Courseiva

1Y0-312 Advanced Security and Access Control Practice Question

Exhibit

log_entry: [ERROR] SSL Handshake failure from 192.168.10.5. Cipher Suite TLS_RSA_WITH_AES_128_CBC_SHA is not supported by the client.

Refer to the exhibit. An administrator is seeing this error in the NetScaler logs. What is the most appropriate action to resolve this connectivity issue?

⚠ Common exam trap

Candidates often look towards renewing expired machine certificates or modifying firewall rules, missing the core cryptographic mismatch caused by outdated cipher configurations on the NetScaler SSL profile.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Update the SSL profile on the NetScaler to include modern ciphers.

The error indicates a cipher suite mismatch between the client and the NetScaler virtual server. Older or insecure ciphers are often disabled by default on modern browsers for security reasons. The administrator should update the SSL profile on the NetScaler to include more modern, secure cipher suites that are compatible with current browser standards, ensuring robust encryption without breaking connectivity for modern clients.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Reinstall the SSL certificate on the client machine.

    Why it's wrong here

    The issue is a cipher suite negotiation error, not a certificate validation error. Reinstalling the certificate will not resolve the incompatibility between the client's supported encryption algorithms and the ciphers configured on the server-side SSL virtual server profile.

  • ✓

    Update the SSL profile on the NetScaler to include modern ciphers.

    Why this is correct

    Modern clients and browsers have deprecated older ciphers like TLS_RSA_WITH_AES_128_CBC_SHA. Updating the SSL profile to include newer, more secure cipher suites that support Forward Secrecy ensures the client can complete the handshake while maintaining high security standards for the connection.

  • ✗

    Disable SSL/TLS on the NetScaler virtual server.

    Why it's wrong here

    Disabling SSL/TLS would expose all internal traffic to the public internet, creating a critical security vulnerability. This action would violate basic compliance and security requirements and should never be used as a troubleshooting step for a cipher negotiation issue.

  • ✗

    Increase the maximum SSL session timeout value.

    Why it's wrong here

    The session timeout determines how long an idle connection is kept open. It has no bearing on the initial SSL handshake process or the negotiation of supported cipher suites between the client and the server, and therefore cannot solve a cipher mismatch error.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

Courseiva writes every 1Y0-312 question from scratch — 186 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Citrix exam blueprint

This 1Y0-312 practice question is part of Courseiva's free Citrix certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 1Y0-312 exam.