Courseiva

1Y0-312 Advanced Security and Access Control Practice Question

A Citrix Administrator is configuring a Citrix Gateway to authenticate users with RADIUS two-factor authentication. The administrator wants to ensure that users are prompted for their RADIUS credentials only after successful Active Directory authentication. Which authentication policy configuration should the administrator use?

⚠ Common exam trap

The trap here is assuming that a single RADIUS policy can perform both AD and RADIUS authentication sequentially, when actually separate policies are needed.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an LDAP authentication policy followed by a RADIUS authentication policy, and bind both to the Gateway vServer.

To prompt for RADIUS credentials only after successful Active Directory authentication, the administrator should bind an LDAP authentication policy first, followed by a RADIUS policy. The Gateway evaluates policies in order, so this sequence ensures AD authentication via LDAP, then RADIUS two-factor authentication. Other options do not enforce the correct order or use inappropriate authentication methods.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure a single RADIUS authentication policy with the 'Enable two-factor authentication' option.

    Why it's wrong here

    A single RADIUS policy with two-factor authentication enabled would prompt for RADIUS credentials as the primary authentication method, not after Active Directory authentication. This does not meet the requirement to have AD authentication first. Two-factor authentication typically combines something you know and something you have, but the sequence here is incorrect. Thus, this configuration is not suitable.

  • ✗

    Configure a Certificate authentication policy and enable 'RADIUS fallback'.

    Why it's wrong here

    Certificate authentication with RADIUS fallback would first attempt certificate authentication, and only if that fails, fall back to RADIUS. This does not ensure that AD authentication occurs before RADIUS. The requirement is for AD authentication first, then RADIUS. Certificate authentication is unrelated to AD credentials and would not provide the desired sequence.

  • ✗

    Use a SAML authentication policy with RADIUS as the identity provider.

    Why it's wrong here

    SAML authentication with RADIUS as the IdP would delegate authentication to an external SAML provider, not directly prompt for RADIUS after AD authentication. This does not guarantee the sequence of AD then RADIUS. SAML is typically used for federated authentication, not for chaining AD and RADIUS in this manner. Therefore, this option does not meet the requirement.

  • ✓

    Create an LDAP authentication policy followed by a RADIUS authentication policy, and bind both to the Gateway vServer.

    Why this is correct

    Binding an LDAP policy first and a RADIUS policy second ensures that users authenticate against Active Directory via LDAP, and then are prompted for RADIUS credentials. This achieves the desired sequence of AD authentication followed by two-factor authentication. The Gateway processes policies in order, so this configuration correctly enforces the requirement.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

One of 186 original 1Y0-312 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Citrix exam blueprint

This 1Y0-312 practice question is part of Courseiva's free Citrix certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 1Y0-312 exam.