nerdexam
Citrix

1Y0-403 · Question #181

Scenario: A Citrix Architect needs to implement XenDesktop in an environment. The XenDesktop design requires enabling TLS encryption between components to ensure Payment Card Industry (PCI)…

The correct answer is A. Run a Citrix-provided PowerShell script on the VDA machine image to enable TLS B. Enable TLS for Delivery Groups on the Delivery Controller E. Deploy certificates to the Delivery Controller. Explanation/Reference: https://docs.citrix.com/en-us/xenapp-and-xendesktop/7-15-ltsr/secure/tls.html Configuring a XenApp or XenDesktop Site to use the Transport Layer Security (TLS) protocol includes the following procedures: Obtain, install, and register a server certificate…

Advanced Configuration for a Citrix Virtual Apps and Desktops Solution

Question

Scenario: A Citrix Architect needs to implement XenDesktop in an environment. The XenDesktop design requires enabling TLS encryption between components to ensure Payment Card Industry (PCI) compliance. A PCI audit determines that TLS must be used for communication with the Virtual Delivery Agent (VDA) machines. Which three tasks should the architect perform to enable TLS on VDA machines? (Choose three.)

Options

  • ARun a Citrix-provided PowerShell script on the VDA machine image to enable TLS
  • BEnable TLS for Delivery Groups on the Delivery Controller
  • CRun a Citrix-provided PowerShell script on the Delivery Controllers.
  • DEnable TLS for the XenDesktop Site
  • EDeploy certificates to the Delivery Controller
  • FDeploy certificates to the VDA machines

How the community answered

(27 responses)
  • A
    81% (22)
  • C
    4% (1)
  • D
    4% (1)
  • F
    11% (3)

Explanation

Explanation/Reference: https://docs.citrix.com/en-us/xenapp-and-xendesktop/7-15-ltsr/secure/tls.html Configuring a XenApp or XenDesktop Site to use the Transport Layer Security (TLS) protocol includes the following procedures: Obtain, install, and register a server certificate on all Delivery Controllers, and configure a port with the TLS certificate. For details, see Install TLS server certificates on Controllers. Optionally, you can change the ports the Controller uses to listen for HTTP and HTTPS traffic. Enable TLS connections between users and Virtual Delivery Agents (VDAs) by completing the following Configure TLS on the machines where the VDAs are installed. (For convenience, further references to machines where VDAs are installed are simply called "VDAs.") You can use a PowerShell script supplied by Citrix, or configure it manually. For general information, see About TLS settings on VDAs. For details, see Configure TLS on a VDA using the PowerShell script and Manually configure TLS on a VDA. Configure TLS in the Delivery Groups containing the VDAs by running a set of PowerShell cmdlets in Studio. For details, see Configure TLS on Delivery Groups.

Topics

#TLS encryption#VDA certificates#PCI compliance#PowerShell configuration

Community Discussion

No community discussion yet for this question.

Full 1Y0-403 Practice