1Y0-204 Security Practice Question
An administrator wants to ensure that end-user sessions are automatically terminated after 30 minutes of inactivity. Which policy should be configured?
⚠ Common exam trap
Candidates often confuse 'Idle timer' with 'Disconnected session timer' or 'Session limit,' failing to realize that the idle timer specifically targets sessions that remain active but show no user input.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Idle timer.
Idle timer policies are essential for maintaining security in environments where workstations might be left unattended. By configuring the 'Idle timer' setting to 30 minutes, the system forces the session to log off or disconnect, ensuring that sensitive data is not exposed to passersby. This is a critical security control to prevent unauthorized use of active user sessions in shared or high-traffic office areas.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Session connection timer.
Why it's wrong here
The session connection timer dictates the maximum duration a session can remain active regardless of activity. It is used to enforce total session limits rather than responding to user inactivity, making it the wrong choice for terminating sessions that have been left idle by an absent user.
- ✗
Disconnected session timer.
Why it's wrong here
This timer determines how long a session can remain in a 'disconnected' state before it is fully terminated. It does not monitor the user's active session for inactivity; rather, it cleans up resources that were left behind after a user disconnected but did not log off.
- ✓
Idle timer.
Why this is correct
The idle timer specifically monitors for mouse and keyboard input. Once the specified duration passes without any user interaction, the session is either disconnected or terminated, providing the necessary security control to protect unattended sessions from unauthorized access by other individuals who might encounter the screen.
- ✗
Auto-client reconnect timer.
Why it's wrong here
This timer manages the behavior of the client device when a network interruption occurs. It allows the system to attempt a reconnection to the session. It does not have any relationship to user activity levels and cannot be used to force a logoff based on session inactivity.
About these practice questions
One of 216 original 1Y0-204 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Citrix exam blueprint
This 1Y0-204 practice question is part of Courseiva's free Citrix certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 1Y0-204 exam.