Courseiva
Security →hardMultiple Choice

1Y0-204 Security Practice Question

A Citrix Administrator is configuring Citrix Gateway to provide external access to published desktops. The security policy requires that after a user authenticates, the Gateway must evaluate the endpoint's posture, such as whether antivirus is running and up to date, before granting access to the desktop. Which Citrix Gateway feature should the administrator configure to meet this requirement?

⚠ Common exam trap

It's easy for candidates to confuse endpoint posture evaluation with access control based on user or session attributes, since both are enforced by Gateway policies but only EPA inspects the device itself.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

EPA (Endpoint Analysis) scans configured in a pre-authentication or post-authentication policy

Endpoint Analysis is the Citrix Gateway capability that inspects the endpoint for compliance conditions such as antivirus presence and update status. Binding EPA scans to a pre-authentication or post-authentication policy lets the Gateway allow or deny access based on the scan result. Other features handle authentication, single sign-on, or traffic routing, but only EPA evaluates endpoint posture.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Citrix Federated Authentication Service (FAS)

    Why it's wrong here

    FAS is used to issue certificates to users so they can single sign-on to Citrix resources without re-entering credentials. It is an authentication mechanism, not an endpoint posture evaluation tool. It does not inspect the endpoint for antivirus status, so it cannot satisfy the posture-check requirement.

  • ✓

    EPA (Endpoint Analysis) scans configured in a pre-authentication or post-authentication policy

    Why this is correct

    Endpoint Analysis (EPA) is the Citrix Gateway feature that runs scans on the endpoint to check for specific conditions, such as whether antivirus software is installed and up to date. EPA scans can be bound to pre-authentication or post-authentication policies, and the results determine whether the user is allowed to proceed, which exactly matches the requirement.

  • ✗

    SmartAccess with Citrix ADC policies

    Why it's wrong here

    SmartAccess uses Gateway session policies and Citrix ADC policy expressions to control access based on attributes like user group, endpoint IP, or whether the connection is over a secure channel. It does not perform endpoint posture checks such as antivirus status, so it cannot enforce the requirement to verify that antivirus is running and current.

  • ✗

    Citrix Gateway VPN with split tunneling disabled

    Why it's wrong here

    Disabling split tunneling forces all endpoint traffic through the Gateway, which can improve security by inspecting traffic, but it does not perform endpoint posture checks. It does not verify antivirus state or other endpoint conditions before granting access, so it does not meet the specific requirement.

About these practice questions

Courseiva writes every 1Y0-204 question from scratch — 216 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Citrix exam blueprint

This 1Y0-204 practice question is part of Courseiva's free Citrix certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 1Y0-204 exam.