the number of requests or connections from clients, throttling traffic spikes that could indicate a DDoS attack.
Which Citrix ADC IP address type is used by the ADC to initiate connections to backend servers on subnets other than the management subnet?
Answer: Subnet IP (SNIP)
The Subnet IP (SNIP) is the source IP the ADC uses when opening connections to backend servers, allowing communication across different network subnets.