Security Fundamentals Flashcards
7 cards from real CCA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Security Fundamentals flashcards as text
What is the primary role of the Secure Ticket Authority (STA) in a Citrix Gateway deployment?
Answer: It issues and validates session tickets for ICA connections proxied through Citrix Gateway
The STA issues a ticket when a session is launched, and Citrix Gateway validates that ticket before proxying the ICA connection to the VDA.
An administrator wants users to authenticate with SAML through Citrix Gateway and then sign in to Windows VDAs without typing a password again. Which component makes this possible?
Answer: Federated Authentication Service (FAS)
FAS issues virtual smart card certificates for users so they can sign in to the VDA after non-password authentication methods such as SAML.
Which Citrix ADC framework lets administrators build flexible multi-step authentication flows, such as asking for a username first and then choosing the factor based on group membership?
Answer: nFactor authentication
nFactor chains login schemas and policy labels so each authentication step can depend on the result of the step before it.
Which feature lets Citrix Virtual Apps and Desktops policies and Delivery Groups use the results of Citrix Gateway endpoint analysis to control access?
Answer: SmartAccess
SmartAccess passes Gateway policy and endpoint analysis results to the Delivery Controller so access and policies can depend on the client's state.
A company wants Citrix Gateway users to enter a one-time password from a hardware token as a second factor. Which authentication protocol does Gateway most commonly use to check that OTP against a third-party server?
Answer: RADIUS
Citrix Gateway usually sends OTP token codes to a RADIUS server, which validates them for two-factor authentication.
What is the purpose of the callback URL configured on a Citrix Gateway entry in StoreFront?
Answer: It lets StoreFront contact Citrix Gateway to confirm the request came from Gateway and to get SmartAccess information
StoreFront uses the callback URL to reach Gateway, confirm the authentication request, and get session information such as SmartAccess filters.
Which port does the Common Gateway Protocol (CGP) use when Session Reliability is enabled for direct internal connections to a VDA?
Answer: 2598
Session Reliability wraps ICA in CGP on TCP port 2598, while plain ICA without CGP uses 1494.