1Y0-231 · Question #53
A Citrix Administrator has deployed a new Citrix ADC MPX appliance in the demilitarized (DMZ) with one interface in the DMZ and the other on the internal network. In which mode should the…
The correct answer is D. Transparent. Transparent mode is correct because the appliance has one interface in the DMZ and one on the internal network, sitting inline as a Layer 2 bridge between the two segments. In this position, the ADC intercepts and processes traffic passing between the DMZ and internal network…
Question
A Citrix Administrator has deployed a new Citrix ADC MPX appliance in the demilitarized (DMZ) with one interface in the DMZ and the other on the internal network. In which mode should the administrator deploy the Citrix ADC?
Options
- AOne-Arm
- BTwo-Arm
- CForward Proxy
- DTransparent
How the community answered
(21 responses)- A5% (1)
- B5% (1)
- C14% (3)
- D76% (16)
Explanation
Transparent mode is correct because the appliance has one interface in the DMZ and one on the internal network, sitting inline as a Layer 2 bridge between the two segments. In this position, the ADC intercepts and processes traffic passing between the DMZ and internal network without appearing as a routed hop - no IP reconfiguration of existing hosts is required, making it the natural fit for inserting security/load-balancing into an existing DMZ architecture.
One-Arm (A) is wrong because it uses a single interface, with traffic arriving and returning through the same path - the ADC sits off to the side as a proxy, not bridging two segments. Two-Arm (B) is incorrect because it implies the ADC operates as a Layer 3 router with its own IP addressing on both networks, which is a more complex topology than bridging; the scenario describes a bridge position, not a routing one. Forward Proxy (C) applies to outbound web traffic scenarios where clients route internet-bound requests through the ADC - that's unrelated to an inline DMZ security appliance.
Memory tip: Think "Transparent = invisible bridge." When the ADC sits physically between two network segments like a pane of glass - letting traffic pass through without the network seeing it as a router - that's Transparent mode. If you ever see "one interface here, one interface there, no IP changes," think Transparent.
Topics
Community Discussion
No community discussion yet for this question.