Courseiva
Security →mediumMultiple Choice

1Y0-204 Security Practice Question

An administrator needs to ensure that all user data saved on the VDA is encrypted at rest. Which solution is most appropriate?

⚠ Common exam trap

Candidates often mistake file-level permissions or user profiles for data-at-rest encryption, ignoring disk-level solutions required for compliance and physical security.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure BitLocker on the VDA disk.

To ensure that data is encrypted at rest, the administrator should implement BitLocker or a similar disk-level encryption technology on the underlying storage or the VDA hard drive. This provides a robust layer of protection, ensuring that even if physical storage media is stolen or if a virtual disk file is copied, the data remains unreadable without the appropriate decryption keys, satisfying stringent compliance and security requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable ICA encryption.

    Why it's wrong here

    ICA encryption only protects data as it travels over the network between the client and the VDA. It provides no protection for data once it is stored on the disk within the VDA, making it ineffective for the requirement of protecting data at rest.

  • ✓

    Configure BitLocker on the VDA disk.

    Why this is correct

    BitLocker provides full-disk encryption, ensuring that all data written to the virtual or physical disk is encrypted. This is the industry-standard method for protecting data at rest, and it is the correct choice for ensuring the security of user files stored on the virtual desktop machine.

  • ✗

    Implement TLS 1.3 for connections.

    Why it's wrong here

    TLS 1.3 is a transport layer security protocol used for securing data in transit over network connections. It has no mechanism for encrypting files stored on a disk and does not satisfy the requirement for data-at-rest protection in the environment.

  • ✗

    Enable SmartAccess.

    Why it's wrong here

    SmartAccess is a feature used for controlling access to resources based on the user's connection context. It is an access control mechanism, not a data encryption tool, and therefore does not perform any function related to the encryption of data stored on the VDA's disks.

About these practice questions

This 1Y0-204 question is part of Courseiva's 216-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Citrix exam blueprint

This 1Y0-204 practice question is part of Courseiva's free Citrix certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 1Y0-204 exam.