1Y0-231 · Question #134
A Citrix Administrator wants a select group of users to use clientless access only when connecting through the Citrix Gateway. What can the administrator create to achieve this requirement?
The correct answer is A. A session policy bound to the user group. Option A is correct because session policies in Citrix Gateway define the type of access a user receives (clientless, ICA proxy, full tunnel, etc.). By binding this policy directly to a user group, the administrator ensures only that specific group is restricted to clientless…
Question
A Citrix Administrator wants a select group of users to use clientless access only when connecting through the Citrix Gateway. What can the administrator create to achieve this requirement?
Options
- AA session policy bound to the user group
- BAn authentication policy bound to the load balancing virtual server
- CAn authentication, authorization, and auditing (AAA) virtual server with nFactor authentication
- DA session policy bound to global
How the community answered
(54 responses)- A76% (41)
- B15% (8)
- C2% (1)
- D7% (4)
Explanation
Option A is correct because session policies in Citrix Gateway define the type of access a user receives (clientless, ICA proxy, full tunnel, etc.). By binding this policy directly to a user group, the administrator ensures only that specific group is restricted to clientless access, while other users remain unaffected - this is the purpose-built mechanism for scoping access behavior per group.
Why the distractors fail:
- B - Authentication policies bound to a load balancing virtual server control how users authenticate, not what access method they receive after logging in.
- C - An AAA virtual server with nFactor addresses multi-step or conditional authentication flows; it has no direct role in enforcing clientless-only access.
- D - A session policy bound to global would apply to all users, directly contradicting the requirement to target only a select group.
Memory tip: Think of it as two separate questions - "Who?" (binding target: group vs. global) and "What experience?" (policy type: session policy controls access method). The answer is always match the binding target to the scope - if it's a group, bind to the group.
Topics
Community Discussion
No community discussion yet for this question.