Courseiva
Security →hardMultiple Choice

1Y0-204 Security Practice Question

A security audit reveals that VDA machines are susceptible to local privilege escalation. Which Citrix policy should the administrator configure to prevent users from running unauthorized applications on the VDA?

⚠ Common exam trap

Many candidates suggest standard NTFS permissions or user rights assignment policies, missing that granular application execution control requires specialized whitelisting tools like AppLocker.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement 'AppLocker' or 'WEM Security' policies.

AppLocker or Citrix Workspace Environment Management (WEM) Security policies are the industry-standard methods to enforce application whitelisting on VDAs. By defining strict execution policies, administrators ensure that only signed or authorized binaries can execute within the user session. This prevents malicious scripts or unauthorized executables from running, thereby mitigating the risk of users gaining administrative privileges or compromising the integrity of the virtual desktop environment during the session.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable 'File Type Association' for all users.

    Why it's wrong here

    File Type Association policies define which applications open specific file types within the session. This is an end-user experience feature and does not provide security controls or the ability to block unauthorized binaries from executing, making it ineffective against local privilege escalation or unauthorized application usage.

  • ✓

    Implement 'AppLocker' or 'WEM Security' policies.

    Why this is correct

    These tools allow administrators to restrict execution to specific authorized files or digitally signed binaries. By whitelisting allowed processes and blocking all others, the administrator effectively prevents the execution of malicious tools that could be used for privilege escalation, significantly hardening the security posture of the VDA.

  • ✗

    Restrict 'Clipboard Redirection' in Citrix policies.

    Why it's wrong here

    Clipboard redirection policies control whether users can copy and paste data between the local endpoint and the virtual session. While this prevents data exfiltration, it does nothing to prevent the execution of malicious software or local privilege escalation attempts initiated within the virtual session itself.

  • ✗

    Disable 'Local Drive Mapping' in the session.

    Why it's wrong here

    Disabling drive mapping prevents users from accessing local files within the virtual session. While this is a data security measure to prevent data leakage, it does not prevent a user from executing unauthorized software already present on the VDA image or downloaded via a browser.

About these practice questions

Courseiva writes every 1Y0-204 question from scratch — 216 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Citrix exam blueprint

This 1Y0-204 practice question is part of Courseiva's free Citrix certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 1Y0-204 exam.