1Y0-351 Exam Details

  • Exam Code
    :1Y0-351
  • Exam Name
    :Citrix NetScaler 10.5 Essentials and Networking
  • Certification
    :Citrix Certifications
  • Vendor
    :Citrix
  • Total Questions
    :289 Q&As
  • Last Updated
    :May 25, 2026

Citrix 1Y0-351 Online Questions & Answers

  • Question 151:

    Which of the listed options is a simple Access Control List (ACL) attribute?

    A. VLAN ID
    B. Source IP address
    C. NetScaler interface
    D. Destination IP address

  • Question 152:

    Scenario: A network engineer has configured a load balancing virtual server for an HTTP application. Due to the application architecture, it is imperative that a user's session remains on a single server during the session. The session has an

    idle timeout of 60 minutes. Some devices are getting inconsistent application access while most are working fine. The problematic devices all have tighter security controls in place.

    Which step should the engineer take to resolve this issue?

    A. Set the cookie timeout to 60 minutes.
    B. Configure a backup persistence of SourceIP.
    C. Change the HTTP parameters to Cookie Version 1.
    D. Utilize SSL offload to enable the application to use SSL.

  • Question 153:

    Which two certificate formats are supported when creating a certificate key pair on the NetScaler? (Choose two.)

    A. PEM
    B. DER
    C. PKCS7
    D. PKCS12

  • Question 154:

    Scenario: An application that uses HTTP for connections and other protocols for different types of content has been deployed. Load balancing virtual servers have been created for each protocol and the engineer now needs to ensure that once a load balancing decision has occurred, further requests for different content are served from the same server.

    How could the engineer achieve this?

    A. Create a persistency group.
    B. Set the Spillover method to DYNAMICCONNECTION.
    C. Add a new virtual server for each protocol that is not directly addressable.
    D. Set each virtual server to use Source IP Hash as the load balancing method.

  • Question 155:

    The network engineer is investigating issues and suspects that one of the administrators recently changed the NetScaler configuration. Which command could the engineer run to check the logs that will contain such details?

    A. nsconmsg -K newnslog -d stats
    B. nsconmsg -K newnslog -d stats -d current
    C. nsconmsg -K /var/nslog/newnslog -d event
    D. nsconmsg -K /var/nslog/newnslog -d consmsg

  • Question 156:

    Which two encryption algorithms are supported on the NetScaler to store the encrypted SSL private key with a password? (Choose two.)

    A. AES
    B. RC4
    C. DES
    D. DES3

  • Question 157:

    Scenario: A security test has shown that the NetScaler is forwarding IP packets. Company standard operating procedure is that the routers should be the only devices forwarding packets. Which step should the network engineer take to prevent forwarding packets?

    A. Enable Layer 2 mode.
    B. Disable Layer 3 mode.
    C. Disable Path MTU Discovery.
    D. Enable MAC based forwarding.

  • Question 158:

    Scenario: A network engineer needs to implement high availability (HA) for a pair of NetScaler appliances. The existing appliance was recently restarted and the new appliance has been rack mounted and turned on for several weeks waiting to be configured. The engineer needs to create an HA pair, but is concerned that his original appliance will get erased when the HA pair is created.

    Which two tasks could the engineer do before the creation of the HA pair to ensure that the exiting unit stays the main appliance? (Choose two.)

    A. Set StayPrimary on the existing node.
    B. Configure StaySecondary on the new node.
    C. Enable HA Sync before adding the second node.
    D. Create a Route Monitor to ensure proper synchronization.
    E. Ensure that INC mode is enabled during creation of HA Pair.

  • Question 159:

    Scenario: An engineer created a new test Web Interface site for the new XenDesktop farm that the IT Department is developing. Several weeks later the engineer finds out that several people across the company have been accessing the new test site. The engineer needs to ensure that only the IT Department subnets can access the test site.

    How could the engineer restrict access to the site so that only certain subnets can access this resource?

    A. Add an Extended ACL to only allow specific subnets to the Web Interface Site.
    B. Modify an existing simple ACL to allow specific subnets to the Web Interface Site.
    C. Enable USNIP Mode on the appliance to allow specific subnets to the Web Interface Site.
    D. Change the Access Method on the Web Interface Site to allow specific subnets to the Web Interface Site.

  • Question 160:

    A network engineer runs the following command:

    nsconmsg -K /var/nslog/newnslog -s nsdebug_pe=1 -d oldconmsg

    What is the engineer trying to check in the log?

    A. Bandwidth information
    B. Load-balancing information
    C. Content-switching statistics
    D. Memory utilization information

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Citrix exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 1Y0-351 exam preparations and Citrix certification application, do not hesitate to visit our Vcedump.com to find your solutions here.