1Y0-204 Architecture Practice Question
A Citrix architect is designing a Virtual Apps and Desktops environment for a hospital campus. The security team requires that no user credentials or session traffic traverse the internal network in clear text, and that StoreFront servers must not be directly reachable from the user VLAN. The architect needs to place a component inline so that all ICA traffic is encrypted end-to-end and StoreFront is isolated. Which component should the architect place in front of the StoreFront servers to meet these requirements?
⚠ Common exam trap
The trap here is assuming that enabling TLS on StoreFront or the XML service alone provides end-to-end encryption and hides the StoreFront tier, when an inline ICA proxy appliance is actually required.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Citrix ADC (NetScaler) with SSL offload and ICA proxy
Placing a Citrix ADC with SSL offload and ICA proxy inline ensures that user connections terminate on the ADC, StoreFront remains hidden from the user VLAN, and ICA sessions are proxied rather than passed through in clear text. This directly satisfies both the encryption and network isolation mandates without redesigning the StoreFront or VDA tiers.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Workspace Environment Management agent on each VDA
Why it's wrong here
The Workspace Environment Management agent optimizes user profiles, CPU, and memory on VDAs; it is not a network edge component. It cannot terminate TLS, proxy ICA sessions, or prevent direct access to StoreFront from the user VLAN, so it does not address the encryption or isolation requirements in this scenario.
- ✗
Delivery Controller with XML service TLS enabled
Why it's wrong here
Enabling TLS on the Delivery Controller XML service encrypts broker communication between StoreFront and the Controller, but it does not sit inline between users and StoreFront. It cannot isolate the StoreFront tier from the user VLAN or provide ICA proxy, so the stated security requirements are not met by this component.
- ✓
Citrix ADC (NetScaler) with SSL offload and ICA proxy
Why this is correct
Citrix ADC with SSL offload and ICA proxy terminates TLS from users, re-encrypts or proxies ICA to VDAs, and hides StoreFront behind the ADC. This satisfies the security team's demand that no credentials or session data traverse the internal network in clear text and that StoreFront is not directly reachable from the user VLAN.
- ✗
StoreFront server group with certificate binding only
Why it's wrong here
A StoreFront server group with a certificate binding encrypts authentication traffic to StoreFront but does not isolate StoreFront from the user VLAN or provide ICA proxy. Users would still reach StoreFront directly, and ICA traffic would not be centrally encrypted or brokered through an inline appliance, so the isolation and end-to-end encryption requirements fail.
Visual reference
About these practice questions
One of 216 original 1Y0-204 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Citrix exam blueprint
This 1Y0-204 practice question is part of Courseiva's free Citrix certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 1Y0-204 exam.