nerdexam
Citrix

1Y0-301 · Question #55

How can a Citrix Engineer ensure that external users connect only to specific desktops through a NetScaler Gateway?

The correct answer is C. Create an access policy assigned to a Delivery Group. To restrict external users to specific desktops via NetScaler Gateway, an access policy must be assigned directly to a Delivery Group to enforce connection-based access control.

Configuring Policies and Profiles

Question

How can a Citrix Engineer ensure that external users connect only to specific desktops through a NetScaler Gateway?

Options

  • ACreate a session policy assigned to users.
  • BCreate a StoreFront VIP on NetScaler Gateway.
  • CCreate an access policy assigned to a Delivery Group.
  • DCreate a StoreFront filter to show only authorized desktops

How the community answered

(63 responses)
  • A
    6% (4)
  • B
    3% (2)
  • C
    76% (48)
  • D
    14% (9)

Why each option

To restrict external users to specific desktops via NetScaler Gateway, an access policy must be assigned directly to a Delivery Group to enforce connection-based access control.

ACreate a session policy assigned to users.

A session policy assigned to users on NetScaler Gateway governs session parameters such as ICA proxy mode and client experience settings, but does not restrict which specific Delivery Groups or desktops a user is permitted to access.

BCreate a StoreFront VIP on NetScaler Gateway.

A StoreFront VIP on NetScaler Gateway is a network-level load balancing construct for directing traffic to StoreFront servers, and has no role in controlling which desktops are enumerated or accessible to external users.

CCreate an access policy assigned to a Delivery Group.Correct

Creating an access policy assigned to a Delivery Group allows the administrator to define SmartAccess filter conditions - such as requiring the connection to originate from a specific NetScaler Gateway - and bind those conditions to a targeted Delivery Group. This ensures only users connecting through the designated gateway can enumerate and launch the restricted desktops, enforcing access control at the broker level rather than just the UI layer.

DCreate a StoreFront filter to show only authorized desktops

A StoreFront filter can control which resources appear in the store UI but operates only at the presentation layer and cannot enforce broker-level access control to prevent users from reaching unauthorized desktops.

Concept tested: NetScaler Gateway SmartAccess policy scoping Delivery Groups

Source: https://docs.citrix.com/en-us/citrix-virtual-apps-desktops/secure/access-gateway.html

Topics

#Delivery Group access policy#NetScaler Gateway#external user access#desktop restriction

Community Discussion

No community discussion yet for this question.

Full 1Y0-301 Practice