Courseiva

1Y0-312 · topic practice

Advanced Security and Access Control practice questions

This domain covers securing Citrix Virtual Apps and Desktops 7 access through NetScaler Gateway and StoreFront, plus hardening VDAs and identity integration. Questions present administrator scenarios: reading NetScaler logs, configuring Azure AD as IdP, enforcing endpoint requirements via policies, and selecting VDA hardening settings. Expect feature-selection and troubleshooting items rather than pure recall.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Advanced Security and Access Control

What the exam tests

What to know about Advanced Security and Access Control

Be able to select the right NetScaler, StoreFront, or VDA feature for a stated security requirement and trace authentication from Gateway to published resource. The most important thing: know how single sign-on is preserved end to end and when EPA or FAS is required.

NetScaler Gateway authentication, session policies, and SmartAccess/SmartControl EPA scans

StoreFront authentication flow and Citrix Gateway integration for published app launches

Azure AD as Identity Provider with SAML and Citrix Federated Authentication Service

VDA hardening: disabling unused services, restricting drive redirection, and Windows security baselines

Watch out for

Common Advanced Security and Access Control exam traps

  • ▸Assuming single sign-on works automatically after NetScaler authentication; StoreFront and VDA often need matching authentication or FAS configuration to avoid a second prompt.
  • ▸Confusing endpoint analysis (EPA) scan policies with authorization policies; EPA checks device posture, while authorization decides resource access.
  • ▸Believing VDA hardening is one setting; it requires multiple coordinated changes across services, policies, and registry, not a single toggle.

Practice set

Advanced Security and Access Control questions

20 questions · select your answer, then reveal the explanation

An enterprise environment requires SmartAccess for ICA sessions to restrict client drive mapping based on endpoint posture evaluation via Citrix Gateway. Which specific component must be correctly configured to evaluate EPA check results and translate them into Session Policies for Virtual Apps and Desktops?

A security auditor requires that all external users connecting through Citrix Gateway have their local clipboard disabled, but internal users must retain clipboard functionality. The administrator wants to achieve this using NetScaler SmartControl to minimize the number of Citrix policies. Which TWO steps are required to implement this? (Select TWO)

An administrator needs to ensure that the Delivery Controllers only accept traffic from trusted StoreFront servers. Which PowerShell command should be executed on the Delivery Controller to enable this security feature?

An administrator is configuring App Protection policies to protect against keylogging and screen capturing. Which TWO components must be specifically updated or configured to support this feature? (Select TWO)

An administrator wants to implement session watermarking to deter users from taking photos of sensitive data. Which condition must be met for the watermark to appear in the session?

A company is using StoreFront in a multi-site configuration with two separate Citrix Virtual Apps and Desktops sites. Which THREE security considerations are critical when configuring 'User Mapping' for multi-site aggregation? (Select THREE)

To enhance security, an administrator wants to ensure that all ICA traffic is encrypted using the highest possible level. Which Citrix policy setting should be configured to enforce TLS encryption for the ICA stream between the client and the VDA?

Which TWO requirements must be met to use the Federated Authentication Service (FAS) to provide single sign-on for NetScaler Gateway users? (Select TWO)

During a Delivery Controller database outage, the Local Host Cache (LHC) becomes active. How does the LHC handle user permissions and security during this period?

An administrator is setting up Session Recording and needs to ensure that only authorized security officers can view the recorded sessions. Where is the access control for viewing recordings configured?

Refer to the exhibit. An administrator has applied this policy to restrict clipboard redirection. However, users connecting via Chrome are still experiencing clipboard functionality. What is the most likely cause for this behavior?

Exhibit

ns_policy_map: { "policy_name": "restrict_clipboard", "action": "deny", "expression": "HTTP.REQ.HEADER(\"User-Agent\").CONTAINS(\"Chrome\")" }

An administrator wants to secure the internal Citrix infrastructure. Which THREE actions should the administrator take to implement a 'Zero Trust' approach for Virtual Apps and Desktops? (Choose three.)

An administrator is configuring a Citrix Gateway to support SmartAccess. The administrator needs to ensure that users connecting from a non-company managed device have the 'Print' function disabled in their session. Where should this policy be configured?

Which TWO of the following methods are effective for securing the communication between the VDA and the Delivery Controller? (Choose two.)

An administrator must prevent users from using the 'Save As' function within a virtual application to copy data to a local USB drive. Which Citrix policy should be modified to achieve this requirement?

An organization wants to log all user access activities for auditing purposes. Which Citrix feature provides detailed visibility into the specific resources accessed and the time of access?

Which mechanism ensures that only authorized users can access specific published applications based on their current Active Directory group membership?

An administrator is tasked with ensuring that all internal traffic to the Delivery Controller is encrypted. Which protocol should be enabled on the Delivery Controller to enforce this?

A security audit requires that all virtual desktop sessions are encrypted using TLS, and that internal traffic between VDAs and StoreFront servers remains secure. Which TWO steps must the administrator perform to harden the environment?

Refer to the exhibit. An administrator is configuring a Citrix Gateway for remote access. After applying the configuration shown, remote users report they cannot launch applications, though authentication succeeds. What is the most likely cause of this issue?

Exhibit

add vpn vserver VIP_GATEWAY -httpProfile ns_http_profile_secure
set vpn vserver VIP_GATEWAY -icaProxy ON -authType CERT
set vpn vserver VIP_GATEWAY -dtls ON

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Advanced Security and Access Control sessions

Start a Advanced Security and Access Control only practice session

Every question in these sessions is drawn from the Advanced Security and Access Control domain — nothing else.

Related practice questions

Related 1Y0-312 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the 1Y0-312 exam test about Advanced Security and Access Control?
Be able to select the right NetScaler, StoreFront, or VDA feature for a stated security requirement and trace authentication from Gateway to published resource. The most important thing: know how single sign-on is preserved end to end and when EPA or FAS is required.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Advanced Security and Access Control questions in a focused session?
Yes — the session launcher on this page draws every question from the Advanced Security and Access Control domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other 1Y0-312 topics?
Use the topic links above to move to related areas, or go back to the 1Y0-312 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the 1Y0-312 exam covers. They are not copied from any real exam or dump site.