Courseiva

1Y0-204 Printing and Profile Management Practice Question

A Citrix Administrator is configuring Citrix Profile Management in a Virtual Apps and Desktops 7 environment. The security team requires that profile data be encrypted while in transit and that the User Store be protected against unauthorized access. The administrator plans to use the default profile management settings. Which statement correctly describes the security posture of the User Store in this default configuration?

⚠ Common exam trap

The trap here is assuming that Citrix Profile Management encrypts profile data by default, when in fact SMB encryption must be explicitly configured on the file server.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Profile data is transmitted unencrypted over SMB unless SMB signing or encryption is configured, and NTFS permissions on the User Store control access.

Citrix Profile Management uses SMB to access the User Store, and by default SMB traffic is not encrypted. Access control is enforced through NTFS permissions on the share. To meet the security team's requirements, the administrator must enable SMB encryption or signing and configure NTFS permissions appropriately. The default configuration does not provide automatic EFS encryption or an Active Directory-stored encryption key.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Profile data is encrypted automatically using EFS on the User Store, and access is restricted to the assigned user only.

    Why it's wrong here

    Citrix Profile Management does not automatically apply EFS encryption to the User Store in the default configuration. While NTFS permissions can be configured to restrict access, EFS is not enabled by default. Assuming automatic EFS encryption would leave the User Store unprotected in transit and at rest, which fails the security team's requirement in this scenario.

  • ✓

    Profile data is transmitted unencrypted over SMB unless SMB signing or encryption is configured, and NTFS permissions on the User Store control access.

    Why this is correct

    By default, Citrix Profile Management stores profiles on an SMB share and relies on NTFS permissions for access control. SMB encryption is not enabled by default, so data in transit is unencrypted unless SMB signing or SMB encryption is configured on the file server. This matches the default security posture and explains why additional hardening is required.

  • ✗

    Profile data is encrypted end-to-end using the Citrix Profile Management encryption key stored in Active Directory.

    Why it's wrong here

    Citrix Profile Management does not provide end-to-end encryption using an Active Directory-stored key by default. While there is a profile management encryption feature for specific data, it is not enabled by default and does not encrypt all profile data in transit. This option misrepresents the default behavior and would not satisfy the security requirement without additional configuration.

  • ✗

    Profile data is stored in the VDA's local cache and synchronized to the User Store using an encrypted Citrix channel.

    Why it's wrong here

    Citrix Profile Management uses a local cache for streaming and active write-back, but synchronization to the User Store does not occur over an encrypted Citrix channel by default. The local cache is a performance feature, not a security mechanism. This option incorrectly describes the synchronization transport and would not meet the security team's encryption requirement.

About these practice questions

Courseiva writes every 1Y0-204 question from scratch — 216 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Citrix exam blueprint

This 1Y0-204 practice question is part of Courseiva's free Citrix certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 1Y0-204 exam.