1Y0-301 · Question #55
How can a Citrix Engineer ensure that external users connect only to specific desktops through a NetScaler Gateway?
The correct answer is C. Create an access policy assigned to a Delivery Group. To restrict external users to specific desktops via NetScaler Gateway, an access policy must be assigned directly to a Delivery Group to enforce connection-based access control.
Question
How can a Citrix Engineer ensure that external users connect only to specific desktops through a NetScaler Gateway?
Options
- ACreate a session policy assigned to users.
- BCreate a StoreFront VIP on NetScaler Gateway.
- CCreate an access policy assigned to a Delivery Group.
- DCreate a StoreFront filter to show only authorized desktops
How the community answered
(63 responses)- A6% (4)
- B3% (2)
- C76% (48)
- D14% (9)
Why each option
To restrict external users to specific desktops via NetScaler Gateway, an access policy must be assigned directly to a Delivery Group to enforce connection-based access control.
A session policy assigned to users on NetScaler Gateway governs session parameters such as ICA proxy mode and client experience settings, but does not restrict which specific Delivery Groups or desktops a user is permitted to access.
A StoreFront VIP on NetScaler Gateway is a network-level load balancing construct for directing traffic to StoreFront servers, and has no role in controlling which desktops are enumerated or accessible to external users.
Creating an access policy assigned to a Delivery Group allows the administrator to define SmartAccess filter conditions - such as requiring the connection to originate from a specific NetScaler Gateway - and bind those conditions to a targeted Delivery Group. This ensures only users connecting through the designated gateway can enumerate and launch the restricted desktops, enforcing access control at the broker level rather than just the UI layer.
A StoreFront filter can control which resources appear in the store UI but operates only at the presentation layer and cannot enforce broker-level access control to prevent users from reaching unauthorized desktops.
Concept tested: NetScaler Gateway SmartAccess policy scoping Delivery Groups
Source: https://docs.citrix.com/en-us/citrix-virtual-apps-desktops/secure/access-gateway.html
Topics
Community Discussion
No community discussion yet for this question.