Courseiva
easyMultiple ChoiceObjective-mapped

350-701 Practice Question: Use Cisco DUO for MFA to protect access to its…

A company wants to use Cisco DUO for MFA to protect access to its Azure AD applications. Which authentication method should be configured for cloud applications?

⚠ Common exam trap

Cisco often tests the misconception that DUO can serve as a primary identity provider for cloud applications, but the trap here is that DUO is strictly a secondary authentication factor and must be layered after the primary IdP (Azure AD) to protect existing cloud applications without breaking the authentication chain.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Secondary authentication via DUO after Azure AD

When integrating Cisco DUO with Azure AD for MFA, the recommended approach is to configure DUO as a secondary authentication provider after Azure AD handles primary authentication. This is achieved by using DUO's Azure AD integration, which acts as a custom control or a conditional access policy that triggers DUO MFA after the user has already authenticated against Azure AD. This ensures that Azure AD remains the identity provider (IdP) for primary authentication, while DUO provides an additional layer of security via a secondary push, phone call, or passcode.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Secondary authentication via DUO after Azure AD

    Why this is correct

    DUO provides MFA as a second factor after Azure AD validates the user identity.

  • DUO for RADIUS authentication

    Why it's wrong here

    RADIUS is for VPN or network device authentication, not cloud applications.

  • DUO as a SAML identity provider

    Why it's wrong here

    Used for on-prem applications that support SAML, not cloud SaaS.

  • Primary authentication via DUO

    Why it's wrong here

    DUO is not designed as a primary IdP for cloud applications.

About these practice questions

This 350-701 question is part of Courseiva's 978-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-701 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-701 exam.