Courseiva
mediumMultiple ChoiceObjective-mapped

350-701 Practice Question: A company deploys a Cisco ASAv in AWS for VPN…

A company deploys a Cisco ASAv in AWS for VPN termination. They need to enforce multi-factor authentication (MFA) for remote access VPN users. Which Cisco solution integrates with ASAv to provide MFA?

⚠ Common exam trap

It's easy for candidates to confuse Cisco ISE's ability to enforce MFA policies with it being a native MFA provider, when in fact ISE requires an external MFA solution like Duo to actually generate and validate second-factor tokens.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Cisco Duo

Cisco Duo is the correct solution because it is a cloud-based MFA platform that integrates directly with the Cisco ASAv via the AnyConnect VPN client or the ASA's authentication proxy. Duo acts as a RADIUS or LDAP proxy, intercepting authentication requests and prompting users for a second factor (e.g., push notification, OTP) after primary credentials are validated. This provides the required multi-factor authentication for remote access VPN users without requiring additional on-premises infrastructure.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Cisco Duo

    Why this is correct

    Duo integrates with ASAv for MFA via RADIUS or other methods.

  • Cisco Umbrella

    Why it's wrong here

    Umbrella does not provide MFA.

  • Cisco ISE

    Why it's wrong here

    ISE provides authentication but not native MFA; requires additional integration.

  • Cisco Cloudlock

    Why it's wrong here

    Cloudlock is a CASB, not MFA.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1XEAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

One of 978 original 350-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-701 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-701 exam.