Courseiva
Secure Access →mediumMultiple Select

1Y0-204 Secure Access Practice Question

Which TWO requirements must be met to ensure that HDX Adaptive Transport (EDT) functions correctly for external users connecting through Citrix Gateway? (Choose two.)

⚠ Common exam trap

Candidates frequently overlook the network transport layer requirements, forgetting that EDT requires both DTLS enabled on the Gateway and UDP port 443 explicitly allowed through firewalls.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The Citrix Gateway virtual server must have DTLS enabled.

HDX Adaptive Transport uses the UDP-based EDT protocol to improve performance over high-latency links. For this to work through a Gateway, the Gateway must be configured to support DTLS, and the network must allow UDP traffic on port 443 from the client to the Gateway's virtual server.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The Citrix Gateway virtual server must have DTLS enabled.

    Why this is correct

    DTLS (Datagram Transport Layer Security) provides the necessary encryption for UDP-based traffic like EDT. If DTLS is not enabled on the Citrix Gateway virtual server, the connection will fail to establish over UDP and will automatically fall back to standard TCP, losing the performance benefits of Adaptive Transport.

  • ✗

    UDP port 1494 must be open on the external firewall.

    Why it's wrong here

    While 1494 is the standard port for ICA, EDT through a Gateway is encapsulated within DTLS on port 443. Therefore, the external firewall needs to allow UDP 443. Opening UDP 1494 would not facilitate EDT for external users and would create an unnecessary security hole in the perimeter.

  • ✗

    The StoreFront server must be version 3.0 or earlier.

    Why it's wrong here

    EDT is a newer technology and actually requires more recent versions of StoreFront and the VDA. Version 3.0 is far too old to support Adaptive Transport, as the feature was introduced in much later releases of the Citrix stack to handle modern network challenges and high-latency connections.

  • ✓

    UDP port 443 must be allowed from the client to the Gateway VIP.

    Why this is correct

    Since EDT uses UDP for its transport, the network path between the user's device and the Citrix Gateway must permit UDP traffic on the same port used for SSL (typically 443). If a firewall blocks UDP 443, the session will reliably fall back to TCP 443.

  • ✗

    The VDA must be configured to use only the TCP protocol for ICA traffic.

    Why it's wrong here

    Configuring the VDA to use only TCP would explicitly disable Adaptive Transport, as EDT is inherently a UDP-based protocol. The VDA should be left at the default 'Preferred' setting, which allows it to attempt an EDT connection first before falling back to TCP if UDP is unavailable.

About these practice questions

Courseiva writes every 1Y0-204 question from scratch — 216 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Citrix exam blueprint

This 1Y0-204 practice question is part of Courseiva's free Citrix certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 1Y0-204 exam.