1Y0-231 · Question #126
A Citrix Administrator needs to customize the user experience for those connecting with the Citrix Gateway plug-in. Using session and traffic policies, which three options can the administrator…
The correct answer is A. Split tunneling B. SSO C. The level of user access to applications. Session and traffic policies in Citrix Gateway govern the behavior of an established connection - what happens after the plug-in authenticates and connects. Split tunneling (A) is a classic session policy setting that determines whether all traffic or only corporate-destined…
Question
A Citrix Administrator needs to customize the user experience for those connecting with the Citrix Gateway plug-in. Using session and traffic policies, which three options can the administrator configure for this customization? (Choose three.)
Options
- ASplit tunneling
- BSSO
- CThe level of user access to applications
- DThe domains to which users are allowed access
- EAuthentication methods
How the community answered
(33 responses)- A91% (30)
- D6% (2)
- E3% (1)
Explanation
Session and traffic policies in Citrix Gateway govern the behavior of an established connection - what happens after the plug-in authenticates and connects. Split tunneling (A) is a classic session policy setting that determines whether all traffic or only corporate-destined traffic goes through the VPN tunnel. SSO (B) is configurable via session or traffic policies to pass user credentials automatically to back-end applications. The level of user access to applications (C) is controlled through traffic policies that define what resources a connected user can reach.
Why D is wrong: Domain-based access restrictions fall under authorization policies, not session or traffic policies. Authorization policies are a distinct policy type in Citrix Gateway specifically designed to permit or deny access to network resources.
Why E is wrong: Authentication methods (LDAP, RADIUS, certificate, etc.) are configured at the virtual server level via authentication policies - a separate policy type that runs before a session is ever established, so it's outside the scope of session/traffic policy customization.
Memory tip: Think of session and traffic policies as controlling the tunnel experience (how data flows, what apps you reach, and how credentials travel inside the session). Authentication and domain authorization live outside the tunnel - they're gatekeeping functions handled by their own dedicated policy types.
Topics
Community Discussion
No community discussion yet for this question.