Courseiva
Secure Access →mediumMultiple Choice

1Y0-204 Secure Access Practice Question

Which component is responsible for performing the 'secure handshake' and establishing the initial connection when a user initiates a session through Citrix Gateway?

⚠ Common exam trap

Candidates often confuse backend components like StoreFront or Delivery Controllers with the security entry point, incorrectly attributing the initial SSL/TLS handshake and external tunnel termination to internal infrastructure rather than the Gateway.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Citrix Gateway

The Citrix Gateway acts as the SSL VPN entry point. When a connection is initiated, the Gateway initiates a TLS/SSL handshake to verify the client's identity and establish an encrypted tunnel. This process is crucial because it ensures that traffic remains private and tamper-proof across public networks. Proper configuration of this handshake is the first line of defense in securing the virtual app environment from external interception.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    StoreFront

    Why it's wrong here

    StoreFront is an internal web-based resource aggregator. While it participates in the session launch process after the authentication is complete, it does not handle the initial secure handshake from the user's device. That responsibility belongs to the Gateway, which serves as the entry point from outside the network.

  • ✓

    Citrix Gateway

    Why this is correct

    Citrix Gateway is specifically designed to terminate SSL/TLS connections from client devices. It performs the secure handshake, validates user credentials, and establishes the encrypted tunnel necessary for secure communication between the endpoint and the internal Citrix infrastructure. This is the primary role of the Gateway in a secure deployment.

  • ✗

    Virtual Delivery Agent (VDA)

    Why it's wrong here

    The VDA is the component that hosts the desktop or application. It is located deep inside the secure network and does not communicate directly with the user's external device. It relies on the Gateway and brokering components to establish the connection before it starts processing the user's session.

  • ✗

    Citrix License Server

    Why it's wrong here

    The License Server is a back-end component that monitors license usage. It plays no role in user connection processes or encryption handshakes. It does not communicate with client devices and is not involved in the network session establishment flow, making it irrelevant to the secure connection process for users.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

One of 216 original 1Y0-204 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Citrix exam blueprint

This 1Y0-204 practice question is part of Courseiva's free Citrix certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 1Y0-204 exam.