1Y0-204 Security Practice Question
A Citrix Administrator is deploying a new Delivery Controller and wants to ensure that only authorized administrators can make changes to the site configuration. Which built-in role should the administrator assign to a help desk operator who needs to view the site configuration but must not be able to modify it?
⚠ Common exam trap
The trap here is choosing a role based on its name rather than its actual permission set, since several administrator roles sound view-oriented but actually include write capabilities.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Read-only Administrator
Role-based access control in Citrix Virtual Apps and Desktops 7 uses predefined roles that bundle permissions. The Read-only Administrator role is the only built-in role that grants visibility across the site without any write access, making it the correct fit for an operator who must inspect but not alter configuration. Other roles either grant excessive permissions or are scoped too narrowly.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Full Administrator
Why it's wrong here
Full Administrator grants complete control over the site, including the ability to create and delete objects, modify policies, and manage other administrators. Giving this role to a help desk operator who only needs to view configuration would violate least privilege and allow unintended changes, so it is not appropriate for this requirement.
- ✓
Read-only Administrator
Why this is correct
The Read-only Administrator role in Citrix Virtual Apps and Desktops 7 provides view-only access to the entire site configuration without the ability to change any settings. Assigning this role to the help desk operator satisfies the requirement to view configuration while preventing modifications, which aligns with the principle of least privilege.
- ✗
Host Administrator
Why it's wrong here
Host Administrator is scoped to managing hosting connections and the resources within them, such as creating catalogs and machine identities. It does not grant the broad site-wide view that a help desk operator needs, and it includes write permissions that exceed the view-only requirement, so it is not the correct role here.
- ✗
Delivery Group Administrator
Why it's wrong here
Delivery Group Administrator allows management of assigned delivery groups, including power operations and session management, but it is limited in scope and includes modification rights. It does not provide the read-only, site-wide visibility requested, and its write capabilities would violate the requirement that the operator must not be able to change configuration.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
About these practice questions
Courseiva writes every 1Y0-204 question from scratch — 216 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Citrix exam blueprint
This 1Y0-204 practice question is part of Courseiva's free Citrix certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 1Y0-204 exam.