Scenario: For security reasons, the NSIP needs to be configured to only be accessible on interface 0/1, which is VLAN 300.
The NSIP address is and the subnet mask is
How would the network engineer achieve this configuration?

A.    set ns config -nsvlan 300 -ifnum 0/1
B.    set ns ip -gui ENABLED -vrID 300
C.    add vlan 300 set ns ip -mgmtAccess ENABLED
D.    set ns config -IPAddress -netmask

Answer: A

Why would an engineer want to specify a TCP Profile for a specific service group?

A.    To enable use of features like SSL over TCP for that specific service group.
B.    To adjust the TCP settings for traffic to and from that specific service group.
C.    To use a specific SNIP for traffic to the back-end servers in that service group.
D.    To enable features like use source IP, TCP keep alive and TCP buffering for a specific service group.

Answer: B

A network engineer wants to optimize a published load balanced SSL virtual server for WAN connection with long delay, high bandwidth with minimal packet drops.
What would the network engineer use to do this type of optimization for the SSL virtual server?

A.    SSL policy
B.    TCP profile
C.    Compression policy
D.    Priority queuing policy

Answer: B

Scenario: The NetScaler is connected to two subnets. The NSIP is The external SNIP is The MIP for internal access is Web servers, authentication servers and time servers are on the network which is available through the router.
The external firewall has the address.
Traffic bound for Internet clients should flow through the external firewall.
Which command should be used to set the default route?

A.    add route
B.    add route
C.    add route
D.    add route

Answer: A

Some SSL certificate files may be missing from a NetScaler appliance.
Which directory should an engineer check to determine which files are missing?

A.    /nsconfig/ssl
B.    /nsconfig/ssh
C.    flash/nsconfig/
D.    /var/netscaler/ssl/

Answer: A

Scenario: An engineer has been hired to manage the content-switching configurations on the NetScaler. The user account for this engineer must have the standard rules that apply to the other administrators.
What should the engineer do to allow for the extra privileges?

A.    Modify the current Command Policy and then save the changes.
B.    Unbind the current Command Policy of the user account and then save the changes.
C.    Remove the custom Command Policy and then create one with the new requirements.
D.    Create a custom Command Policy and bind it to the user account with the highest priority.

Answer: D

A network engineer needs to configure smart card-based authentication on NetScaler Access Gateway.
Which type of authentication policy could the engineer configure in order to accomplish this task?

A.    Local
C.    Certificate
D.    Secure LDAP

Answer: C

A network engineer needs to configure load balancing for an FTP site.
Which type of session persistence method can the engineer select for this scenario?

A.    Rule
B.    Source IP
C.    Cookie Insert
D.    Custom Server ID

Answer: B

Scenario: Example.com runs a dating service site that provides a service with videos of candidates. They want to use RTSP load balancing to stream the videos more effectively.
Which load balancing method should the engineer select?

A.    Least packet
B.    Round Robin
C.    Least bandwidth
D.    Least connection

Answer: C

A network engineer needs to configure load balancing for secured web traffic that does NOT terminate at the NetScaler device.
Which type of session persistence method can the engineer select for this scenario?

A.    Source IP
B.    Cookie Insert
C.    URL Passive

Answer: A

A company has two sites that host six cache web servers that are used to promote sales information.
Which feature on the NetScaler should an engineer enable to provide faster application performance and also provide additional capacity if the demand increases for one site?

A.    Load balancing
B.    Integrated Cache
C.    Responder Policy
D.    Content switching

Answer: A

Scenario: A network engineer has configured a load balancing virtual server for an HTTP application. Due to the application architecture, it is imperative that a user’s session remains on a single server during the session. The session has an idle timeout of 60 minutes.
Some devices are getting inconsistent application access while most are working fine.
The problematic devices all have tighter security controls in place.
Which step should the engineer take to resolve this issue?

A.    Set the cookie timeout to 60 minutes.
B.    Configure a backup persistence of SourceIP.
C.    Change the HTTP parameters to Cookie Version 1.
D.    Utilize SSL offload to enable the application to use SSL.

Answer: B

Scenario: The network engineer has created a monitor and bound it to a service group containing four web servers to verify that the web application responds. During routine maintenance one of the web servers is shut down; however, the server state remains UP and user requests are still attempting to communicate with the server.
What could be causing this problem?

A.    The server has been disabled.
B.    The monitor is not bound at the correct bind point.
C.    Health monitoring is disabled for the service group.
D.    The NetScaler configuration has not been saved since before the monitor was bound.

Answer: C

Which NetScaler feature could be used to stall policy processing to retrieve information from an external server?

A.    Responder
B.    HTTP callout
C.    AppExpert template
D.    EdgeSight monitoring

Answer: B

An engineer has bound three monitors to a service group and configured each of the monitors with a weight of 10.
How should the engineer ensure that the members of the service group are marked as DOWN when at least two monitors fail?

A.    Re-configure the weight of each monitor to 0.
B.    Configure the service group with a threshold of 21.
C.    Configure the service group with a threshold of 20.
D.    Re-configure the weight of each monitor to 5, and configure the service group threshold to 15.

Answer: C

