Courseiva

SCAZT · domain

troubleshooting

Practise Cisco Designing and Implementing Secure Cloud Access for Users and Endpoints (SCAZT, 300-740, CCNP Security) (SCAZT) troubleshooting practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

316 questions68 easy143 medium105 hard

Focused practice

Practice troubleshooting questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about troubleshooting

troubleshooting questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common troubleshooting exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Question index

All troubleshooting questions (316)

Click any question to see the full explanation, or start a practice session above.

1

Which TWO capabilities does Cisco Cloudlock bring to a SaaS environment?

Medium
2

Which THREE items must be configured to successfully implement an Umbrella SIG tunnel?

Medium
3

Which TWO of the following are valid Duo authentication methods that do not require an internet-connected mobile device for the user?

Medium
4

You are configuring a SASE design to secure traffic from a branch office to the cloud. What is the recommended method for routing internet-bound traffic from the branch to the Cisco Umbrella SIG?

Medium
5

In Cisco Secure Cloud Analytics, what is the function of the 'Host Group' configuration?

Medium
6

Which TWO factors are critical when configuring an automated remediation workflow in Cisco Cloudlock to prevent data loss?

Hard
7

Which Cisco Umbrella feature allows you to categorize destinations and apply custom block or allow lists?

Medium
8

In the context of cloud compliance, you are reviewing the Cisco Cloudlock dashboard. Which feature allows you to identify users who are sharing sensitive documents publicly across corporate SaaS applications like Google Workspace or Office 365?

Easy
9

A security engineer is designing a SOAR playbook in Cisco SecureX Orchestration to isolate a compromised virtual machine in AWS. The playbook must query Cisco Secure Endpoint (AMP for Endpoints) for file trajectory data before performing the isolation. Which activity node should be placed first to ensure the endpoint is correctly identified in the cloud environment?

Hard
10

Which TWO methods can Cisco Cloudlock use to notify an administrator of a policy violation?

Medium
11

Which THREE types of data are commonly visualized in a Cisco Secure Cloud Analytics dashboard?

Medium
12

Which THREE features are provided by the Cisco Umbrella 'Intelligent Proxy'?

Hard
13

When designing incident response playbooks, which THREE of the following are considered best practices for maintaining security and operational continuity?

Easy
14

Which feature in Cisco Cloudlock allows administrators to view a dashboard of users who are behaving outside of their normal baseline?

Easy
15

When configuring visibility for SaaS applications in Cloudlock, which TWO of the following tasks are necessary to ensure the solution can inspect and protect the files in the SaaS environment? (Choose two.)

Medium
16

Which THREE pieces of information are displayed in the Umbrella 'Activity Search' report?

Hard
17

Which THREE steps are involved in the standard SecureX orchestration lifecycle for a new workflow?

Hard
18

An organization requires that users on iOS devices must have a passcode enabled to access cloud resources. Which Duo feature enforces this?

Hard
19

When implementing a Zero Trust architecture, what is the 'Principle of Least Privilege' (PoLP) specifically intended to achieve?

Easy
20

Which TWO actions can be taken in the SecureX 'Threat Response' investigation graph to aid in incident analysis?

Medium
21

Which TWO actions can a user take if a file is quarantined by Cisco Cloudlock?

Hard
22

When creating a policy in Cisco Cloudlock, what is the significance of setting a 'Threshold'?

Medium
23

You are integrating a cloud-native security tool with SecureX. Which authentication method is generally preferred for the API integration?

Medium
24

You are deploying Umbrella Virtual Appliances (VAs) in a local Active Directory environment. What is the primary purpose of the VA in this deployment?

Medium
25

Which TWO of the following are required to successfully deploy a SecureX Orchestration workflow that interacts with a Cisco Secure Endpoint API?

Hard
26

You are configuring Cisco SecureX orchestration to automate threat containment. You need to trigger a playbook when a high-severity alert is ingested from Cisco Secure Endpoint. Which component must be defined to map the alert fields to the playbook input variables?

Medium
27

Which THREE items are included in a Duo Authentication Log entry?

Hard
28

What is the primary role of a Cloud Access Security Broker (CASB)?

Easy
29

Which TWO components are essential for a complete Cisco Umbrella deployment on end-user laptops?

Easy
30

A user's device is marked as 'Out-of-Date' in Duo. How does the system determine this status?

Medium
31

Which THREE components are critical for a successful cloud network segmentation strategy?

Medium
32

You need to export compliance data from the Cisco Security Management Appliance (SMA) regarding web traffic policy violations. Which format ensures the most efficient ingestion into a SIEM via the SecureX orchestration workflow?

Hard
33

In a SASE deployment, why is the integration between Cisco ISE and Cisco Secure Access considered a critical design pattern?

Medium
34

Which THREE items are typically included in a SecureX compliance report?

Easy
35

Which TWO settings should be verified if a Cisco Cloudlock API connector to Google Workspace is showing a 'Warning' status?

Medium
36

Which THREE criteria are used by Cisco Secure Access to determine if a connection should be allowed?

Hard
37

You are troubleshooting a workflow where an API call to Cisco Secure Email fails with a 401 error. What is the most likely cause?

Hard
38

Which feature of the Cisco Umbrella SIG is specifically designed to prevent 'Command and Control' (C2) callbacks from infected endpoints?

Medium
39

In an automated threat response scenario, you want to block a malicious domain globally across your environment using Cisco Umbrella. Which API endpoint is utilized by the SecureX orchestrator?

Medium
40

In Cisco SecureX, which dashboard component allows a security analyst to view the real-time status of triggered automated workflows and their execution history?

Easy
41

You want to restrict access to specific cloud apps (e.g., Dropbox). Which Umbrella feature is used?

Medium
42

You are analyzing a 'Domain Blocked' event in Umbrella. The explanation says 'Proxy'. What does this imply?

Hard
43

Which THREE metrics are useful for assessing the security posture of an endpoint in Cisco Secure Endpoint?

Easy
44

You are troubleshooting an Umbrella SIG tunnel connection. The IPsec tunnel is up, but users report timeouts. What is the most likely cause if the tunnel MTU is not adjusted correctly?

Hard
45

When configuring a SIG tunnel in Umbrella, which protocol is typically used to establish the encrypted connection between the branch office firewall and the Umbrella data center?

Easy
46

You are configuring Cisco SecureX threat response to investigate a file hash. You notice that the integration module for Cisco Umbrella is showing a status of 'Partial Success'. What is the most likely cause?

Medium
47

A security engineer is configuring Duo Authentication for Microsoft 365. The organization requires that users must be prompted for MFA only when accessing cloud resources from outside the corporate network. Which configuration setting in the Duo Admin Panel achieves this?

Medium
48

In Cisco Secure Access, you need to configure a Global Policy to block access to specific cloud applications based on risk levels. Where do you define this logic?

Medium
49

Which TWO pieces of information are used by the Duo Authentication Proxy to identify which application is sending an auth request?

Medium
50

What is the primary function of an 'atomic action' in the context of SecureX orchestration?

Easy
51

Which of the following is a key component of a successful 'Identity and Access Management' (IAM) strategy in the cloud?

Easy
52

In a SASE deployment using Cisco SD-WAN and Umbrella, how is traffic steered to the cloud security stack when a branch router loses its direct tunnel connection to the Umbrella SIG headend?

Hard
53

When integrating Duo with an application that uses the OIDC protocol, where are the 'Client ID' and 'Client Secret' configured?

Medium
54

Which TWO identity sources can be integrated with Cisco Duo for user authentication?

Medium
55

You are auditing your Cisco Defense Orchestrator (CDO) environment. Why would a device appear in 'Staging' mode instead of 'Managed'?

Medium
56

In a SOAR playbook, which THREE types of data can be used to enrich an incident within a case?

Hard
57

Which TWO methods can be used to tunnel traffic from a branch office to the Cisco Umbrella SIG?

Hard
58

Which TWO settings should you check if a SecureX integration module shows 'Offline' status?

Hard
59

A user is attempting to upload a file to a SaaS application, but the Cisco Umbrella Intelligent Proxy blocks it. What is the most effective way to troubleshoot the block?

Hard
60

When migrating from an explicit proxy to the Umbrella SIG, what is the primary challenge for legacy applications?

Hard
61

What does the 'Umbrella dashboard' allow you to do regarding DNS security?

Easy
62

You are using a 'Loop' node in a SecureX workflow to process a list of IPs. How do you access the current item within the loop iteration?

Hard
63

Which THREE settings are part of the 'Authentication Policy' in the Duo Admin Panel?

Hard
64

You need to ensure that only corporate-managed devices can access Microsoft 365. Which component should be configured to verify the device's security posture before granting access?

Hard
65

You notice an alert in SecureX indicating 'Identity Correlation Failure'. What is the most common reason for this when integrating Cisco Secure Endpoint and Cisco Identity Services Engine (ISE)?

Hard
66

You are auditing your Cisco Secure Cloud Analytics environment. Which metric is most critical for identifying potential data exfiltration attempts?

Medium
67

Where can you view the overall security posture and threat trends across your organization within the Umbrella dashboard?

Easy
68

An organization wants to restrict access to Salesforce to specific IP addresses. Where should this policy be configured?

Medium
69

An administrator needs to ensure that only managed devices can access sensitive data in Box. Which Cisco solution feature enables this verification?

Hard
70

An organization is using Cisco Duo for MFA and wants to monitor for suspicious administrative activity. Which report type in the Duo dashboard provides the most granular visibility into changes made to global settings by an administrator?

Hard
71

You have a branch office with a static IP. You want to secure it without a local virtual appliance. What is the best method?

Hard
72

A user is experiencing 'SSL Certificate Mismatch' errors. You suspect it is caused by the Umbrella proxy. How do you resolve this permanently?

Hard
73

In Cisco Cloudlock, what is the purpose of an 'Incident'?

Easy
74

When an alert is triggered in Cisco Secure Cloud Analytics, which action is most appropriate to perform first?

Medium
75

An organization wants to use Duo for both Windows Logon and Cloud SSO. What is the difference in deployment?

Hard
76

Which THREE criteria can be used to classify a 'Shadow IT' application in Cisco Umbrella?

Medium
77

Which THREE items are necessary for troubleshooting a failed 'Umbrella AD Connector' sync?

Hard
78

You need to ensure that an orchestration workflow is only triggered during business hours. Which logical component allows you to restrict execution?

Medium
79

What is the primary function of the 'CASB' category in Cisco Umbrella's web policy?

Medium
80

You are analyzing an incident in SecureX. You see an 'Observable' marked in red. What does this indicate?

Hard
81

Which TWO features are part of the Cisco Secure Access suite for remote users?

Medium
82

When defining a 'Decision' node in SecureX orchestration, which THREE types of comparison operators are commonly available?

Hard
83

How does Duo protect an application that does not support modern authentication protocols?

Medium
84

You are configuring a Cisco Cloudlock policy to detect sensitive PII in a Salesforce instance. Which configuration step ensures that the policy specifically triggers when sensitive data is uploaded to a public-facing object?

Medium
85

When deploying a secure remote access solution, how do you handle 'Split Tunneling' safely in a Zero Trust environment?

Hard
86

You are designing a playbook that isolates a host based on its IP. What is the standard practice for handling the dynamic IP address of an endpoint using DHCP?

Hard
87

What is the primary benefit of the Cisco Umbrella 'Global Network' architecture?

Easy
88

You are building a custom integration in SecureX orchestration to fetch identity data from an external IDP. If the IDP uses OAuth2, which field must be secured using the 'Credential' object type?

Hard
89

When investigating a file hash in SecureX Threat Response, which TWO sources can provide intelligence?

Medium
90

When configuring an OAuth policy in Cisco Cloudlock, which TWO actions can be taken against third-party applications granted access to user data?

Hard
91

When setting up a DLP policy for cloud storage, which TWO elements should be defined to ensure accurate classification of sensitive data?

Hard
92

A network architect is deploying Cisco Umbrella SIG to enforce Zero Trust access. Which mechanism provides the initial posture assessment before allowing a user to access a SaaS application via the Secure Web Gateway?

Medium
93

A firm is adopting SASE and needs to secure mobile devices. Which component of the Cisco SASE suite is best suited to protect mobile endpoints?

Medium
94

What is the primary benefit of the Duo Universal Prompt compared to the traditional iframe-based prompt?

Easy
95

You are auditing a Cisco Cloudlock deployment for O365. Which TWO methods can be used to remediate a file that violates a Data Loss Prevention policy?

Medium
96

When integrating Cisco Secure Endpoint with SecureX, which API key type is recommended for long-term integration stability?

Hard
97

Which TWO pieces of information are required for a 'Network Identity' in Umbrella?

Medium
98

What is the benefit of the 'One-Click Investigation' feature in the SecureX browser extension?

Easy
99

You have integrated Cisco Secure Firewall with SecureX. You want to automate the addition of a suspicious IP address to a dynamic object group. Which component in the FMC API architecture is primarily used for this?

Hard
100

Which feature in Cisco Cloudlock allows you to identify if a SaaS user is logging in from an anonymizer or TOR exit node?

Easy
101

A security auditor notices that Duo authentication logs show an 'Authentication Succeeded' status, but the user was denied access to the SaaS application. Which policy setting is the most likely cause?

Hard
102

How do you verify if your cloud-native security posture meets a specific compliance framework like PCI-DSS within the Cisco platform ecosystem?

Medium
103

You notice that some of your users are bypassing the Umbrella SIG by using a personal VPN. What is the most effective way to prevent this with Cisco products?

Hard
104

You are troubleshooting a missing event in Cisco Secure Cloud Analytics (formerly Stealthwatch Cloud). Which configuration should you verify to ensure the cloud gateway is successfully pushing traffic metadata?

Medium
105

You are designing a secure hybrid cloud environment and need to ensure that traffic between the public cloud and private data center is inspected. Which architecture pattern is most effective?

Hard
106

Which TWO methods are natively supported within Cisco SecureX Orchestration for passing data between disparate security tools in a single workflow?

Hard
107

When configuring a SecureX integration for a third-party product, what is the 'Client ID' used for?

Medium
108

Which TWO components are essential for implementing a Zero Trust Network Access (ZTNA) model using Cisco Duo and Secure Access?

Medium
109

When designing a Secure Access Service Edge (SASE) architecture, which principle best describes the shift from traditional hub-and-spoke networking?

Easy
110

During a Duo enrollment phase, a user is required to install the Duo Mobile app. What is the main security purpose of the app in the MFA flow?

Medium
111

Which TWO items can trigger an orchestration workflow in SecureX?

Hard
112

When a threat response workflow completes, what is the best practice for auditing the action?

Medium
113

A user on a corporate laptop is unable to reach a specific SaaS application that is blocked by the Cisco Secure Access SIG. How can you verify the specific rule causing this block?

Hard
114

You have configured a DLP policy in Cisco Cloudlock that flags files shared with external users. You notice files shared with 'Anyone with the link' are not being flagged. What is the most likely configuration error?

Hard
115

Which Cisco product provides the primary telemetry source for endpoint-based threat response?

Easy
116

You are implementing Cisco Secure Access and want to use PAC files for browsers. Where must the PAC file be hosted for automatic proxy configuration?

Hard
117

When evaluating cloud security reference architectures, what is the primary purpose of a 'Cloud Access Security Broker' (CASB)?

Easy
118

You have detected a compromised account in Google Workspace via Cloudlock. Which automated response action can immediately prevent further data exfiltration from this user account?

Medium
119

Which THREE of the following are primary benefits of integrating Cisco products into the SecureX dashboard?

Medium
120

Which THREE actions can be performed by the Cisco Cloudlock UBA engine?

Medium
121

You are configuring an email notification step in a SOAR playbook. You want the email to include the results of a previous 'Search IP' activity. How do you reference the IP address in the email body?

Hard
122

When setting up an automated response workflow in Cisco SecureX, which THREE of the following are valid trigger sources for initiating a playbook?

Medium
123

When integrating Cisco Secure Firewall Management Center (FMC) with SecureX, which protocol is primarily used for the exchange of threat intelligence and orchestration commands?

Easy
124

When designing a SOAR workflow, what is the best practice for handling errors in a network isolation script?

Medium
125

Which feature in Cisco SecureX allows for the visualization of threats across multiple security products, including cloud and on-premises tools?

Easy
126

Which THREE actions can be taken by an administrator if a user's mobile device is reported as stolen?

Hard
127

Which protocol and format are used for the payload when triggering an incoming webhook for a SecureX orchestration workflow?

Medium
128

You are integrating a third-party SIEM with SecureX. If the SIEM does not have a native integration, how can you ingest its alerts into SecureX?

Hard
129

Which capability is provided by the Cisco Umbrella 'Reporting' tab?

Easy
130

You are deploying Duo Passwordless authentication. Which factor must be verified on the endpoint before a user can successfully authenticate?

Medium
131

Which capability of the Cisco Umbrella SIG ensures that sensitive data, such as PII or credit card numbers, does not leave the organization via web traffic?

Medium
132

Which TWO conditions must be met for a user to be effectively managed by the Umbrella Roaming Client?

Easy
133

What is the primary benefit of using 'Parameters' within a SecureX orchestration workflow?

Medium
134

Where do you manage the Umbrella Roaming Client deployment configuration?

Easy
135

When troubleshooting DNS queries in Umbrella, which command is most useful on a local machine to see if it is using the Umbrella resolvers?

Medium
136

Which THREE features are provided by the Cisco Umbrella 'Deployments' menu?

Medium
137

Which Cisco technology should be used to provide visibility and threat detection for traffic traversing between cloud workloads in a VPC?

Medium
138

Which THREE types of traffic are typically protected by a SIG?

Easy
139

An administrator wants to audit all Duo administrative actions. Which log provides this information?

Hard
140

In Cisco Cloudlock, why would you use a 'Custom Regex' pattern in a DLP policy?

Medium
141

A security engineer is worried about 'MFA fatigue' attacks. Which Duo configuration is the best defense?

Hard
142

When designing for high availability in a SASE architecture, which THREE strategies are recommended?

Hard
143

You are setting up cloud network segmentation. In the context of Secure Access, how are groups of resources isolated from each other?

Medium
144

When configuring Cisco Duo for SaaS application access, which THREE conditions can be used in a 'Policy' to restrict access to a sensitive application?

Hard
145

You are integrating Cisco Secure Access with an IdP. What protocol is used to facilitate this authentication?

Medium
146

Which THREE actions can be taken in an Umbrella policy based on content categories?

Medium
147

What is the purpose of 'Internal Networks' in the Umbrella dashboard?

Medium
148

What is the primary function of the 'Duo Network Gateway'?

Medium
149

Which interface in Cisco SecureX allows users to manually trigger an orchestration workflow?

Easy
150

Which of the following describes the 'Duo Central' portal?

Easy
151

Which menu in the SecureX dashboard allows you to manage the API clients for third-party integrations?

Easy
152

Which TWO of the following are primary components of the Cisco SASE security stack?

Medium
153

What is the primary benefit of using 'SAML' (Security Assertion Markup Language) for cloud application authentication?

Medium
154

A user is attempting to access a SaaS application, but the session is blocked by Cisco Cloudlock due to a detected policy violation. Which component is responsible for analyzing the API calls and triggering the remediation?

Medium
155

You are configuring a Cisco Cloudlock policy to detect sensitive data in a Salesforce environment. You need to identify instances where credit card numbers are shared publicly. Which specific policy category should you configure?

Medium
156

Which component of SecureX tracks the history of all executed playbooks, allowing you to debug failed automated responses?

Easy
157

Which TWO things must be done to successfully protect a legacy VPN with Duo?

Medium
158

You are configuring Cisco Umbrella to protect roaming users. Which component must be installed on the endpoint to ensure consistent policy enforcement when the user is off-VPN?

Easy
159

To ensure compliance, you must ensure that all emails containing credit card numbers sent via O365 are encrypted. How is this achieved within the Cloudlock framework?

Medium
160

You need to ensure that an incident response playbook in Cisco SecureX automatically updates a case in the Casebook feature. Which action is required in the workflow design?

Medium
161

Which feature in Cisco Umbrella is used to categorize web traffic for reporting and filtering?

Easy
162

Which component of the Cisco SASE architecture provides the primary security enforcement point for remote users browsing the web from untrusted networks?

Easy
163

You want to monitor the health of your Cisco Secure Firewall Management Center (FMC) from within SecureX. Which integration component is required?

Medium
164

Which THREE factors can be evaluated by Duo Device Health during an access request?

Hard
165

When configuring a Duo authentication policy for a SaaS app, which THREE device health indicators can be required?

Hard
166

Which TWO configuration parameters are required when setting up the Duo Authentication Proxy for an LDAP source?

Medium
167

When configuring a custom dashboard in Cisco SecureX, what is the primary purpose of adding 'Tiles' from the 'Asset' category?

Easy
168

Which Cisco technology provides the 'Visibility' aspect of SecureX, allowing you to see traffic patterns across cloud and hybrid environments?

Easy
169

Which THREE factors influence the risk rating of an application in Cisco Umbrella's App Discovery tool?

Medium
170

Where do you view the aggregate security posture score across all integrated Cisco cloud security products in the SecureX dashboard?

Easy
171

You are creating a custom dashboard in SecureX and need to display data from Cisco Secure Endpoint (AMP for Endpoints). Which component must be properly configured first?

Hard
172

You are troubleshooting a connection issue where a remote user cannot access a private cloud application via the Cisco Secure Access ZTNA connector. Which step is most likely to resolve the issue?

Hard
173

Which TWO features of Cisco Umbrella assist in preventing data loss?

Medium
174

Which component is required to enable Active Directory integration with Umbrella for user-level reporting?

Easy
175

In Cisco Umbrella, what is the primary purpose of defining a 'Cloud Application' in the 'App Discovery' dashboard?

Medium
176

You need to handle a case where an endpoint device is not reachable during an isolation attempt. How should the workflow respond?

Hard
177

Which THREE of the following are primary functions of a Cloud Access Security Broker (CASB) regarding application and data security?

Medium
178

How do you access the 'SecureX' suite from another Cisco security console like FMC?

Easy
179

When deploying the Cisco Secure Access AnyConnect module, what is the primary role of the Umbrella DNS module within it?

Hard
180

An administrator is configuring Cisco Umbrella for a branch office and needs to ensure that all DNS requests are inspected for malicious domains without requiring a client-side agent. Which configuration approach should the administrator implement?

Medium
181

When configuring Duo Trust Monitor, what is the primary purpose of 'Baseline' behavior?

Medium
182

A user is using a managed laptop. How does 'Device Posture' in the Cisco SASE model verify that an antivirus solution is active?

Medium
183

You are troubleshooting a lack of visibility in the SecureX 'Device Trajectory' view for a roaming laptop. The device is connected to the network via AnyConnect, but SecureX is not showing the internal IP history. Which configuration is required to ensure this data is visible?

Medium
184

Which type of file allows you to import and share a complete workflow design between different SecureX organizations?

Easy
185

Which TWO ways does Cisco SecureX simplify the management of security operations?

Medium
186

Which THREE factors influence the performance of a SASE deployment?

Hard
187

An organization is migrating to a Secure Internet Gateway (SIG) architecture. They currently have an on-premises firewall blocking all traffic except for specific ports. What is the recommended method to forward traffic to the SIG while maintaining existing security policy consistency?

Medium
188

Which TWO logging methods can be used to export Umbrella logs for SIEM analysis?

Hard
189

Which section in the Cisco Secure Firewall Management Center (FMC) is primarily used to view security events generated by intrusion policies?

Easy
190

Which TWO ways does Cisco Secure Cloud Analytics provide visibility into encrypted traffic?

Medium
191

In the context of the Duo Authentication Proxy, what is the 'fail_mode' parameter used for?

Medium
192

Which THREE actions can be automated via the Cisco Secure Firewall integration in SecureX?

Hard
193

When configuring a webhook from an external source to trigger a SecureX orchestration workflow, what is the mandatory authentication requirement?

Hard
194

Which component is required to allow Umbrella to perform SSL decryption on web traffic?

Medium
195

When building a custom API integration in SecureX, which TWO authentication protocols are commonly supported for secure access?

Medium
196

Which Cisco product facilitates 'Cloud-to-Cloud' security by monitoring activities in SaaS platforms like Microsoft 365?

Easy
197

When using Umbrella's 'Selective Proxy', how is the determination made to route traffic through the proxy vs. direct to destination?

Medium
198

When designing a cloud security architecture, why is 'logging and observability' so critical?

Medium
199

When designing a SOAR playbook for cloud security incidents, which TWO factors are critical for ensuring successful execution?

Medium
200

Which THREE items are included in a Cisco Cloudlock 'Incident' report?

Hard
201

An organization is deploying Cisco Umbrella SIG to enforce Zero Trust access. You must configure the selective decryption policy. Which setting ensures that specific sensitive traffic, such as financial and healthcare sites, is bypassed for inspection to comply with privacy regulations?

Medium
202

A company wants to prevent users from using personal devices for work. Which Duo policy is most effective for this?

Hard
203

An organization uses Duo Access Gateway (DAG) to protect on-premises applications. They want to transition to Duo SSO. What is the primary difference in architecture?

Hard
204

A global company needs to ensure that users in different regions have the lowest latency when accessing cloud applications. How should the SASE architecture be configured?

Medium
205

You are configuring Cisco Secure Cloud Analytics (formerly Stealthwatch Cloud) to trigger an automated response when a suspicious S3 bucket access pattern is detected. Which integration method is best suited for executing a pre-defined playbook in response to this alert?

Medium
206

When managing a large-scale incident in SecureX, which THREE features assist in collaborative investigation?

Hard
207

A user is attempting to access a cloud application protected by Duo SSO. The Duo prompt shows 'Access Denied: Your device is not running a supported browser'. Where is this restriction defined?

Medium
208

Which TWO methods can be used to identify internal clients in Cisco Umbrella reports?

Hard
209

What is the purpose of the 'Enrollment Email' sent by Duo?

Easy
210

What is the purpose of the 'Casebook' in Cisco SecureX?

Easy
211

You are integrating Cisco Umbrella with your incident response process. When a domain is flagged as malicious, you want to automatically add the domain to a 'Blocked' destination list. Which API or service should the SecureX Orchestration workflow utilize to achieve this?

Medium
212

Which THREE factors are typically considered when evaluating 'Device Posture' in a Zero Trust environment?

Medium
213

What is the primary function of the 'Reporting' section in Cisco Defense Orchestrator?

Easy
214

What is the primary function of the 'Threat Response' module within SecureX?

Easy
215

Which THREE of the following are components of the Duo 'Trusted Endpoints' solution?

Hard
216

What is the primary benefit of deploying a 'Managed' SaaS application configuration in Cisco Umbrella?

Easy
217

When using SecureX Threat Response, you perform a search for a specific IP address. Which sources are queried to build the investigation graph?

Hard
218

When configuring Cisco Umbrella for SaaS, how does SSL inspection impact the visibility of application traffic?

Hard
219

When managing incidents in SecureX, which TWO actions can be performed directly from a Casebook?

Medium
220

You are using SecureX Orchestration. What is the difference between a 'Global' and a 'Local' workflow variable?

Medium
221

Which Duo feature allows an administrator to visualize the percentage of users who have successfully registered their mobile devices?

Easy
222

When integrating Cisco Umbrella with a SaaS application, which TWO methods can be used to ensure secure user authentication?

Medium
223

Which of the following is a key component of the SecureX 'Dashboard' customization?

Easy
224

Why is 'SSL/TLS Inspection' necessary in a SASE architecture?

Medium
225

You are reviewing the SecureX 'Threat Response' module. Which THREE actions can you perform directly from the investigation canvas once you have identified a malicious file hash? (Choose three.)

Easy
226

You need to ensure that an orchestration workflow only runs if a specific threat intelligence score exceeds a threshold. Which node type do you use?

Hard
227

You have a requirement to perform 'File Analysis' on downloads. Which Umbrella product component must be enabled?

Hard
228

Which Cisco technology provides visibility and control over SaaS applications using API-based integration to inspect data at rest?

Easy
229

Which TWO settings must be correctly configured to ensure that Cisco Secure Access provides effective decryption and inspection of HTTPS traffic?

Hard
230

In a Cisco Secure Access environment, you are applying an application-layer policy to restrict access to a specific SaaS application based on the user's geolocation. Which tool is used to define this access control rule?

Hard
231

You are integrating Cisco Umbrella into Cisco SecureX. You have successfully configured the API key and registered the organization. However, no Umbrella events are populating the SecureX dashboard. Which configuration step is the most likely cause of this visibility gap?

Medium
232

Which Duo feature helps prevent phishing attacks by requiring the user to tap a button only after a verified authentication request?

Easy
233

Which TWO pieces of information are required in the Duo Admin Panel to configure a new SAML application integration?

Medium
234

Which THREE types of information are typically displayed in the Cisco Umbrella 'App Discovery' report?

Medium
235

When integrating Cisco Cloudlock with O365, which authentication mechanism is required to allow the CASB to perform administrative actions, such as removing a malicious file share?

Hard
236

Which THREE components are critical to consider when designing a 'cloud security reference architecture'?

Hard
237

Which TWO of the following are primary benefits of Cisco Umbrella DNS-layer security?

Easy
238

Which TWO of the following scenarios would lead to an 'Access Denied' message in the Duo Authentication Log?

Medium
239

You are investigating a security incident and need to correlate logs from Cisco Secure Endpoint and Cisco Umbrella. What is the key piece of information needed to link these two sets of logs in SecureX?

Hard
240

Which capability does the Cisco SecureX 'Response' feature provide to an incident responder when analyzing a file hash detected in the cloud?

Easy
241

You notice an employee is accessing a cloud app that is not approved by IT. Which Umbrella feature allows you to see this activity?

Medium
242

A user is prompted for MFA but their phone is dead. Which administrative feature allows for a temporary bypass?

Medium
243

You are troubleshooting a scenario where users are unable to access a specific internal cloud resource after migrating to Cisco Secure Access. The traffic is being blocked by a default policy. How should you modify the traffic flow to ensure internal traffic stays off the SIG?

Hard
244

Which mechanism does Duo use to integrate with non-SAML cloud applications?

Medium
245

When designing a SOAR playbook, which mechanism ensures that the playbook does not trigger multiple times for the same alert?

Medium
246

You want to ensure that users are warned before visiting a newly registered domain. Which feature in Cisco Umbrella handles this?

Medium
247

Which TWO are common 'secure access design patterns' in a hybrid cloud?

Medium
248

Which of the following is a requirement for using the Duo 'Remembered Devices' feature?

Easy
249

You are implementing Cisco Duo Device Health for a Windows fleet. Users report that they are blocked from accessing cloud apps despite having valid credentials. The Duo Health app reports a missing OS security patch. Which component is responsible for enforcing this posture check during the authentication flow?

Medium
250

Which Duo log would be most useful for troubleshooting a failure during the initial push notification delivery?

Medium
251

You are designing a secure access path for a BYOD device. What is the most effective approach to ensure the device does not compromise the network?

Hard
252

When monitoring compliance in Cisco Defense Orchestrator (CDO), which action should you perform to identify out-of-sync configurations across your Cisco ASA and Firepower Threat Defense devices?

Medium
253

What is the role of a 'Policy' in Cisco Umbrella?

Easy
254

What are TWO primary ways to trigger an orchestration workflow in SecureX?

Medium
255

Which THREE items are considered primary components of the Cisco Umbrella 'Identity' structure when creating security policies?

Medium
256

When designing a Zero Trust architecture using Cisco Secure Access, how does the 'Device Posture' check specifically influence the access decision for a managed laptop?

Hard
257

Which method is the most secure way to authenticate users for Cisco Secure Access?

Medium
258

In Cisco Defense Orchestrator, why would an object show a 'Read Only' status?

Medium
259

You are setting up a secure hybrid cloud environment. How do you implement 'Micro-segmentation' between virtual machines in the same subnet?

Hard
260

If you configure an API-based connector for a new SaaS app in Cisco Cloudlock, when does the initial scan typically begin?

Hard
261

Which TWO aspects of threat response are improved by using SecureX orchestration?

Medium
262

Which THREE mechanisms are commonly used by a CASB to enforce access control to SaaS applications?

Medium
263

What is the primary goal of the 'Cisco SASE' framework?

Easy
264

When performing automated threat hunting, you need to query multiple cloud platforms. Which SecureX feature enables this unified query?

Medium
265

You are investigating an authentication failure. The log shows 'Error: User not found in directory'. What does this imply?

Medium
266

You observe that Cisco Secure Cloud Analytics is not reporting any 'Watchlist' alerts. What is the most likely reason?

Hard
267

Which Cisco Cloudlock policy type should be used to detect when a user logs in from an unusual geographic location?

Medium
268

During the design of a SOAR playbook for cloud incident response, you need to ensure that evidence collection is preserved in a compliant manner. Which action is recommended when integrating with Cisco Secure Endpoint for forensic data collection?

Hard
269

In Cisco Umbrella, which component is used to associate internal IP addresses with Active Directory user identities for granular policy reporting?

Easy
270

Which TWO methods are used to verify compliance against security policies in Cisco Defense Orchestrator?

Hard
271

You are creating a custom report in SecureX for compliance auditing. You need to include data from both Cisco Secure Endpoint and Cisco Secure Firewall. What is the requirement to make this possible?

Hard
272

An administrator needs to ensure that only managed devices can access SaaS applications via Cisco Duo. Which configuration step is mandatory in the Duo Admin Panel to ensure the device is recognized as 'Managed'?

Hard
273

In SecureX orchestration, which object type is used to store sensitive API keys used by workflows?

Medium
274

In Secure Access, how are 'Traffic Forwarding' profiles used?

Medium
275

What is the function of an Umbrella 'Integrations' key?

Easy
276

A user is experiencing 'Access Denied' when trying to access a cloud resource. You are using the SecureX 'Pivot' menu to investigate. What are you looking for in the logs?

Hard
277

Which THREE factors influence the user experience when using Duo Passwordless?

Hard
278

Which THREE components are part of the Cisco SecureX suite?

Easy
279

You are implementing Cisco Secure Access and need to configure a Global Policy that restricts access to unsanctioned SaaS applications based on their risk score. Where should this policy be applied in the Secure Access dashboard?

Hard
280

In the context of SASE, what is the primary role of the 'Global Anycast Network'?

Medium
281

Which THREE conditions must be met for a user to be able to use the 'Self-Service Portal' for device enrollment?

Hard
282

Which report in Cisco Umbrella provides the most direct view of security threats identified in your environment?

Easy
283

What is the primary function of the Duo 'Telephony Credits'?

Medium
284

Which TWO of the following are benefits of using the Duo Authentication Proxy for on-premises AD integration?

Medium
285

Which component in the Cisco SecureX suite allows you to build custom, automated security tasks?

Easy
286

You are setting up visibility for a hybrid-cloud environment using SecureX. Which THREE of the following represent valid data sources that can be integrated to provide comprehensive threat context? (Choose three.)

Hard
287

You need to ensure that all web traffic from a branch office is inspected by the Umbrella SIG. Which configuration step is mandatory on your perimeter router?

Medium
288

When designing an automated threat response for cloud-native applications, why is it critical to include a 'Human-in-the-loop' (HITL) step in the orchestration workflow?

Medium
289

A company wants to prevent users from bypassing security policies by using unauthorized VPNs or proxies. Which feature in Cisco Umbrella should be enabled to mitigate this risk?

Medium
290

Which component of Cisco's secure cloud access architecture is responsible for performing URL filtering and malware scanning on traffic destined for SaaS applications?

Medium
291

A administrator wants to implement 'Strict' device health checks. What happens if a device reports an unknown OS version?

Hard
292

A company is using Cisco Tetration (Secure Workload) for data center visibility. They need to generate a compliance report that shows communication flows between 'PCI-scoped' and 'Non-PCI-scoped' workloads. Which feature should be used to define this boundary?

Medium
293

Which THREE actions are required when configuring a new IPsec tunnel for the Cisco SIG (Secure Internet Gateway)?

Medium
294

When syncing users from Active Directory to Duo, what is the role of the 'Duo Authentication Proxy'?

Medium
295

Which THREE components are required to successfully deploy a webhook-based trigger for SecureX orchestration?

Hard
296

Which TWO methods can be used to bypass Duo authentication in an emergency?

Medium
297

Which THREE of the following are supported by the Duo Authentication Proxy?

Hard
298

Which Cisco Umbrella report provides the most granular visibility into the specific security categories triggered by user traffic?

Easy
299

Which THREE factors should be considered when designing an IaaS security architecture using Cisco Secure Workload (formerly Tetration)?

Hard
300

What are TWO benefits of integrating Cisco Secure Email with SecureX orchestration?

Medium
301

You are utilizing Cisco Umbrella to block access to unsanctioned SaaS apps. You want to allow access to O365 but restrict users to only your corporate tenant. Which feature should you enable?

Hard
302

Which THREE types of information are analyzed by Cisco Secure Workload (Tetration) to enforce micro-segmentation?

Hard
303

Which term describes the unauthorized use of cloud applications by employees within an organization?

Easy
304

A security architect is designing a SASE solution. What is the significance of 'Identity-Based Segmentation' in this design?

Medium
305

When using SecureX to orchestrate response, which action is best suited for blocking a URL globally?

Medium
306

Which THREE data types are commonly supported by the Cisco Cloudlock DLP engine for pattern matching?

Medium
307

What is the main advantage of using a Secure Internet Gateway (SIG) over a traditional on-premises firewall?

Easy
308

A user is traveling and needs to access a cloud application. The user has no cellular service but has Wi-Fi. Which authentication method is best suited for this scenario?

Medium
309

You are seeing 'SSL Inspection Error' in your logs. What is the most likely cause?

Hard
310

Which THREE factors are evaluated by the Umbrella policy engine when processing a DNS request?

Easy
311

When troubleshooting a Cisco Umbrella roaming client visibility issue, what does the 'Diagnostic Tool' verify?

Hard
312

An administrator notices that sensitive data is being shared via Microsoft Teams. Where in the Cloudlock dashboard should they navigate to identify which specific users are sharing the files?

Easy
313

When automating threat response using SecureX, you want to verify if a file hash is malicious using Talos Intelligence. Which tool provides this lookup capability?

Medium
314

You are designing a secure remote access solution for a hybrid cloud environment. Which Cisco technology should you implement to replace a traditional VPN while enforcing Zero Trust principles?

Hard
315

Which THREE types of activities are commonly used in SecureX orchestration playbooks for threat containment?

Hard
316

When implementing a ZTNA solution, which factor is most crucial when defining an 'Application Access Policy'?

Hard

Frequently asked questions

What does the troubleshooting domain cover on the SCAZT exam?
troubleshooting questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 316 troubleshooting questions in the SCAZT question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only troubleshooting questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.