โ† All CCA Flashcard Decks

Security Fundamentals Flashcards

7 cards from real CCA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Security Fundamentals flashcards as text
  1. When external users launch HDX sessions through Citrix Gateway, which port do clients normally use to connect to the Gateway virtual server?

    Answer: TCP 443

    Citrix Gateway wraps ICA traffic in TLS and accepts it on the standard HTTPS port, TCP 443.

  2. An administrator needs to enable TLS encryption directly between Citrix Workspace app and a VDA without using Citrix Gateway. Which tool does Citrix provide to configure the VDA listener for this?

    Answer: The Enable-VdaSSL.ps1 PowerShell script

    Citrix provides the Enable-VdaSSL.ps1 script to bind a certificate and turn on the TLS listener on the VDA.

  3. Why does Citrix strongly recommend HTTPS instead of HTTP for StoreFront stores?

    Answer: With HTTP, user credentials and session data can cross the network unencrypted

    Without TLS, the credentials and resource data exchanged with StoreFront can be intercepted on the network.

  4. By default, StoreFront talks to the Delivery Controller XML Service over HTTP port 80. What is the recommended way to secure this traffic?

    Answer: Set up HTTPS (TLS) on the XML Service and set the StoreFront delivery controller transport type to HTTPS

    Binding a certificate to the XML Service and setting StoreFront's transport type to HTTPS encrypts the credentials sent between them.

  5. Which certificate requirement must be met for the server certificate bound to a Citrix Gateway virtual server?

    Answer: Its common name or SAN must match the FQDN users connect to, and the ADC must have its private key

    Clients check that the certificate name matches the Gateway FQDN, and the ADC needs the private key to complete the TLS handshake.

  6. Some users get certificate trust errors when they connect to Citrix Gateway, even though the server certificate comes from a public CA. What is the most likely missing step on the ADC?

    Answer: Linking the intermediate CA certificate to the server certificate

    If the intermediate certificate is not linked, the ADC sends an incomplete chain and some clients cannot build trust to the root CA.

  7. Which is the security best practice for the TLS protocol settings on a Citrix Gateway virtual server?

    Answer: Enable only TLS 1.2 and TLS 1.3 and disable SSLv3, TLS 1.0, and TLS 1.1

    Older protocols such as SSLv3 and TLS 1.0/1.1 have known weaknesses, so hardened profiles allow only TLS 1.2 and 1.3.