1Y0-231 · Question #49
A Citrix Administrator deploys a new Citrix ADC MPX appliance in the demilitarized zone (DMZ), with one interface in the DMZ and the other on the internal network. In which mode should the…
The correct answer is C. Forward proxy. Deploying the Citrix ADC in forward proxy mode is correct because the appliance is positioned in the DMZ to intercept and forward outbound client requests on behalf of internal users - this is precisely what a forward proxy does: it acts as an intermediary between internal…
Question
A Citrix Administrator deploys a new Citrix ADC MPX appliance in the demilitarized zone (DMZ), with one interface in the DMZ and the other on the internal network. In which mode should the administrator deploy the Citrix ADC?
Options
- ATwo-arm
- BOne-arm
- CForward proxy
- DTransparent
How the community answered
(48 responses)- A15% (7)
- B6% (3)
- C71% (34)
- D8% (4)
Explanation
Deploying the Citrix ADC in forward proxy mode is correct because the appliance is positioned in the DMZ to intercept and forward outbound client requests on behalf of internal users - this is precisely what a forward proxy does: it acts as an intermediary between internal clients and external destinations, with the ADC's DMZ-facing interface handling external communication and its internal interface serving LAN clients. Two-arm (A) describes a physical topology (two interfaces on separate networks), not a logical deployment mode - the question asks how the ADC should function, not how it's cabled. One-arm (B) refers to a topology where a single interface handles both client and server traffic, which contradicts the described two-interface setup. Transparent (D) is incorrect because transparent mode silently intercepts traffic without clients knowing the proxy exists, which is a different use case (typically for inline traffic inspection), not the standard DMZ gateway deployment described here.
Memory tip: Think "Forward = For the client going Forward to the internet" - a forward proxy serves internal users heading outward, which matches an ADC sitting between the internal LAN and the DMZ acting on their behalf.
Topics
Community Discussion
No community discussion yet for this question.