Courseiva

1Y0-312 Advanced Security and Access Control Practice Question

A Citrix Administrator must configure a Citrix Gateway so that when users authenticate, they are required to provide their domain credentials plus a one-time passcode generated by a RADIUS server. The administrator has already configured the RADIUS server as an authentication policy and bound it to the Gateway. However, after testing, users are prompted for credentials twice but are never asked for a passcode. What should the administrator do to resolve this?

⚠ Common exam trap

The trap here is assuming that the RADIUS policy itself needs a special configuration to act as a second factor, when the real issue is duplicate LDAP policies causing repeated credential prompts.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Ensure that only one LDAP authentication policy is bound to the Gateway and that the RADIUS policy is bound after it.

The double credential prompt indicates that more than one LDAP authentication policy is bound to the Gateway. For two-factor authentication with LDAP and RADIUS, only one LDAP policy should be bound for the first factor, followed by the RADIUS policy for the second factor. The binding order ensures the user is prompted for domain credentials first, then the one-time passcode.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Change the authentication policy binding order so that the RADIUS policy is first and the LDAP policy is second.

    Why it's wrong here

    Binding order determines which policy is evaluated first, but having RADIUS first would prompt for the passcode before the domain credentials, which is not the desired flow. The user would still be prompted for both, but in the wrong sequence. This does not resolve the double credential prompt.

  • ✓

    Ensure that only one LDAP authentication policy is bound to the Gateway and that the RADIUS policy is bound after it.

    Why this is correct

    Having multiple LDAP policies bound causes the user to be prompted for credentials more than once. The correct configuration is a single LDAP policy for the first factor and the RADIUS policy for the second factor. The binding order should place LDAP first, then RADIUS, so the user is prompted for domain credentials first, followed by the one-time passcode.

  • ✗

    Modify the RADIUS authentication policy to use the 'pap' authentication type and enable 'second factor'.

    Why it's wrong here

    The 'pap' authentication type is used for Password Authentication Protocol, not for indicating a second factor. There is no 'second factor' checkbox within the RADIUS policy itself; RADIUS is simply one authentication method. The issue is not the authentication type but the binding order and the removal of duplicate LDAP policies.

  • ✗

    Configure the Citrix Gateway to use 'DualAuth' mode in the authentication profile.

    Why it's wrong here

    'DualAuth' is not a valid authentication mode on Citrix Gateway. Authentication is handled through policies bound to the Gateway. There is no such setting, and enabling it would not change the authentication flow. The administrator must instead correct the policy bindings to achieve the desired two-factor authentication.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

Courseiva writes every 1Y0-312 question from scratch — 186 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Citrix exam blueprint

This 1Y0-312 practice question is part of Courseiva's free Citrix certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 1Y0-312 exam.