SCAZT · domain
User And Device Security
Practise Cisco Designing and Implementing Secure Cloud Access for Users and Endpoints (SCAZT, 300-740, CCNP Security) (SCAZT) User And Device Security practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice User And Device Security questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about User And Device Security
User And Device Security questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common User And Device Security exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All User And Device Security questions (50)
Click any question to see the full explanation, or start a practice session above.
Which TWO of the following are valid Duo authentication methods that do not require an internet-connected mobile device for the user?
Medium2An organization requires that users on iOS devices must have a passcode enabled to access cloud resources. Which Duo feature enforces this?
Hard3Which THREE items are included in a Duo Authentication Log entry?
Hard4A user's device is marked as 'Out-of-Date' in Duo. How does the system determine this status?
Medium5A security engineer is configuring Duo Authentication for Microsoft 365. The organization requires that users must be prompted for MFA only when accessing cloud resources from outside the corporate network. Which configuration setting in the Duo Admin Panel achieves this?
Medium6Which TWO pieces of information are used by the Duo Authentication Proxy to identify which application is sending an auth request?
Medium7When integrating Duo with an application that uses the OIDC protocol, where are the 'Client ID' and 'Client Secret' configured?
Medium8Which THREE settings are part of the 'Authentication Policy' in the Duo Admin Panel?
Hard9An organization wants to restrict access to Salesforce to specific IP addresses. Where should this policy be configured?
Medium10An organization wants to use Duo for both Windows Logon and Cloud SSO. What is the difference in deployment?
Hard11How does Duo protect an application that does not support modern authentication protocols?
Medium12What is the primary benefit of the Duo Universal Prompt compared to the traditional iframe-based prompt?
Easy13A security auditor notices that Duo authentication logs show an 'Authentication Succeeded' status, but the user was denied access to the SaaS application. Which policy setting is the most likely cause?
Hard14During a Duo enrollment phase, a user is required to install the Duo Mobile app. What is the main security purpose of the app in the MFA flow?
Medium15Which THREE actions can be taken by an administrator if a user's mobile device is reported as stolen?
Hard16You are deploying Duo Passwordless authentication. Which factor must be verified on the endpoint before a user can successfully authenticate?
Medium17An administrator wants to audit all Duo administrative actions. Which log provides this information?
Hard18A security engineer is worried about 'MFA fatigue' attacks. Which Duo configuration is the best defense?
Hard19What is the primary function of the 'Duo Network Gateway'?
Medium20Which of the following describes the 'Duo Central' portal?
Easy21Which TWO things must be done to successfully protect a legacy VPN with Duo?
Medium22Which THREE factors can be evaluated by Duo Device Health during an access request?
Hard23Which TWO configuration parameters are required when setting up the Duo Authentication Proxy for an LDAP source?
Medium24When configuring Duo Trust Monitor, what is the primary purpose of 'Baseline' behavior?
Medium25In the context of the Duo Authentication Proxy, what is the 'fail_mode' parameter used for?
Medium26A company wants to prevent users from using personal devices for work. Which Duo policy is most effective for this?
Hard27An organization uses Duo Access Gateway (DAG) to protect on-premises applications. They want to transition to Duo SSO. What is the primary difference in architecture?
Hard28A user is attempting to access a cloud application protected by Duo SSO. The Duo prompt shows 'Access Denied: Your device is not running a supported browser'. Where is this restriction defined?
Medium29What is the purpose of the 'Enrollment Email' sent by Duo?
Easy30Which THREE of the following are components of the Duo 'Trusted Endpoints' solution?
Hard31Which Duo feature allows an administrator to visualize the percentage of users who have successfully registered their mobile devices?
Easy32Which Duo feature helps prevent phishing attacks by requiring the user to tap a button only after a verified authentication request?
Easy33Which TWO pieces of information are required in the Duo Admin Panel to configure a new SAML application integration?
Medium34Which TWO of the following scenarios would lead to an 'Access Denied' message in the Duo Authentication Log?
Medium35A user is prompted for MFA but their phone is dead. Which administrative feature allows for a temporary bypass?
Medium36Which mechanism does Duo use to integrate with non-SAML cloud applications?
Medium37Which of the following is a requirement for using the Duo 'Remembered Devices' feature?
Easy38You are implementing Cisco Duo Device Health for a Windows fleet. Users report that they are blocked from accessing cloud apps despite having valid credentials. The Duo Health app reports a missing OS security patch. Which component is responsible for enforcing this posture check during the authentication flow?
Medium39Which Duo log would be most useful for troubleshooting a failure during the initial push notification delivery?
Medium40You are investigating an authentication failure. The log shows 'Error: User not found in directory'. What does this imply?
Medium41An administrator needs to ensure that only managed devices can access SaaS applications via Cisco Duo. Which configuration step is mandatory in the Duo Admin Panel to ensure the device is recognized as 'Managed'?
Hard42Which THREE factors influence the user experience when using Duo Passwordless?
Hard43Which THREE conditions must be met for a user to be able to use the 'Self-Service Portal' for device enrollment?
Hard44What is the primary function of the Duo 'Telephony Credits'?
Medium45Which TWO of the following are benefits of using the Duo Authentication Proxy for on-premises AD integration?
Medium46A administrator wants to implement 'Strict' device health checks. What happens if a device reports an unknown OS version?
Hard47When syncing users from Active Directory to Duo, what is the role of the 'Duo Authentication Proxy'?
Medium48Which TWO methods can be used to bypass Duo authentication in an emergency?
Medium49Which THREE of the following are supported by the Duo Authentication Proxy?
Hard50A user is traveling and needs to access a cloud application. The user has no cellular service but has Wi-Fi. Which authentication method is best suited for this scenario?
MediumOther domains
All SCAZT exam domains
Frequently asked questions
- What does the User And Device Security domain cover on the SCAZT exam?
- User And Device Security questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 50 User And Device Security questions in the SCAZT question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only User And Device Security questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.