Be able to configure and troubleshoot Citrix Gateway authentication, Kerberos constrained delegation, SmartAccess filtering, and Configuration Logging. The single most important thing is knowing which layer enforces each control and how to verify it with the right console, command, or log.
Start practicing
Security — choose a session length
Free · No account required
Domain overview
The Security domain of 1Y0-204 covers authentication, authorization, and auditing in Citrix Virtual Apps and Desktops 7. Expect exhibit-based items on Citrix Gateway, Kerberos constrained delegation, SmartAccess policies, StoreFront, and Delivery Controller configuration, plus questions on logging administrative actions and restricting resource access by user, device, or location.
Exam objectives
Configuring Kerberos constrained delegation for Citrix Gateway and StoreFront authentication
Using SmartAccess and Citrix ADC policies to filter access by location and device
Enabling and reading Configuration Logging to a central SQL database
Applying Delivery Controller, Studio, and PowerShell security settings and delegated administration
Confusing SmartAccess endpoint analysis with StoreFront access control, or applying filters at the wrong layer so restrictions never trigger.
Forgetting that Kerberos constrained delegation requires correct SPNs and protocol transition, causing resource launch failures.
Assuming Configuration Logging is on by default, or missing that it records administrative changes rather than user session activity.
Click any question to see the full explanation and answer options, or start a focused practice session above.
Refer to the exhibit. An administrator runs the provided command on a Delivery Controller. What is the security implication of this setting?
2A security audit reveals that VDA machines are susceptible to local privilege escalation. Which Citrix policy should the administrator configure to prevent users from running unauthorized applications on the VDA?
3An administrator wants to ensure that end-user sessions are automatically terminated after 30 minutes of inactivity. Which policy should be configured?
4Refer to the exhibit. A user receives this error when attempting to launch a resource via Citrix Gateway using Kerberos constrained delegation. What is the most likely cause?
5An administrator is tasked with securing the internal communication between Delivery Controllers and VDAs. Which protocol should be used for this connection to satisfy security requirements?
6An administrator needs to restrict access to a sensitive desktop application based on the user's location. Which feature should be used?
7An administrator needs to ensure that all user data saved on the VDA is encrypted at rest. Which solution is most appropriate?
8A security team has requested that all administrative access to the Citrix environment be logged to a central, tamper-proof repository. Which Citrix feature provides this capability?
9An administrator needs to ensure that users connecting from public networks are restricted from accessing local drives on their endpoints during a Citrix Virtual Apps and Desktops session. Which policy setting should the administrator configure to achieve this requirement?
10An administrator is hardening a Citrix environment. Which TWO actions should the administrator perform to secure the communication between the Citrix Gateway and the internal StoreFront server? (Choose two.)
11A Citrix Administrator is configuring a new Delivery Group for a set of published applications. Security policy requires that users must not be able to copy or paste data between published applications and their local endpoint devices. Which setting should the administrator configure to enforce this requirement?
12A Citrix Administrator is configuring a new Citrix Gateway deployment to provide secure remote access. The security team requires that all user authentication occur against Active Directory and that users be prompted for their credentials only once. Which Citrix Gateway authentication policy should the administrator configure?
13A Citrix Administrator is configuring a Citrix Gateway to provide secure remote access. The security team requires that all authentication to the Gateway be multifactor and that the Gateway itself be protected against common web attacks. Which TWO configurations should the administrator implement to meet these requirements? (Choose two.)
14A Citrix Administrator is configuring a StoreFront server to authenticate users. The security team requires that users authenticate using smart cards and that the smart card PIN is not cached. Which StoreFront authentication method should the administrator configure?
15A Citrix Administrator needs to ensure that only users connecting from managed corporate devices can access a published desktop. The environment uses Citrix Gateway with SmartAccess. Which Citrix Gateway policy expression should the administrator use to allow access only when the endpoint has a valid corporate certificate?
16A Citrix Administrator is deploying a new Delivery Controller and wants to ensure that only authorized administrators can make changes to the site configuration. Which built-in role should the administrator assign to a help desk operator who needs to view the site configuration but must not be able to modify it?
17A Citrix Administrator has configured a Citrix Gateway to provide external access to published applications. The security team wants to ensure that users authenticating from outside the corporate network must provide two different authentication factors before they can reach StoreFront. Which Citrix Gateway configuration should the administrator implement?
18A Citrix Administrator is reviewing the security posture of a Citrix Virtual Apps and Desktops 7 site. The security team wants to reduce the risk of privileged credential theft from the Delivery Controllers. Which TWO measures should the administrator implement to harden the Controllers? (Choose two.)
19A Citrix Administrator is asked to reduce the risk of credential theft in a Virtual Apps and Desktops 7 environment. The security team wants to prevent users' domain credentials from being stored or cached on VDAs in a way that would allow lateral movement if a VDA were compromised. Which Citrix feature should the administrator implement to meet this goal?
20A Citrix Administrator is configuring Citrix Gateway to provide external access to published desktops. The security policy requires that after a user authenticates, the Gateway must evaluate the endpoint's posture, such as whether antivirus is running and up to date, before granting access to the desktop. Which Citrix Gateway feature should the administrator configure to meet this requirement?
Be able to configure and troubleshoot Citrix Gateway authentication, Kerberos constrained delegation, SmartAccess filtering, and Configuration Logging. The single most important thing is knowing which layer enforces each control and how to verify it with the right console, command, or log.
The Courseiva 1Y0-204 question bank contains 20 questions in the Security domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Security domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included