1Y0-301 · Question #48
Scenario: A Citrix Engineer needs to provide virtual desktop access to branch office users by deploying NetScaler to an existing Citrix StoreFront environment. Active Directory, along with RSA…
The correct answer is B. LDAP C. RADIUS. Authenticating users with Active Directory credentials plus RSA tokens on NetScaler requires both an LDAP server (for AD) and a RADIUS server (for RSA token validation).
Question
Scenario: A Citrix Engineer needs to provide virtual desktop access to branch office users by deploying NetScaler to an existing Citrix StoreFront environment. Active Directory, along with RSA tokens, will be used for authentication on the NetScaler. Which two authentication servers should the engineer configure on the NetScaler? (Choose two.)
Options
- ALocal
- BLDAP
- CRADIUS
- DTACACS
How the community answered
(47 responses)- A15% (7)
- B74% (35)
- D11% (5)
Why each option
Authenticating users with Active Directory credentials plus RSA tokens on NetScaler requires both an LDAP server (for AD) and a RADIUS server (for RSA token validation).
Local authentication uses accounts stored directly on the NetScaler appliance and has no integration with Active Directory or RSA token infrastructure.
LDAP is required to authenticate users against Active Directory, validating their domain username and password as the first authentication factor.
RADIUS is required to validate RSA token passcodes because RSA Authentication Manager exposes token validation through the RADIUS protocol, making it the correct second-factor authentication server type on NetScaler.
TACACS is a Cisco-centric protocol primarily used for device administration and network access control, not for RSA token or Active Directory user authentication in a Citrix environment.
Concept tested: NetScaler two-factor authentication with LDAP and RADIUS
Source: https://docs.netscaler.com/en-us/citrix-adc/current-release/aaa-tm/authentication-methods/multi-factor-nfactor-authentication.html
Topics
Community Discussion
No community discussion yet for this question.