Courseiva
Troubleshooting →mediumMultiple Choice

1Y0-204 Troubleshooting Practice Question

Exhibit

Error: The connection to the resource could not be made. Please try again or contact your administrator. (Reason: SSL Error 61)

Refer to the exhibit. A user attempts to launch a published desktop and receives an SSL Error 61. What is the most likely cause of this issue?

⚠ Common exam trap

Candidates often assume SSL Error 61 relates to expired certificates on the server side, missing that the endpoint client device lacks the Root CA certificate.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The client lacks the Root CA certificate.

SSL Error 61 typically indicates a failure during the SSL handshake process, often due to an untrusted certificate or a mismatch in the certificate chain. By validating the certificate installation and ensuring the root CA is trusted by the client device, the admin resolves the trust gap. This issue is common in deployments where new certificates are rolled out without updating the client certificate store on endpoint devices.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The Delivery Controller is offline.

    Why it's wrong here

    An offline Delivery Controller would trigger a generic connection timeout or an inability to enumerate resources, not an SSL handshake error. SSL errors are specifically related to cryptographic authentication issues between the client and the Citrix Gateway or VDA, rather than the state of the backend brokering services.

  • ✓

    The client lacks the Root CA certificate.

    Why this is correct

    SSL Error 61 is a standard client-side error indicating that the certificate presented by the Citrix Gateway is not trusted. The client device cannot verify the certificate chain because the issuing Root Certificate Authority is not installed in the local trusted store, causing the connection attempt to abort.

  • ✗

    The user is not entitled to the resource.

    Why it's wrong here

    A lack of user entitlement results in an 'Access Denied' message or a failure to display the resource in the Workspace app. It does not trigger SSL protocol errors, as these errors occur at the transport layer before authorization or entitlement checks can even be performed by the broker.

  • ✗

    The VDA is in maintenance mode.

    Why it's wrong here

    When a VDA is in maintenance mode, the broker informs the client that the resource is unavailable for new connections. This results in an informational message explaining the maintenance state, rather than a security-related SSL error. SSL errors are independent of the functional state of the target resource.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

This 1Y0-204 question is part of Courseiva's 216-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Citrix exam blueprint

This 1Y0-204 practice question is part of Courseiva's free Citrix certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 1Y0-204 exam.