1Y0-204 Security Practice Question
A Citrix Administrator is configuring a new Citrix Gateway deployment to provide secure remote access. The security team requires that all user authentication occur against Active Directory and that users be prompted for their credentials only once. Which Citrix Gateway authentication policy should the administrator configure?
⚠ Common exam trap
The trap here is assuming that any authentication method that validates against AD will automatically provide single sign-on, but only LDAP with SSO explicitly passes credentials to the Citrix environment without a second prompt.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
LDAP authentication policy with single sign-on enabled.
Configuring an LDAP authentication policy on Citrix Gateway allows direct validation of user credentials against Active Directory. Enabling single sign-on ensures that the credentials are reused for the Citrix Virtual Apps and Desktops session, so users authenticate only once. This satisfies both the security team's requirement for AD authentication and the user experience requirement for a single prompt.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
RADIUS authentication policy with two-factor authentication.
Why it's wrong here
RADIUS authentication is typically used for two-factor authentication, such as with tokens. While it can authenticate against AD via a RADIUS server, it would require an additional component and may prompt the user for a second factor, which conflicts with the requirement for a single credential prompt. Also, RADIUS alone does not provide SSO to the Citrix environment without additional configuration.
- ✗
SAML authentication policy with Citrix Federated Authentication Service.
Why it's wrong here
SAML authentication is used for federated identity scenarios, often involving external identity providers. It requires additional infrastructure like FAS and is not the simplest way to authenticate directly against Active Directory for internal users. While it can provide SSO, it introduces complexity and is not necessary when direct AD authentication is required. The scenario does not mention federation.
- ✓
LDAP authentication policy with single sign-on enabled.
Why this is correct
An LDAP authentication policy allows Citrix Gateway to validate user credentials directly against Active Directory. Enabling single sign-on (SSO) means that after the initial authentication, the user's credentials are passed to the Citrix Virtual Apps and Desktops environment, so they are not prompted again. This meets the requirement of authenticating against AD and providing a single login experience for the user.
- ✗
Certificate authentication policy with smart card.
Why it's wrong here
Certificate authentication with smart card would require users to have smart cards and would prompt for a PIN, which is not a single credential prompt in the traditional sense. It also requires a PKI infrastructure. The requirement is to authenticate against Active Directory with a single prompt, which is more directly achieved with LDAP and SSO. Smart card authentication is a different method and not specified here.
About these practice questions
Courseiva writes every 1Y0-204 question from scratch — 216 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Citrix exam blueprint
This 1Y0-204 practice question is part of Courseiva's free Citrix certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 1Y0-204 exam.