1Y0-312 Advanced Security and Access Control Practice Question
A Citrix Administrator must configure a Citrix Gateway so that when users authenticate, they are required to provide their domain credentials plus a one-time passcode generated by a RADIUS server. The administrator has already configured the RADIUS server as an authentication policy and bound it to the Gateway. However, after testing, users are prompted for credentials twice but are never asked for a passcode. What should the administrator do to resolve this?
⚠ Common exam trap
The trap here is assuming that the RADIUS policy itself needs a special configuration to act as a second factor, when the real issue is duplicate LDAP policies causing repeated credential prompts.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Ensure that only one LDAP authentication policy is bound to the Gateway and that the RADIUS policy is bound after it.
The double credential prompt indicates that more than one LDAP authentication policy is bound to the Gateway. For two-factor authentication with LDAP and RADIUS, only one LDAP policy should be bound for the first factor, followed by the RADIUS policy for the second factor. The binding order ensures the user is prompted for domain credentials first, then the one-time passcode.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Change the authentication policy binding order so that the RADIUS policy is first and the LDAP policy is second.
Why it's wrong here
Binding order determines which policy is evaluated first, but having RADIUS first would prompt for the passcode before the domain credentials, which is not the desired flow. The user would still be prompted for both, but in the wrong sequence. This does not resolve the double credential prompt.
- ✓
Ensure that only one LDAP authentication policy is bound to the Gateway and that the RADIUS policy is bound after it.
Why this is correct
Having multiple LDAP policies bound causes the user to be prompted for credentials more than once. The correct configuration is a single LDAP policy for the first factor and the RADIUS policy for the second factor. The binding order should place LDAP first, then RADIUS, so the user is prompted for domain credentials first, followed by the one-time passcode.
- ✗
Modify the RADIUS authentication policy to use the 'pap' authentication type and enable 'second factor'.
Why it's wrong here
The 'pap' authentication type is used for Password Authentication Protocol, not for indicating a second factor. There is no 'second factor' checkbox within the RADIUS policy itself; RADIUS is simply one authentication method. The issue is not the authentication type but the binding order and the removal of duplicate LDAP policies.
- ✗
Configure the Citrix Gateway to use 'DualAuth' mode in the authentication profile.
Why it's wrong here
'DualAuth' is not a valid authentication mode on Citrix Gateway. Authentication is handled through policies bound to the Gateway. There is no such setting, and enabling it would not change the authentication flow. The administrator must instead correct the policy bindings to achieve the desired two-factor authentication.
Visual reference
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
About these practice questions
Courseiva writes every 1Y0-312 question from scratch — 186 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Citrix exam blueprint
This 1Y0-312 practice question is part of Courseiva's free Citrix certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 1Y0-312 exam.