1Y0-312 Advanced Security and Access Control Practice Question
An administrator is implementing SmartAccess policies in a Citrix Virtual Apps and Desktops 7 environment with Citrix Gateway. The requirement is to allow users to access a published application only if they connect through Citrix Gateway and their endpoint has a specific registry key set. The administrator has configured the Gateway and StoreFront. Which Delivery Controller policy filter should be used to enforce this condition?
⚠ Common exam trap
The trap here is assuming that any Gateway-related filter can evaluate endpoint attributes, but only Endpoint Analysis filters provide that capability.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Endpoint Analysis
SmartAccess policies in Citrix Virtual Apps and Desktops can be filtered based on the results of endpoint analysis performed by Citrix Gateway. The Endpoint Analysis filter allows the Delivery Controller to apply policies conditionally when the endpoint meets specific criteria, such as a registry key being present. This enables granular control over access to published applications based on endpoint posture. The administrator must configure the endpoint analysis scan on the Gateway to include the registry check, and then use the Endpoint Analysis filter in the Delivery Controller policy.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Endpoint Analysis
Why this is correct
Endpoint Analysis filters evaluate the results of the endpoint analysis scan performed by Citrix Gateway. These results include registry keys, files, and processes. By configuring the endpoint analysis scan to check for the specific registry key, the administrator can create a Delivery Controller policy that applies only when that key is present. This directly enforces the SmartAccess condition. The policy can then be used to allow or deny access to the published application based on the endpoint's compliance.
- ✗
Access Control
Why it's wrong here
Access Control filters in Citrix policies are used to apply settings based on user or group membership, not endpoint attributes like registry keys. They do not evaluate the presence of a registry key on the endpoint. Thus, they cannot enforce the specified condition. Using Access Control would not meet the requirement of checking endpoint registry state.
- ✗
Citrix Gateway protocol
Why it's wrong here
The Citrix Gateway protocol filter checks whether the connection is made through a Gateway, but it does not evaluate endpoint registry settings. It can be used to differentiate internal versus external connections, but here the requirement also includes a specific registry key condition. This filter alone would not enforce the registry check. Therefore, it is insufficient for the scenario.
- ✗
User or Group
Why it's wrong here
User or Group filters apply policies based on the identity of the user or their group membership. They do not inspect endpoint characteristics such as registry keys. While they are useful for assigning policies to specific users, they cannot enforce the endpoint registry requirement. Therefore, this filter is not appropriate for the scenario.
About these practice questions
Courseiva writes every 1Y0-312 question from scratch — 186 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Citrix exam blueprint
This 1Y0-312 practice question is part of Courseiva's free Citrix certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 1Y0-312 exam.