1Y0-201 · Question #52
Scenario: A Citrix Administrator needs to audit logins from the NetScaler Gateway. Company policy states that the logs need to be sent to a centralized server. What should the administrator…
The correct answer is A. SYSLOG. SYSLOG is the standard protocol for forwarding audit and event logs from NetScaler Gateway to a centralized logging server.
Question
Scenario: A Citrix Administrator needs to audit logins from the NetScaler Gateway. Company policy states that the logs need to be sent to a centralized server. What should the administrator configure to audit ICA sessions on the NetScaler Gateway?
Options
- ASYSLOG
- BHDX Monitoring
- CApplication Firewall
- DConfiguration Logging
- ENetScaler Web Logging
How the community answered
(26 responses)- A88% (23)
- B4% (1)
- C4% (1)
- E4% (1)
Why each option
SYSLOG is the standard protocol for forwarding audit and event logs from NetScaler Gateway to a centralized logging server.
NetScaler Gateway supports SYSLOG (and NSLOG) audit logging, which forwards log messages including ICA session login events to a remote SYSLOG server over UDP or TCP. Configuring a SYSLOG action and audit policy on the NetScaler satisfies the company requirement to centralize logs on a dedicated server, making it the correct auditing mechanism for gateway sessions.
HDX Monitoring tracks performance metrics of HDX/ICA sessions such as latency and bandwidth; it does not export login audit records to a centralized server.
Application Firewall inspects and protects HTTP/HTTPS web application traffic; it is not used to audit ICA session logins.
Configuration Logging records administrative changes to the NetScaler configuration, not user login or ICA session events.
NetScaler Web Logging (NSWL) captures HTTP/HTTPS web server-style access logs; it does not cover ICA gateway session login events.
Concept tested: NetScaler Gateway SYSLOG audit logging configuration
Source: https://docs.netscaler.com/en-us/citrix-adc/current-release/system/audit-logging.html
Topics
Community Discussion
No community discussion yet for this question.