1Y0-204 · domain
Secure Access
Secure Access on 1Y0-204 covers how external users reach published apps and desktops through Citrix Gateway: authentication policies, multi-factor authentication, ICA file generation, and HDX transport behavior. Questions are scenario-based, asking you to pick the right component or predict the consequence of a specific Gateway configuration, including command output exhibits.
Focused practice
Practice Secure Access questions
Scored sessions drawing only from this domain — pick a length below.
What this domain covers
What to know about Secure Access
Be able to choose the correct Citrix component for external authentication and resource launch, and read Gateway command output to predict its effect. The single most important thing: know that Citrix Gateway handles external authentication, MFA, and ICA file delivery, not StoreFront alone.
Configuring Citrix Gateway authentication policies and nFactor for multi-factor authentication of external users
Identifying which component generates the ICA file downloaded by browser or Workspace app
Requirements for HDX Adaptive Transport (EDT) to work through Citrix Gateway for external users
Interpreting Citrix Gateway configuration commands and predicting their direct operational consequence
Watch out for
Common Secure Access exam traps
- ▸Assuming StoreFront or Delivery Controller generates the ICA file; the Gateway/HDX XML brokering path is what external launches depend on.
- ▸Believing MFA is enabled by default on Citrix Gateway; it requires explicit authentication policy and nFactor configuration.
- ▸Overlooking that EDT needs UDP 443 permitted end-to-end, including firewall and Gateway, or it silently falls back to TCP.
Question index
All Secure Access questions (18)
Click any question to see the full explanation, or start a practice session above.
Which component is responsible for generating the ICA file that is downloaded by the user's browser or Workspace app during the resource launch process?
Easy2Refer to the exhibit. A Citrix Administrator has applied these security settings to a Gateway virtual server. A group of users with older thin clients can no longer connect. What is the most likely reason for this connection failure?
Hard3A Citrix Administrator is troubleshooting a Citrix Gateway deployment where users connecting via the Gateway can authenticate but cannot launch published applications. The administrator notices that the Gateway is configured with a callback URL of https://storefront.corp.example.com/Citrix/StoreAuth/ and the StoreFront server is configured for HTTPS. However, the StoreFront server's certificate is issued by an internal CA that is not trusted by the Gateway. Which action should the administrator take to resolve the issue?
Hard4A Citrix Administrator is deploying Citrix Gateway in a high-availability pair. The administrator wants to ensure that if the primary Gateway fails, the secondary Gateway takes over seamlessly without requiring users to re-authenticate. Which configuration should the administrator implement?
Hard5A Citrix Administrator is configuring a Citrix Gateway in a Citrix Virtual Apps and Desktops 7 environment. The security team requires that all user connections from the internet are encrypted and that the Gateway presents a valid certificate to external users. The administrator has obtained a wildcard certificate for *.company.com from a public CA. Which action should the administrator take to bind the certificate to the Gateway virtual server?
Medium6An administrator is hardening a Citrix environment. Which THREE of the following are recommended security best practices for the Virtual Delivery Agent (VDA)? (Select THREE)
Hard7An administrator wants to optimize the HDX traffic path for users who are physically in the London office but accessing a StoreFront store located in the New York data center. Which feature should be used?
Medium8Which component is responsible for performing the 'secure handshake' and establishing the initial connection when a user initiates a session through Citrix Gateway?
Medium9A Citrix Administrator needs to configure Citrix Gateway to require two-factor authentication only when users connect from outside the corporate network, while internal users authenticate with only their Active Directory credentials. The environment uses Citrix Gateway 13.0 with StoreFront 1912. Which configuration should the administrator implement?
Medium10A Citrix Administrator needs to ensure that users connecting to virtual desktops from outside the corporate network are required to perform multi-factor authentication. Which component should the administrator configure to achieve this requirement?
Medium11Refer to the exhibit. An administrator is reviewing the StoreFront configuration file. What is the purpose of the 'callbackUrl' parameter in this configuration?
Medium12A Citrix Administrator is configuring a Citrix Gateway virtual server to allow external users to access published applications. The administrator wants to enforce that external users must authenticate using their Active Directory credentials before they can access any resources. Which authentication policy should the administrator configure on the Citrix Gateway?
Medium13A Citrix Administrator needs to configure a Citrix Gateway to allow users to access published applications without requiring a full VPN tunnel. The administrator wants to ensure that only specific internal web applications are accessible, and that users cannot access other network resources. Which feature should the administrator configure?
Medium14A Citrix Administrator is configuring a Citrix Gateway to provide secure remote access. The security team requires that users authenticate using two factors: Active Directory credentials and a one-time password from a hardware token. Which authentication policy should the administrator configure on the Gateway?
Medium15Refer to the exhibit. A Citrix Administrator has executed the commands shown to configure a Citrix Gateway. What is a direct consequence of this specific configuration?
Hard16Which TWO requirements must be met to ensure that HDX Adaptive Transport (EDT) functions correctly for external users connecting through Citrix Gateway? (Choose two.)
Medium17A Citrix Administrator is configuring SmartAccess to restrict access to published applications based on the endpoint device's security posture. The environment uses Citrix Gateway and StoreFront. The administrator needs to ensure that only devices with up-to-date antivirus and a specific registry key are allowed access. Which two components must be configured to achieve this? (Choose two.)
Medium18A Citrix Administrator needs to update the SSL certificate on a Citrix Gateway virtual server. After installing the new certificate on the Citrix ADC, what is the next mandatory step to ensure it is used by the Gateway?
MediumOther domains
All 1Y0-204 exam domains
Frequently asked questions
- What does the Secure Access domain cover on the 1Y0-204 exam?
- Be able to choose the correct Citrix component for external authentication and resource launch, and read Gateway command output to predict its effect. The single most important thing: know that Citrix Gateway handles external authentication, MFA, and ICA file delivery, not StoreFront alone.
- How many questions are in this domain?
- This page lists all 18 Secure Access questions in the 1Y0-204 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Secure Access questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.