1Y0-204 Security Practice Question
A Citrix Administrator is reviewing the security posture of a Citrix Virtual Apps and Desktops 7 site. The security team wants to reduce the risk of privileged credential theft from the Delivery Controllers. Which TWO measures should the administrator implement to harden the Controllers? (Choose two.)
⚠ Common exam trap
The trap here is picking options that sound like general best practices, such as disabling the firewall or adding monitoring, when the scenario specifically asks about protecting privileged credentials.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable Windows Defender Credential Guard on the Delivery Controllers
Credential Guard protects derived credentials on the Controller by isolating them in a virtualized environment, and restricting interactive logon rights limits who can even attempt to harvest credentials. Together they address the specific risk of privileged credential theft. The other options either add components, weaken network controls, or change the database in ways that do not improve security.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure the Delivery Controllers to use a SQL Server Express database for the site
Why it's wrong here
SQL Server Express is limited in size and performance and is intended for lab or small deployments, not for production security. Switching to Express does not harden the Controllers against credential theft and may introduce availability and scalability problems, so it does not address the stated risk.
- ✗
Install the Citrix Director component on every Delivery Controller
Why it's wrong here
Director is a monitoring and troubleshooting console, and installing it on Controllers increases the server's role footprint rather than reducing it. Adding components does not harden against credential theft and may expand the attack surface, so it is not a recommended security measure for this scenario.
- ✓
Enable Windows Defender Credential Guard on the Delivery Controllers
Why this is correct
Credential Guard uses virtualization-based security to isolate and protect derived domain credentials such as NTLM hashes and Kerberos tickets. On Delivery Controllers, which often hold highly privileged service accounts, this significantly reduces the risk of credential theft through tools like Mimikatz. It is a supported and recommended hardening step for Citrix infrastructure servers.
- ✓
Restrict interactive logon rights on the Delivery Controllers to only authorized administrators
Why this is correct
Limiting interactive logon to a small set of administrators reduces the attack surface by preventing unnecessary users from establishing sessions on the Controllers. Fewer interactive sessions mean fewer opportunities for credential dumping and lateral movement. This is a standard least-privilege hardening measure that directly mitigates the risk of privileged credential theft.
- ✗
Disable the Windows Firewall on the Delivery Controllers to simplify management traffic
Why it's wrong here
Disabling Windows Firewall removes a key network security control and exposes the Controllers to unnecessary inbound traffic. This increases rather than reduces the risk of compromise and credential theft, and it contradicts standard hardening guidance for Citrix infrastructure servers.
About these practice questions
Courseiva writes every 1Y0-204 question from scratch — 216 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Citrix exam blueprint
This 1Y0-204 practice question is part of Courseiva's free Citrix certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 1Y0-204 exam.