Courseiva
Security →mediumMultiple Choice

1Y0-204 Security Practice Question

A Citrix Administrator is asked to reduce the risk of credential theft in a Virtual Apps and Desktops 7 environment. The security team wants to prevent users' domain credentials from being stored or cached on VDAs in a way that would allow lateral movement if a VDA were compromised. Which Citrix feature should the administrator implement to meet this goal?

⚠ Common exam trap

The trap here is assuming that smart card redirection or profile caching removes credential exposure, when only certificate-based logon through FAS keeps the domain password off the VDA.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Deploy Citrix Federated Authentication Service (FAS) so the VDA receives a certificate-based logon instead of the user's password.

FAS replaces password-based logon to VDAs with certificate-based authentication. Because the user's domain password is never sent to or cached on the VDA, a compromised VDA cannot harvest reusable credentials, which reduces lateral movement risk while preserving single sign-on.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable "Local profile" caching on each VDA so credentials are retained only on the endpoint.

    Why it's wrong here

    Local profile caching stores user profile data on the VDA or endpoint, not the domain credential itself, and does not prevent credential exposure during authentication. It addresses profile behaviour rather than credential theft, so it does not meet the stated security goal.

  • ✓

    Deploy Citrix Federated Authentication Service (FAS) so the VDA receives a certificate-based logon instead of the user's password.

    Why this is correct

    FAS issues short-lived certificates to VDAs on behalf of authenticated users, allowing single sign-on to the VDA and to resources without transmitting or caching the user's domain password on the VDA. This directly reduces the credential-theft risk described.

  • ✗

    Configure "Smart card" redirection on the VDA so the smart card PIN is passed through to applications.

    Why it's wrong here

    Smart card redirection forwards smart card operations into the session but does not remove the need for credentials to be handled by the session. It does not address the goal of preventing domain credentials from being cached or exposed on the VDA in a way that enables lateral movement.

  • ✗

    Enable "Credential passing" on the Delivery Controller so credentials are reused across sessions.

    Why it's wrong here

    There is no Delivery Controller setting named "Credential passing" that reuses credentials across sessions. Even conceptually, reusing credentials would increase exposure rather than reduce it, so this option fails both technically and against the security requirement.

About these practice questions

This 1Y0-204 question is part of Courseiva's 216-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Citrix exam blueprint

This 1Y0-204 practice question is part of Courseiva's free Citrix certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 1Y0-204 exam.