1Y0-204 Security Practice Question
A Citrix Administrator has configured a Citrix Gateway to provide external access to published applications. The security team wants to ensure that users authenticating from outside the corporate network must provide two different authentication factors before they can reach StoreFront. Which Citrix Gateway configuration should the administrator implement?
⚠ Common exam trap
The trap here is treating multiple authentication policies as inherently multi-factor, when factors must be of different types to count as two-factor.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure an LDAP authentication policy and a RADIUS authentication policy, then bind both to the Gateway in a single authentication policy that uses them in sequence.
Two-factor authentication on Citrix Gateway is achieved by chaining two policies that validate different factor types, typically an LDAP policy for the directory password and a RADIUS policy for a one-time code or token. The Gateway then requires both to succeed before granting access to StoreFront.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Configure an LDAP authentication policy and a RADIUS authentication policy, then bind both to the Gateway in a single authentication policy that uses them in sequence.
Why this is correct
Binding LDAP and RADIUS policies to the Gateway and requiring both in sequence creates a two-factor authentication flow: the directory password plus a one-time code or token validated by RADIUS. This is the standard way to enforce two distinct factors before StoreFront access is granted.
- ✗
Enable "Clientless Access" on the Gateway and require users to install the Citrix Workspace app.
Why it's wrong here
Clientless access and Workspace app installation affect how resources are delivered after authentication. They do not add a second authentication factor and therefore do not satisfy the requirement that two different factors be verified before reaching StoreFront.
- ✗
Bind a single LDAP policy to the Gateway and enable "Single sign-on" to StoreFront.
Why it's wrong here
Single sign-on with one LDAP policy authenticates the user with a single factor and then reuses that identity for StoreFront. It reduces prompts but does not introduce a second factor, so it cannot meet the two-factor authentication requirement.
- ✗
Configure two LDAP authentication policies pointing to the same domain controller and bind both to the Gateway.
Why it's wrong here
Two LDAP policies against the same directory both validate the same password factor. Binding both does not add a second distinct factor, so an attacker who obtains the password can still authenticate. This configuration fails the two-factor requirement even though two policies are present.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
About these practice questions
This 1Y0-204 question is part of Courseiva's 216-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Citrix exam blueprint
This 1Y0-204 practice question is part of Courseiva's free Citrix certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 1Y0-204 exam.