Practice SCAZT User And Device Security questions with full explanations on every answer.
Start practicing
User And Device Security — choose a session length
Free · No account required
Click any question to see the full explanation and answer options, or start a focused practice session above.
A user is attempting to access a cloud application protected by Duo SSO. The Duo prompt shows 'Access Denied: Your device is not running a supported browser'. Where is this restriction defined?
2A user's device is marked as 'Out-of-Date' in Duo. How does the system determine this status?
3You are implementing Cisco Duo Device Health for a Windows fleet. Users report that they are blocked from accessing cloud apps despite having valid credentials. The Duo Health app reports a missing OS security patch. Which component is responsible for enforcing this posture check during the authentication flow?
4Which Duo feature allows an administrator to visualize the percentage of users who have successfully registered their mobile devices?
5An administrator needs to ensure that only managed devices can access SaaS applications via Cisco Duo. Which configuration step is mandatory in the Duo Admin Panel to ensure the device is recognized as 'Managed'?
6You are deploying Duo Passwordless authentication. Which factor must be verified on the endpoint before a user can successfully authenticate?
7An organization uses Duo Access Gateway (DAG) to protect on-premises applications. They want to transition to Duo SSO. What is the primary difference in architecture?
8A security engineer is configuring Duo Authentication for Microsoft 365. The organization requires that users must be prompted for MFA only when accessing cloud resources from outside the corporate network. Which configuration setting in the Duo Admin Panel achieves this?
9Which of the following is a requirement for using the Duo 'Remembered Devices' feature?
10What is the primary benefit of the Duo Universal Prompt compared to the traditional iframe-based prompt?
11When configuring Duo Trust Monitor, what is the primary purpose of 'Baseline' behavior?
12During a Duo enrollment phase, a user is required to install the Duo Mobile app. What is the main security purpose of the app in the MFA flow?
13An organization wants to restrict access to Salesforce to specific IP addresses. Where should this policy be configured?
14Which mechanism does Duo use to integrate with non-SAML cloud applications?
15A security auditor notices that Duo authentication logs show an 'Authentication Succeeded' status, but the user was denied access to the SaaS application. Which policy setting is the most likely cause?
16A administrator wants to implement 'Strict' device health checks. What happens if a device reports an unknown OS version?
17Which of the following describes the 'Duo Central' portal?
18When syncing users from Active Directory to Duo, what is the role of the 'Duo Authentication Proxy'?
19Which Duo feature helps prevent phishing attacks by requiring the user to tap a button only after a verified authentication request?
20An administrator wants to audit all Duo administrative actions. Which log provides this information?
21You are investigating an authentication failure. The log shows 'Error: User not found in directory'. What does this imply?
22A user is traveling and needs to access a cloud application. The user has no cellular service but has Wi-Fi. Which authentication method is best suited for this scenario?
23A company wants to prevent users from using personal devices for work. Which Duo policy is most effective for this?
24In the context of the Duo Authentication Proxy, what is the 'fail_mode' parameter used for?
25What is the purpose of the 'Enrollment Email' sent by Duo?
26What is the primary function of the Duo 'Telephony Credits'?
27When integrating Duo with an application that uses the OIDC protocol, where are the 'Client ID' and 'Client Secret' configured?
28An organization requires that users on iOS devices must have a passcode enabled to access cloud resources. Which Duo feature enforces this?
29How does Duo protect an application that does not support modern authentication protocols?
30An organization wants to use Duo for both Windows Logon and Cloud SSO. What is the difference in deployment?
31Which Duo log would be most useful for troubleshooting a failure during the initial push notification delivery?
32A user is prompted for MFA but their phone is dead. Which administrative feature allows for a temporary bypass?
33What is the primary function of the 'Duo Network Gateway'?
34A security engineer is worried about 'MFA fatigue' attacks. Which Duo configuration is the best defense?
35Which TWO of the following are valid Duo authentication methods that do not require an internet-connected mobile device for the user?
36Which TWO pieces of information are required in the Duo Admin Panel to configure a new SAML application integration?
37Which THREE factors can be evaluated by Duo Device Health during an access request?
38Which THREE conditions must be met for a user to be able to use the 'Self-Service Portal' for device enrollment?
39Which THREE actions can be taken by an administrator if a user's mobile device is reported as stolen?
40Which TWO of the following are benefits of using the Duo Authentication Proxy for on-premises AD integration?
41Which TWO methods can be used to bypass Duo authentication in an emergency?
42Which THREE items are included in a Duo Authentication Log entry?
43Which THREE of the following are supported by the Duo Authentication Proxy?
44Which THREE settings are part of the 'Authentication Policy' in the Duo Admin Panel?
45Which TWO configuration parameters are required when setting up the Duo Authentication Proxy for an LDAP source?
46Which TWO things must be done to successfully protect a legacy VPN with Duo?
47Which THREE of the following are components of the Duo 'Trusted Endpoints' solution?
48Which TWO of the following scenarios would lead to an 'Access Denied' message in the Duo Authentication Log?
49Which TWO pieces of information are used by the Duo Authentication Proxy to identify which application is sending an auth request?
50Which THREE factors influence the user experience when using Duo Passwordless?
The User And Device Security domain covers the key concepts tested in this area of the SCAZT exam blueprint published by Cisco. Courseiva provides free domain-focused practice, mock exams, missed-question review, and readiness tracking across all SCAZT domains — no account required.
The Courseiva SCAZT question bank contains 50 questions in the User And Device Security domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the User And Device Security domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included