I don't see how that solves anything. If the guard knows the answer, then you assume the enemy knows the answer. So all "throwing it away" does, is allow the enemy to cross the border once and the spy stranded!
The idea is that X is the credential, and Y is a sort of digital signature of X.
So the spy knows X, and the border guard has a record of Y. When the spy wants to cross the border, he tells the guard X, and the guard can check that the credential is legitimate by seeing whether it matches the signature Y.
It's public / private key encryption, or one way hashing.