1Y0-204 · domain
Security
The Security domain of 1Y0-204 covers authentication, authorization, and auditing in Citrix Virtual Apps and Desktops 7. Expect exhibit-based items on Citrix Gateway, Kerberos constrained delegation, SmartAccess policies, StoreFront, and Delivery Controller configuration, plus questions on logging administrative actions and restricting resource access by user, device, or location.
Focused practice
Practice Security questions
Scored sessions drawing only from this domain — pick a length below.
What this domain covers
What to know about Security
Be able to configure and troubleshoot Citrix Gateway authentication, Kerberos constrained delegation, SmartAccess filtering, and Configuration Logging. The single most important thing is knowing which layer enforces each control and how to verify it with the right console, command, or log.
Configuring Kerberos constrained delegation for Citrix Gateway and StoreFront authentication
Using SmartAccess and Citrix ADC policies to filter access by location and device
Enabling and reading Configuration Logging to a central SQL database
Applying Delivery Controller, Studio, and PowerShell security settings and delegated administration
Watch out for
Common Security exam traps
- ▸Confusing SmartAccess endpoint analysis with StoreFront access control, or applying filters at the wrong layer so restrictions never trigger.
- ▸Forgetting that Kerberos constrained delegation requires correct SPNs and protocol transition, causing resource launch failures.
- ▸Assuming Configuration Logging is on by default, or missing that it records administrative changes rather than user session activity.
Question index
All Security questions (20)
Click any question to see the full explanation, or start a practice session above.
A Citrix Administrator needs to ensure that only users connecting from managed corporate devices can access a published desktop. The environment uses Citrix Gateway with SmartAccess. Which Citrix Gateway policy expression should the administrator use to allow access only when the endpoint has a valid corporate certificate?
Medium2A Citrix Administrator is asked to reduce the risk of credential theft in a Virtual Apps and Desktops 7 environment. The security team wants to prevent users' domain credentials from being stored or cached on VDAs in a way that would allow lateral movement if a VDA were compromised. Which Citrix feature should the administrator implement to meet this goal?
Medium3A security team has requested that all administrative access to the Citrix environment be logged to a central, tamper-proof repository. Which Citrix feature provides this capability?
Hard4An administrator needs to ensure that users connecting from public networks are restricted from accessing local drives on their endpoints during a Citrix Virtual Apps and Desktops session. Which policy setting should the administrator configure to achieve this requirement?
Medium5A Citrix Administrator is configuring Citrix Gateway to provide external access to published desktops. The security policy requires that after a user authenticates, the Gateway must evaluate the endpoint's posture, such as whether antivirus is running and up to date, before granting access to the desktop. Which Citrix Gateway feature should the administrator configure to meet this requirement?
Hard6A Citrix Administrator is reviewing the security posture of a Citrix Virtual Apps and Desktops 7 site. The security team wants to reduce the risk of privileged credential theft from the Delivery Controllers. Which TWO measures should the administrator implement to harden the Controllers? (Choose two.)
Medium7A Citrix Administrator is deploying a new Delivery Controller and wants to ensure that only authorized administrators can make changes to the site configuration. Which built-in role should the administrator assign to a help desk operator who needs to view the site configuration but must not be able to modify it?
Easy8An administrator is hardening a Citrix environment. Which TWO actions should the administrator perform to secure the communication between the Citrix Gateway and the internal StoreFront server? (Choose two.)
Medium9A Citrix Administrator is configuring a Citrix Gateway to provide secure remote access. The security team requires that all authentication to the Gateway be multifactor and that the Gateway itself be protected against common web attacks. Which TWO configurations should the administrator implement to meet these requirements? (Choose two.)
Medium10A security audit reveals that VDA machines are susceptible to local privilege escalation. Which Citrix policy should the administrator configure to prevent users from running unauthorized applications on the VDA?
Hard11An administrator needs to ensure that all user data saved on the VDA is encrypted at rest. Which solution is most appropriate?
Medium12A Citrix Administrator is configuring a new Delivery Group for a set of published applications. Security policy requires that users must not be able to copy or paste data between published applications and their local endpoint devices. Which setting should the administrator configure to enforce this requirement?
Medium13An administrator is tasked with securing the internal communication between Delivery Controllers and VDAs. Which protocol should be used for this connection to satisfy security requirements?
Medium14A Citrix Administrator has configured a Citrix Gateway to provide external access to published applications. The security team wants to ensure that users authenticating from outside the corporate network must provide two different authentication factors before they can reach StoreFront. Which Citrix Gateway configuration should the administrator implement?
Easy15A Citrix Administrator is configuring a new Citrix Gateway deployment to provide secure remote access. The security team requires that all user authentication occur against Active Directory and that users be prompted for their credentials only once. Which Citrix Gateway authentication policy should the administrator configure?
Easy16An administrator needs to restrict access to a sensitive desktop application based on the user's location. Which feature should be used?
Medium17Refer to the exhibit. A user receives this error when attempting to launch a resource via Citrix Gateway using Kerberos constrained delegation. What is the most likely cause?
Hard18A Citrix Administrator is configuring a StoreFront server to authenticate users. The security team requires that users authenticate using smart cards and that the smart card PIN is not cached. Which StoreFront authentication method should the administrator configure?
Medium19Refer to the exhibit. An administrator runs the provided command on a Delivery Controller. What is the security implication of this setting?
Medium20An administrator wants to ensure that end-user sessions are automatically terminated after 30 minutes of inactivity. Which policy should be configured?
MediumOther domains
All 1Y0-204 exam domains
Frequently asked questions
- What does the Security domain cover on the 1Y0-204 exam?
- Be able to configure and troubleshoot Citrix Gateway authentication, Kerberos constrained delegation, SmartAccess filtering, and Configuration Logging. The single most important thing is knowing which layer enforces each control and how to verify it with the right console, command, or log.
- How many questions are in this domain?
- This page lists all 20 Security questions in the 1Y0-204 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Security questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.