Courseiva
Secure Access →mediumMultiple Select

1Y0-204 Secure Access Practice Question

A Citrix Administrator is configuring SmartAccess to restrict access to published applications based on the endpoint device's security posture. The environment uses Citrix Gateway and StoreFront. The administrator needs to ensure that only devices with up-to-date antivirus and a specific registry key are allowed access. Which two components must be configured to achieve this? (Choose two.)

⚠ Common exam trap

Watch out — candidates often confuse authentication policies with endpoint posture checks; authentication verifies who the user is, while EPA and session policies determine what the device can access.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Session policies on Citrix Gateway to apply the results of the Endpoint Analysis scan.

SmartAccess based on endpoint security posture requires an Endpoint Analysis scan on Citrix Gateway to check the device for antivirus and registry keys, and session policies to apply the scan results and control access. These two components work together: the scan collects posture data, and the session policy enforces the appropriate level of access based on that data.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    StoreFront Citrix Receiver for Web site configured with SmartAccess filters.

    Why it's wrong here

    StoreFront can display different applications based on SmartAccess tags, but it relies on the Gateway to provide the tags. Configuring StoreFront alone does not enforce endpoint security; it only presents the filtered resources. The actual posture check and policy enforcement happen at the Gateway, making this component insufficient by itself.

  • ✓

    Session policies on Citrix Gateway to apply the results of the Endpoint Analysis scan.

    Why this is correct

    Session policies on Citrix Gateway use the results of the EPA scan to apply actions, such as allowing or denying access, or restricting features. They are essential to translate the scan outcome into access control. Without session policies, the scan results would not be enforced, so this is a required component.

  • ✗

    Citrix ADC authentication policies with LDAP and RADIUS for multi-factor authentication.

    Why it's wrong here

    Authentication policies verify user identity, not device posture. While multi-factor authentication enhances security, it does not check for antivirus or registry keys. The scenario requires endpoint security posture checks, which are handled by EPA and session policies, not authentication policies.

  • ✗

    Delivery Controller policies to filter applications based on user group membership.

    Why it's wrong here

    Delivery Controller policies control access to applications and desktops based on user or group membership, not device posture. They do not evaluate endpoint security. While they can restrict access, they cannot enforce antivirus or registry key checks, so they are not part of the SmartAccess endpoint posture solution.

  • ✓

    Endpoint Analysis scan on Citrix Gateway to check for antivirus and registry key.

    Why this is correct

    Endpoint Analysis (EPA) scans run on the user device when connecting through Citrix Gateway. They can check for antivirus status and registry keys. The scan results are used to assign session policies that control access. Without EPA, the Gateway cannot determine device posture, making this a required component for SmartAccess based on endpoint security.

About these practice questions

Courseiva writes every 1Y0-204 question from scratch — 216 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Citrix exam blueprint

This 1Y0-204 practice question is part of Courseiva's free Citrix certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 1Y0-204 exam.