Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Citrix 1Y0-241 Exam - Topic 11 Question 112 Discussion

Scenario: A Citrix Administrator suspects an attack on a load-balancing vServer (IP address 192.168.100.25).The administrator needs to restrict access to this vServer for 10 minutes.Which Access Control List (ACL) will accomplish this?
D) add ns acl rule1 DENY --destIP 192.168.100.25 --TTL 600
A) add simpleacl rule1 DENY --srcIP 192.168.100.25 --TTL 600000
B) add simpleacl rule1 DENY --srcIP 192.168.100.25 --TTL 600
C) add ns acl rule1 DENY --destIP 192.168.100.25 --TTL 600000

Citrix 1Y0-241 Exam - Topic 11 Question 112 Discussion

Actual exam question for Citrix's 1Y0-241 exam
Question #: 112
Topic #: 11
[All 1Y0-241 Questions]

Scenario: A Citrix Administrator suspects an attack on a load-balancing vServer (IP address 192.168.100.25).

The administrator needs to restrict access to this vServer for 10 minutes.

Which Access Control List (ACL) will accomplish this?

Show Suggested Answer Hide Answer
Suggested Answer: D

https://docs.citrix.com/en-us/citrix-adc/current-release/networking/access-control-lists-acls/extended-acls-and-extended-acl6s.html

By binding a multiple SAN certificate, we only need to adapt the DNS entries of the websites to point to the same IP (1 IP with 3 DNS) and we will be able to forward the requests to any backend server since all of them are serving the same content.


Contribute your Thoughts:

0/2000 characters
Vilma
3 days ago
This question is tricky.
upvoted 0 times
...
Kerrie
8 days ago
I’m not convinced, why not just block it longer?
upvoted 0 times
...
Jess
13 days ago
Totally agree with B, it's straightforward!
upvoted 0 times
...
Mariann
18 days ago
Wait, are we sure about the TTL values?
upvoted 0 times
...
Pamella
23 days ago
I think D is better since it uses destIP.
upvoted 0 times
...
Deeanna
28 days ago
Option B is the right choice, 600 seconds is 10 minutes.
upvoted 0 times
...
Dean
1 month ago
I feel like option B could be correct since it uses seconds, but I can't recall if the TTL should be longer or shorter.
upvoted 0 times
...
Lavina
3 months ago
I might be mixing up the syntax, but I think the "add ns acl" command is the right format for this kind of restriction.
upvoted 0 times
...
Louann
3 months ago
I remember practicing with ACLs, and I feel like the destination IP is what we need to focus on for this scenario.
upvoted 0 times
...
Magnolia
3 months ago
I think the TTL value is important here, but I'm not sure if it should be in milliseconds or seconds.
upvoted 0 times
...

Save Cancel