Courseiva
Secure Access →mediumMultiple Choice

1Y0-204 Secure Access Practice Question

A Citrix Administrator needs to configure Citrix Gateway to require two-factor authentication only when users connect from outside the corporate network, while internal users authenticate with only their Active Directory credentials. The environment uses Citrix Gateway 13.0 with StoreFront 1912. Which configuration should the administrator implement?

⚠ Common exam trap

The trap here is assuming that SmartAccess or endpoint analysis can enforce a second authentication factor, when in fact authentication policies with IP-based expressions are required to differentiate internal and external users.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create two authentication policies: one LDAP-only for internal IPs and one LDAP plus RADIUS for all other IPs, then bind them to the Citrix Gateway virtual server in priority order with appropriate expressions.

The requirement is to apply two-factor authentication only for external users. This is achieved by creating separate authentication policies with expressions that match internal versus external IP ranges, and binding them to the Citrix Gateway virtual server in the correct priority order. Internal users match the LDAP-only policy, while external users fall through to the LDAP plus RADIUS policy, ensuring the second factor is enforced only where needed.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create two authentication policies: one LDAP-only for internal IPs and one LDAP plus RADIUS for all other IPs, then bind them to the Citrix Gateway virtual server in priority order with appropriate expressions.

    Why this is correct

    This approach uses policy expressions to differentiate internal and external users, applying LDAP-only for internal IPs and LDAP plus RADIUS for external IPs. Binding both policies to the virtual server with correct priorities ensures internal users get single-factor and external users get two-factor authentication, meeting the requirement precisely without affecting the other group.

  • ✗

    Configure a Citrix Gateway policy with the expression REQ.IP.SOURCEIP == 10.0.0.0 -netmask 255.0.0.0 and bind it to the Primary Authentication policy, enabling LDAP as the first factor.

    Why it's wrong here

    Binding an LDAP policy to a policy expression that matches internal IP addresses would force LDAP authentication for internal users, but it does not add a second factor for external users. External users would still only perform LDAP authentication, failing the two-factor requirement. This approach misapplies the policy binding and does not address external multi-factor needs.

  • ✗

    Configure Citrix Gateway to use LDAP authentication and enable the 'Two-factor authentication' checkbox in the global authentication settings, which automatically applies to external users only.

    Why it's wrong here

    Citrix Gateway does not have a global 'Two-factor authentication' checkbox that automatically applies only to external users. Authentication policies must be explicitly configured and bound with expressions. This option describes a non-existent feature and would not meet the requirement to differentiate internal and external users.

  • ✗

    Enable SmartAccess on the Citrix Gateway virtual server and configure a session policy that requires a second factor when the endpoint analysis scan detects a non-domain-joined device.

    Why it's wrong here

    SmartAccess with endpoint analysis can enforce policies based on device posture, but it does not directly enforce a second authentication factor. It is used for authorization and session policies after authentication. The scenario requires two-factor authentication based on network location, not device posture, so this does not satisfy the requirement.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

Courseiva writes every 1Y0-204 question from scratch — 216 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Citrix exam blueprint

This 1Y0-204 practice question is part of Courseiva's free Citrix certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 1Y0-204 exam.