A Citrix Administrator needs to ensure that only users connecting from managed corporate devices can access a published desktop. The environment uses Citrix Gateway with SmartAccess. Which Citrix Gateway policy expression should the administrator use to allow access only when the endpoint has a valid corporate certificate?
This Citrix Gateway policy expression evaluates to true if the client presents a client certificate during the SSL handshake. By requiring a valid corporate certificate, the administrator can restrict access to managed devices that have the certificate installed. This is a common SmartAccess method to enforce device identity. The expression is used in a policy that is evaluated after authentication, allowing or denying access based on certificate presence.
Why this answer
The expression CLIENT.SSL.CLIENT_CERT.EXISTS evaluates whether the client presented a certificate during the SSL handshake. By using this in a Citrix Gateway policy, the administrator can ensure that only devices with a valid corporate certificate are granted access. This leverages SmartAccess to enforce device compliance.
The other expressions do not verify certificate presence and thus cannot restrict access to managed devices.
Exam trap
The trap here is confusing client certificate presence with simple header or URL checks, which can be easily spoofed and do not provide true device authentication.