1Y0-204 Secure Access Practice Question
Exhibit
set ssl vserver Gateway_VS -ssl3 DISABLED set ssl vserver Gateway_VS -tls1 DISABLED set ssl vserver Gateway_VS -tls11 DISABLED set ssl vserver Gateway_VS -tls12 ENABLED bind ssl vserver Gateway_VS -cipherName High_Encryption_Suite
Refer to the exhibit. A Citrix Administrator has applied these security settings to a Gateway virtual server. A group of users with older thin clients can no longer connect. What is the most likely reason for this connection failure?
⚠ Common exam trap
Candidates often assume the issue is a firewall block or a licensing error, overlooking that modern security protocols (TLS 1.2) are incompatible with legacy thin client hardware.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The thin clients are unable to negotiate a connection using TLS 1.2.
By disabling SSL 3.0, TLS 1.0, and TLS 1.1, the administrator has restricted the Gateway to only accept TLS 1.2 connections. Older devices, such as legacy thin clients, often do not support TLS 1.2 or the modern ciphers included in the 'High_Encryption_Suite', leading to a handshake failure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The thin clients do not support the AES-256 encryption standard.
Why it's wrong here
While the cipher suite might include AES-256, the primary point of failure is usually the TLS protocol version itself. Even if a client supports AES, it cannot use it if it cannot first successfully complete a TLS handshake using a protocol version that the server has been configured to accept.
- ✗
The Gateway is now requiring a client-side certificate for authentication.
Why it's wrong here
The provided commands only modify the SSL/TLS protocol versions and the cipher suites; they do not enable client certificate authentication. Enabling client certificates would require a 'set ssl vserver -clientAuth ENABLED' command, which is not present in the exhibit shown to the administrator in this scenario.
- ✓
The thin clients are unable to negotiate a connection using TLS 1.2.
Why this is correct
Legacy hardware and older operating systems often lack the software stack required to support TLS 1.2. Because the administrator has disabled all earlier, less secure versions of the protocol, these older thin clients have no common protocol to use for the handshake, resulting in a total connection failure.
- ✗
The 'High_Encryption_Suite' requires a minimum of 4096-bit RSA keys.
Why it's wrong here
Cipher suites define the encryption algorithms, not the RSA key length of the server certificate. While a 4096-bit key is highly secure, it is a property of the certificate itself, not the cipher suite. Most high-encryption suites work perfectly well with standard 2048-bit RSA keys commonly used today.
About these practice questions
One of 216 original 1Y0-204 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Citrix exam blueprint
This 1Y0-204 practice question is part of Courseiva's free Citrix certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 1Y0-204 exam.