1Y0-401 · Question #413
How should the components be set up for this environment?
The correct answer is A. Configure NetScaler high-availability pairs at each site. Place the StoreFront servers and Delivery. The components should be set up by configuring NetScaler high-availability pairs at each site to provide redundant secure remote access. Additionally, StoreFront servers and Delivery Controllers should be placed within the secure internal network to maintain robust security and e
Question
Options
- AConfigure NetScaler high-availability pairs at each site. Place the StoreFront servers and Delivery
- BConfigure one NetScaler cluster at each site. Place the StoreFront servers and Delivery Controllers in
- CConfigure NetScaler high-availability pairs at each site. Place the StoreFront servers in the DMZ and the
- DConfigure one NetScaler cluster at each site. Place the StoreFront servers in the DMZ and the Delivery
How the community answered
(33 responses)- A76% (25)
- B9% (3)
- C12% (4)
- D3% (1)
Why each option
The components should be set up by configuring NetScaler high-availability pairs at each site to provide redundant secure remote access. Additionally, StoreFront servers and Delivery Controllers should be placed within the secure internal network to maintain robust security and efficient communication.
Configuring NetScaler high-availability pairs at each site provides redundancy and fault tolerance for secure remote access without requiring a complex cluster setup. Placing StoreFront servers and Delivery Controllers within the secure internal network aligns with best practices, as StoreFront does not require direct public exposure and Delivery Controllers are core infrastructure that should be protected behind the corporate firewall.
Configuring a NetScaler cluster at each site is typically for scaling throughput rather than providing simple high-availability pairs for the ICA proxy function, and can add unnecessary complexity for a multi-site setup.
Placing StoreFront servers in the DMZ is generally not a recommended security practice; StoreFront should reside in the internal network, protected by the corporate firewall, with only the Citrix Gateway in the DMZ.
This option combines the less suitable NetScaler cluster configuration with the problematic placement of StoreFront servers in the DMZ, which contradicts standard architectural guidelines for security and efficiency.
Concept tested: Citrix Component Network Placement and HA
Source: https://docs.citrix.com/en-us/tech-zone/design/design-guidance/storefront.html
Topics
Community Discussion
No community discussion yet for this question.