1Y0-312 Advanced Security and Access Control Practice Question
A Citrix Administrator is configuring a Citrix Gateway to use Smart Card authentication for external users. The environment uses a two-factor authentication requirement: smart card and Active Directory password. The administrator has configured the Gateway virtual server with a Smart Card authentication policy and an LDAP authentication policy. Users report that they are only prompted for the smart card and not for the LDAP password. What should the administrator do to enforce the two-factor authentication?
⚠ Common exam trap
The trap here is thinking that binding multiple authentication policies to a Gateway virtual server automatically enforces multi-factor authentication, when actually next-factor chaining is required.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the Smart Card authentication policy to use 'Next Factor' and specify the LDAP policy as the next factor.
To enforce two-factor authentication with smart card and LDAP, the administrator must configure the Smart Card authentication policy to include a 'Next Factor' that points to the LDAP policy. This creates a chain where the user first authenticates with the smart card and then is prompted for LDAP credentials. Simply binding both policies does not chain them; the next-factor configuration is essential.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Configure the Smart Card authentication policy to use 'Next Factor' and specify the LDAP policy as the next factor.
Why this is correct
In Citrix ADC, multi-factor authentication is achieved by configuring a 'Next Factor' in the primary authentication policy. The Smart Card policy should be configured with a next factor that points to the LDAP policy. This ensures that after successful smart card authentication, the user is prompted for LDAP credentials, thus enforcing two-factor authentication.
- ✗
Set the LDAP authentication policy to 'Secondary' and bind it to the Gateway virtual server after the Smart Card policy.
Why it's wrong here
While authentication policies can be bound in a sequence, simply setting the LDAP policy to 'Secondary' is not a standard configuration step. Citrix ADC uses authentication policy labels or next-factor authentication to chain policies. The term 'Secondary' is not a valid binding option. The administrator must configure the Smart Card policy to invoke the LDAP policy as a next factor.
- ✗
Enable 'Two-factor Authentication' in the Gateway virtual server settings and select both Smart Card and LDAP from the drop-down list.
Why it's wrong here
There is no single 'Two-factor Authentication' checkbox in the Gateway virtual server settings that allows selecting multiple authentication types. Authentication policies must be individually configured and chained. This option describes a non-existent feature and would not enable two-factor authentication.
- ✗
Bind both the Smart Card and LDAP policies to the Gateway virtual server and set the priority so that LDAP is evaluated first.
Why it's wrong here
Binding multiple authentication policies to a virtual server without chaining them results in only one policy being used, typically the one with the highest priority. Setting LDAP first would prompt for LDAP only, not smart card. To enforce both, the policies must be linked using next-factor authentication, not just bound with priorities.
About these practice questions
Courseiva writes every 1Y0-312 question from scratch — 186 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Citrix exam blueprint
This 1Y0-312 practice question is part of Courseiva's free Citrix certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 1Y0-312 exam.