1Y0-231 Sample Questions & Answers
Authentication and authorization configuration carries the top weight, alongside load balancing, StoreFront integration, VPN session management, basic networking and VLANs, SSL certificate handling, system security, high availability, and Gateway customization.
Launch the full 1Y0-231 simulator →Showing 10 of 20 free samples.
- Question 1
Scenario: After deploying a Citrix ADC in production, a Citrix Administrator notices that client requests are NOT being evenly distributed among backend resources. The administrator wants to change from the default load-balancing method to one that will help distribute the load more evenly.
Which load-balancing method would ensure that the server with the least amount of network utilization is receiving new connections?
Show answer & explanation
Correct answer: B
Least bandwidth is the optimal load-balancing method for ensuring more even distribution of client requests based on current server utilization and available capacity. This method directs new connections to the server currently handling the least amount of bandwidth, helping to balance the load more evenly across backend resources. Least response time may still create uneven distribution if servers have different processing capabilities, least connection only considers connection count not actual workload, and least packets does not account for varying packet sizes or processing requirements.
- Question 2
Which authentication type can a Citrix Administrator use to enable Citrix ADC authentication, authorization, and auditing (AAA) dual-factor authentication from a user’s mobile device app?
Show answer & explanation
Correct answer: A
LDAP authentication serves as the primary authentication factor in Citrix ADC AAA dual-factor authentication scenarios, typically combined with mobile device-based second factors like RADIUS OTP or native authenticator apps. LDAP validates user credentials against Active Directory or other directory services as the first factor, then the system can prompt for mobile device-based authentication as the second factor. LOCAL authentication stores credentials locally on the ADC rather than integrating with mobile devices, TACACS+ is primarily for network device management, and SAML is for federated single sign-on rather than dual-factor mobile authentication.
- Question 3Select 2
A Citrix Administrator needs to integrate an existing certification-based authentication policy into an existing Citrix Gateway virtual server.
Which three steps can the administrator take to accomplish this? (Choose three.)
Show answer & explanation
Correct answers: D, E
Server clustering is the appropriate high availability method for ensuring continuous service when backend servers fail in a load-balanced environment. Server clustering provides automatic failover between servers and maintains service continuity when individual servers become unavailable. High availability pairs are used for Citrix ADC appliances themselves rather than backend servers, load balancing distributes traffic but does not provide failover capabilities by itself, and SSL bridging is a traffic handling method rather than a high availability solution.
HTTP redirect policy with URL rewriting is the correct method for redirecting client requests from HTTP to HTTPS while maintaining proper URL structure and query parameters. This ensures secure communication by automatically redirecting insecure HTTP requests to their secure HTTPS equivalents. Content switching policies route traffic based on content rather than performing redirects, SSL bridging handles SSL termination and re-encryption but does not perform HTTP-to-HTTPS redirection, and authentication policies handle user authentication rather than protocol redirection.
- Question 4
Scenario: A Citrix Administrator configures an access control list (ACL) to block traffic from the IP address 10.102.29.5:
add simpleacl rulel DENY -srclP 10.102.29.5
A week later, the administrator discovers that the ACL is no longer present on the Citrix ADC.
What could be the reason for this?
Show answer & explanation
Correct answer: A
The administrator did not run the apply ACL command, which is required to save simple ACL configurations to the Citrix ADC persistent configuration. Simple ACLs are temporary by default and only exist in running memory until explicitly applied using the 'apply simpleacl' command to make them persistent across reboots. Simple ACLs do not have automatic timeout periods of 60 or 600 seconds, and configuration loss due to restart would affect all configurations, not just ACLs.
- Question 5
Which Citrix Gateway feature should a Citrix Administrator configure to allow traffic for specific iOS applications only?
Show answer & explanation
Correct answer: B
Per app VPN tunnel is the specific Citrix Gateway feature designed to allow traffic routing for designated iOS applications only, providing granular application-level VPN access control. This feature integrates with iOS MDM policies to selectively tunnel specific applications through the Citrix Gateway while allowing other traffic to flow directly. Full SSL VPN tunnel routes all traffic, Split DNS only affects name resolution, and SmartControl for iOS provides broader access control but not application-specific tunneling functionality.
- Question 6
A Citrix Administrator needs to configure a Citrix ADC high availability (HA) pair with each Citrix ADC in a different subnet.
What does the administrator need to do for HA to work in different subnets?
Show answer & explanation
Correct answer: B
Independent Network Configuration (INC) mode must be enabled for Citrix ADC high availability pairs deployed across different subnets. INC mode allows each ADC node to maintain its own network configuration including IP addresses, VLAN assignments, and routing tables, while still participating in HA operations. SyncVLAN is used for HA communication but does not solve different subnet issues, HA monitoring on interfaces is standard configuration, and fail-safe mode prevents split-brain scenarios but does not address network configuration differences.
- Question 7
Which Citrix ADC platform offers an out-of-the-box, hardware-independent, multi-tenant solution?
Show answer & explanation
Correct answer: A
A responder policy with HTTP redirect action is the correct method for redirecting HTTP requests to HTTPS automatically to ensure secure communication. The responder policy evaluates incoming requests and can issue HTTP 301 or 302 redirects to force clients to use HTTPS. Rewrite policies modify request content rather than issuing redirects, SSL offloading handles certificate processing but does not redirect HTTP traffic, and content switching routes traffic based on content rather than performing protocol redirection.
- Question 8Select 2
The Citrix ADC SDX architecture allows instances to share ___________ and ___________. (Choose the two correct options to complete the sentence.)
Show answer & explanation
Correct answers: B, D
CPU and physical interfaces are the two primary resources shared in Citrix ADC SDX architecture among multiple VPX instances. The SDX management server allocates CPU cores and threads dynamically across VPX instances based on configured policies and resource requirements, while physical interfaces utilize SR-IOV technology for shared network connectivity. The kernel and memory are isolated per instance for security and performance reasons, not shared resources.
Physical interfaces and CPU are the two primary resources shared in Citrix ADC SDX architecture among multiple VPX instances. Physical network interfaces utilize SR-IOV technology to provide dedicated virtual functions to each VPX instance while sharing the underlying hardware, and CPU resources are dynamically allocated across instances. The kernel and memory are isolated per VPX instance to ensure security boundaries and prevent cross-tenant interference.
- Question 9
A Citrix Administrator wants to configure independent and isolated access on a single appliance to allow three different departments to manage and isolate their own applications.
What can the administrator configure to isolate department-level administration?
Show answer & explanation
Correct answer: B
Admin partitions that use dedicated VLANs provide the optimal solution for isolating department-level administration on a single Citrix ADC appliance. Admin partitions create complete administrative and configuration isolation, allowing each department to manage their own virtual servers, policies, SSL certificates, and networking configurations independently. When combined with dedicated VLANs, this ensures both administrative separation and network-level traffic isolation. Each partition operates as a separate administrative domain with its own login credentials, configuration namespace, and resource allocation. Simple routing or VIP configurations cannot provide the comprehensive administrative isolation required for multi-department management. Reference: https://docs.citrix.com/en-us/citrix-adc/current-release/admin-partition.html
- Question 10
If a user device does NOT comply with a company’s security requirements, which type of policy can a Citrix Administrator apply to a Citrix Gateway virtual server to limit access to Citrix Virtual Apps and Desktops resources?
Show answer & explanation
Correct answer: A
Session policies are the correct policy type for limiting access to Citrix Virtual Apps and Desktops resources when user devices do not comply with security requirements. Session policies in Citrix Gateway can evaluate device compliance status through endpoint analysis, device certificates, registry checks, and antivirus validation to make dynamic access control decisions. These policies can restrict session establishment, limit published application visibility, control clipboard and file transfer permissions, or completely deny access based on device compliance posture. Responder policies handle HTTP responses, Authorization policies control user permissions but not device compliance, and Traffic policies manage network traffic flow rather than application access control based on device security status. Reference: https://www.citrix.com/content/dam/citrix/en_us/documents/products-solutions/creating-and-enforcing-advanced-access-policies-with-xenapp.pdf
Ready for the real thing?
The full 1Y0-231 simulator has every exam-style question, timed mode, and instant scoring.