1Y0-204 Security Practice Question
A Citrix Administrator needs to ensure that only users connecting from managed corporate devices can access a published desktop. The environment uses Citrix Gateway with SmartAccess. Which Citrix Gateway policy expression should the administrator use to allow access only when the endpoint has a valid corporate certificate?
⚠ Common exam trap
A common mix-up: candidates confuse client certificate presence with simple header or URL checks, which can be easily spoofed and do not provide true device authentication.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
CLIENT.SSL.CLIENT_CERT.EXISTS
The expression CLIENT.SSL.CLIENT_CERT.EXISTS evaluates whether the client presented a certificate during the SSL handshake. By using this in a Citrix Gateway policy, the administrator can ensure that only devices with a valid corporate certificate are granted access. This leverages SmartAccess to enforce device compliance. The other expressions do not verify certificate presence and thus cannot restrict access to managed devices.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
HTTP.REQ.URL.PATH.STARTSWITH("/Citrix/")
Why it's wrong here
This expression checks if the requested URL path starts with '/Citrix/'. It is used for routing or content switching based on the URL, not for device authentication. It does not verify any client certificate or device identity. Using this to restrict access would not meet the security requirement because any device could request that URL. It is unrelated to SmartAccess endpoint analysis.
- ✗
HTTP.REQ.HEADER("User-Agent").CONTAINS("CitrixReceiver")
Why it's wrong here
This expression checks the User-Agent header for the string 'CitrixReceiver'. While it can identify Citrix Receiver clients, it does not verify the presence of a corporate certificate. Any client with a Citrix Receiver could spoof the User-Agent. Therefore, it does not enforce the requirement that only managed corporate devices with a valid certificate can access the desktop. It is not a secure method for device identification.
- ✓
CLIENT.SSL.CLIENT_CERT.EXISTS
Why this is correct
This Citrix Gateway policy expression evaluates to true if the client presents a client certificate during the SSL handshake. By requiring a valid corporate certificate, the administrator can restrict access to managed devices that have the certificate installed. This is a common SmartAccess method to enforce device identity. The expression is used in a policy that is evaluated after authentication, allowing or denying access based on certificate presence.
- ✗
CLIENT.TCP.DSTPORT.EQ(443)
Why it's wrong here
This expression checks if the destination port of the client TCP connection is 443 (HTTPS). It does not provide any information about the device's identity or certificate. Any device connecting to port 443 would satisfy this condition, so it cannot be used to restrict access to managed corporate devices. It is a basic network-level check and not suitable for SmartAccess device compliance.
About these practice questions
Courseiva writes every 1Y0-204 question from scratch — 216 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Citrix exam blueprint
This 1Y0-204 practice question is part of Courseiva's free Citrix certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 1Y0-204 exam.