Exam 1Y0-402 All QuestionsBrowse all questions from this exam
Question 116

Scenario: A Citrix Architect needs to implement XenDesktop in an environment. The XenDesktop design requires enabling TLS encryption between components to ensure Payment Card Industry (PCI) compliance. A PCI audit determines that TLS must be used for communication with the Virtual Delivery Agent (VDA) machines.

Which three tasks should the architect perform to enable TLS on VDA machines? (Choose three.)

    Correct Answer: A, B, F

    To enable TLS on VDA machines, the Citrix Architect needs to perform three specific tasks. First, running a Citrix-provided PowerShell script on the VDA machine image to enable TLS ensures that the necessary configurations are applied directly to the VDAs. Second, enabling TLS for Delivery Groups on the Delivery Controller affects the communication protocols used between the Delivery Controller and the VDAs, ensuring they align with TLS requirements. Finally, deploying certificates to the VDA machines is critical for establishing the secure communication channels mandated by PCI compliance and TLS. Therefore, the appropriate tasks are running the PowerShell script on the VDA, enabling TLS for Delivery Groups, and deploying certificates to the VDA machines.

Discussion
rraviskaOptions: ABE

A, B, E https://docs.citrix.com/en-us/xenapp-and-xendesktop/7-15-ltsr/secure/tls.html

rraviskaOptions: ABF

Apologies. It is A, B, F enable TLS on DDC, enable TLS on VDA. Deploy certificates to VDA

pkcitrixguru

Its A,C,F https://www.carlstalhood.com/virtual-delivery-agent-vda-cr/

kepler

only enable TLS on VDA, but not deploy cert. cert only deployed on DDC.

bicycleOptions: ACE

A,C,E https://docs.citrix.com/en-us/xenapp-and-xendesktop/7-15-ltsr/secure/tls.html

d0bermannnOptions: ABE

do it this way E->A->B https://support.citrix.com/article/CTX220062

maurizio_n91Options: ABF

A B F E is wrong (you have to do when securing XML with SF)