Be able to select the right NetScaler, StoreFront, or VDA feature for a stated security requirement and trace authentication from Gateway to published resource. The most important thing: know how single sign-on is preserved end to end and when EPA or FAS is required.
Start practicing
Advanced Security and Access Control — choose a session length
Free · No account required
Domain overview
This domain covers securing Citrix Virtual Apps and Desktops 7 access through NetScaler Gateway and StoreFront, plus hardening VDAs and identity integration. Questions present administrator scenarios: reading NetScaler logs, configuring Azure AD as IdP, enforcing endpoint requirements via policies, and selecting VDA hardening settings. Expect feature-selection and troubleshooting items rather than pure recall.
Exam objectives
NetScaler Gateway authentication, session policies, and SmartAccess/SmartControl EPA scans
StoreFront authentication flow and Citrix Gateway integration for published app launches
Azure AD as Identity Provider with SAML and Citrix Federated Authentication Service
VDA hardening: disabling unused services, restricting drive redirection, and Windows security baselines
Assuming single sign-on works automatically after NetScaler authentication; StoreFront and VDA often need matching authentication or FAS configuration to avoid a second prompt.
Confusing endpoint analysis (EPA) scan policies with authorization policies; EPA checks device posture, while authorization decides resource access.
Believing VDA hardening is one setting; it requires multiple coordinated changes across services, policies, and registry, not a single toggle.
Click any question to see the full explanation and answer options, or start a focused practice session above.
An administrator is implementing Azure AD as the Identity Provider (IdP) for a Citrix environment. Users successfully authenticate via the NetScaler Gateway but are prompted for credentials again when launching their published desktops. Which component must be configured to ensure seamless single sign-on to the VDA in this scenario?
2A company requires that help desk staff be able to view session information and reset sessions but must not be able to modify machine catalogs or delivery groups. Which built-in administrative role should be assigned to the help desk group?
3When using Citrix Gateway with 'Clientless Access' for certain web applications, an administrator notices that some advanced security features of the web apps are breaking. What is the most likely cause of this issue?
4A company wants to implement Adaptive Authentication to change the authentication requirements based on the user's location and device posture. Which Citrix component is primarily responsible for evaluating these factors and choosing the appropriate authentication flow?
5An administrator needs to ensure that internal users accessing Virtual Apps and Desktops via Citrix Gateway are authenticated using multi-factor authentication, while external users must use a client certificate. Which NetScaler feature should the administrator implement to satisfy these diverse authentication requirements?
6A security auditor requires that all users connecting to the internal Citrix environment via NetScaler must have their device disk encrypted. Which feature should the administrator configure to enforce this requirement before the user's session is established?
7Which component is primarily responsible for performing the initial authentication of a remote user before allowing access to internal Citrix resources?
8Refer to the exhibit. An administrator is seeing this error in the NetScaler logs. What is the most appropriate action to resolve this connectivity issue?
9Which security best practice should be implemented to protect the Citrix Gateway against brute-force password guessing attacks?
10Which THREE configurations contribute to a 'Hardened' VDA environment? (Choose three.)
11An administrator needs to implement granular control over clipboard redirection based on the user's connection point. Users accessing resources from the internal office network should have full clipboard access, while those connecting via Citrix Gateway from public locations must have clipboard redirection disabled. Which tool should the administrator configure to achieve this?
12A company requires that users accessing virtual desktops via Citrix Gateway must pass a multi-factor authentication (MFA) check. The administrator uses Citrix ADC as the SAML Service Provider. Which configuration step is mandatory to ensure the SAML assertion is correctly validated?
13Which feature should an administrator enable to protect against unauthorized users capturing the screen or recording keystrokes from a compromised endpoint while a user is working in a virtual session?
14A Citrix Administrator is configuring smart card authentication for internal users accessing published applications through Citrix Workspace app. The administrator wants to enforce the use of a specific cryptographic service provider (CSP) on the VDA for all smart card operations. Which Citrix policy setting should the administrator configure?
15A Citrix Administrator is configuring a Citrix Gateway to provide secure remote access to published applications. The administrator wants to implement SmartAccess to control access based on endpoint analysis results. Which two components are required to enable SmartAccess with EPA? (Choose two.)
16A Citrix Administrator is configuring a Citrix Gateway to authenticate users with RADIUS two-factor authentication. The administrator wants to ensure that users are prompted for their RADIUS credentials only after successful Active Directory authentication. Which authentication policy configuration should the administrator use?
17A Citrix Administrator is configuring a Citrix Gateway to provide access to published applications. The administrator wants to ensure that users can only access resources if their device has a specific registry key set. Which Citrix Gateway feature should the administrator use?
18An administrator is configuring Citrix Gateway to use Adaptive Authentication. The security team wants to require multi-factor authentication (MFA) only when users connect from outside the corporate network. Which Citrix ADC policy expression should the administrator use to trigger MFA based on the user's location?
19A Citrix administrator needs to enforce a policy that prevents users from accessing local drives and printers on their endpoint devices when they connect to published applications through Citrix Gateway. The policy must apply only to remote users and not to internal users. Which Citrix policy setting and filter should the administrator configure?
20A Citrix Administrator must configure a Citrix Gateway so that when users authenticate, they are required to provide their domain credentials plus a one-time passcode generated by a RADIUS server. The administrator has already configured the RADIUS server as an authentication policy and bound it to the Gateway. However, after testing, users are prompted for credentials twice but are never asked for a passcode. What should the administrator do to resolve this?
21A Citrix administrator is setting up a new StoreFront store for external users. The security team requires that users authenticate using their Active Directory credentials, and that the authentication process is protected with multi-factor authentication (MFA). The company uses Citrix Gateway with RADIUS for MFA. Which authentication method should the administrator configure on Citrix Gateway to meet these requirements?
22A Citrix Administrator is configuring a Citrix Gateway to use Smart Card authentication for external users. The environment uses a two-factor authentication requirement: smart card and Active Directory password. The administrator has configured the Gateway virtual server with a Smart Card authentication policy and an LDAP authentication policy. Users report that they are only prompted for the smart card and not for the LDAP password. What should the administrator do to enforce the two-factor authentication?
23A Citrix Administrator is configuring a Citrix Gateway to provide access to published applications. The security team requires that all user connections use smart card authentication with certificate validation. The administrator has configured the gateway with a server certificate and enabled smart card authentication. Users report that they are prompted for a PIN but then receive an error stating 'Cannot complete your request.' Which Citrix ADC setting should the administrator verify to ensure that the client certificate is being validated correctly?
24An administrator is implementing SmartAccess policies in a Citrix Virtual Apps and Desktops 7 environment with Citrix Gateway. The requirement is to allow users to access a published application only if they connect through Citrix Gateway and their endpoint has a specific registry key set. The administrator has configured the Gateway and StoreFront. Which Delivery Controller policy filter should be used to enforce this condition?
25An administrator is configuring Citrix StoreFront to use HTTPS for all communications. The security team requires that the StoreFront server uses a certificate that is trusted by all user devices. The administrator has obtained a certificate from a public CA and installed it on the StoreFront server. Which StoreFront configuration must be updated to bind the certificate to the IIS website?
26An administrator is configuring Citrix Gateway to use SAML authentication with Microsoft Azure AD as the identity provider. The requirement is that users must authenticate using Azure AD and then be authorized to access specific published applications based on their group membership in Azure AD. The administrator has configured the SAML action and policy on Citrix ADC and imported the Azure AD certificate. Which Citrix ADC feature should be configured to extract the group membership from the SAML assertion and use it for authorization?
27A Citrix Administrator is configuring App Protection policies in a Citrix Virtual Apps and Desktops 7 environment to prevent keylogging and screen capturing on user devices. The administrator wants to ensure that the protection is applied to both the VDA and the user device. Which two components must be installed or configured to enable App Protection? (Choose two.)
28An administrator needs to configure a Citrix Gateway to use Smart Card authentication for users connecting from outside the network. The environment uses Citrix Virtual Apps and Desktops 7 with StoreFront. The administrator has installed the Smart Card certificate on the Gateway and configured the LDAP authentication policy. What additional step must be taken on the Gateway to enable Smart Card authentication?
Be able to select the right NetScaler, StoreFront, or VDA feature for a stated security requirement and trace authentication from Gateway to published resource. The most important thing: know how single sign-on is preserved end to end and when EPA or FAS is required.
The Courseiva 1Y0-312 question bank contains 28 questions in the Advanced Security and Access Control domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Advanced Security and Access Control domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included