1Y0-312 Advanced Troubleshooting Practice Question
An administrator notices that Session Recording agents are failing to connect to the Session Recording Server. The connection test using PowerShell indicates a certificate handshake failure. Which step should the administrator take to resolve this certificate validation issue?
⚠ Common exam trap
Candidates often assume the issue is related to firewall port configurations rather than inspecting the certificate store and trust chain validity for proper handshake completion.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Verify that the trusted root certification authority certificate is properly installed in the local computer certificate store on both the agent and the server.
Resolving the handshake failure requires ensuring that the Session Recording server certificate contains the correct enhanced key usage and that both machines trust the issuing root certificate authority. Verifying the certificate store avoids communication disruptions during session recording tasks in enterprise environments.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Reconfigure the firewall rules to open TCP port 80 for unencrypted administrative traffic fallback.
Why it's wrong here
Session Recording communications rely heavily on secure channels and do not fallback to unencrypted port 80 traffic for agent communication during handshake failures. Modifying firewall rules for port 80 will not resolve a certificate validation or trust chain issue.
- ✗
Modify the registry on the Session Recording server to disable certificate revocation list checking entirely.
Why it's wrong here
Disabling certificate revocation list checking removes a security control rather than fixing the handshake; the failure stems from the agent's certificate chain not being trusted by the server. It tempts administrators because CRL checking genuinely causes handshake failures when the server cannot reach the distribution point, a scenario where disabling it is the accepted workaround.
- ✓
Verify that the trusted root certification authority certificate is properly installed in the local computer certificate store on both the agent and the server.
Why this is correct
Mutual authentication and secure channel establishment require both the Session Recording agent and server to trust the issuing certificate authority. Missing root or intermediate certificates directly trigger TLS handshake failures during the connection establishment phase.
- ✗
Restart the Citrix Broker Service on all Delivery Controllers to force a refresh of the machine catalog database entries.
Why it's wrong here
Restarting the Broker Service refreshes machine catalog registrations, which has no bearing on the TLS handshake between Session Recording agents and the Session Recording Server. It tempts because Broker restarts resolve many agent registration faults, and would be correct if the PowerShell test showed agents unregistered rather than a certificate validation error.
Visual reference
About these practice questions
This 1Y0-312 question is part of Courseiva's 186-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Citrix exam blueprint
This 1Y0-312 practice question is part of Courseiva's free Citrix certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 1Y0-312 exam.