Compliance Standards Flashcards
7 cards from real CCA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Compliance Standards flashcards as text
A federal agency requires cryptographic modules validated by NIST. Which standard addresses this requirement?
Answer: FIPS 140-2/140-3
FIPS 140 validation certifies cryptographic modules for U.S. federal use.
Which European regulation imposes data-protection and data-residency considerations on organizations hosting EU citizens' personal data in Citrix Cloud?
Answer: GDPR
GDPR governs processing of personal data of individuals in the EU.
What is the recommended minimum TLS version for Citrix Gateway and StoreFront connections in a compliance-focused deployment?
Answer: TLS 1.2
SSL 3.0, TLS 1.0, and TLS 1.1 are deprecated, so TLS 1.2 or higher is required by most standards.
Which App Protection feature defends against malware capturing keystrokes entered into a published application?
Answer: Anti-keylogging
Anti-keylogging scrambles keystrokes so endpoint keyloggers cannot read them.
An auditor asks who launched a specific desktop session last Tuesday and from which client IP. Which console is the best source?
Answer: Citrix Director
Director shows historical session and connection details, including user and client information.
To meet a requirement that no corporate data be stored on unmanaged home PCs, which policy is most directly relevant?
Answer: Client drive redirection
Disabling client drive redirection stops users saving session files to local drives.
Which multifactor authentication method is commonly required for U.S. federal compliance (for example, PIV/CAC) and is supported by Citrix Workspace app?
Answer: Smart card authentication
Federal PIV/CAC programs rely on smart card certificates, which Citrix supports end to end.