Courseiva

CCNA User And Device Security Questions

50 questions · User And Device Security · All types, answers revealed

1
Multi-Selectmedium

Which TWO of the following are valid Duo authentication methods that do not require an internet-connected mobile device for the user?

Select 2 answers
A.Hardware Token
B.SMS Passcode
C.Duo Mobile TOTP
D.Duo Push
E.Phone Callback
AnswersA, B

Works offline.

Why this answer

Hardware tokens and SMS passcodes (if telephony is available) or bypass codes work without the Duo Mobile app.

2
MCQhard

An organization requires that users on iOS devices must have a passcode enabled to access cloud resources. Which Duo feature enforces this?

A.Active Directory GPO for iOS
B.Duo Mobile Application Policy
C.MDM solution integration
D.Duo Authentication Proxy RADIUS rule
AnswerB

This policy allows enforcing device settings like screen locks for mobile access.

Why this answer

Duo Device Health (or mobile posture checks) can inspect for common mobile security settings, such as screen locks/passcodes.

3
Multi-Selecthard

Which THREE items are included in a Duo Authentication Log entry?

Select 3 answers
A.The user's plain-text password
B.The result of the authentication (Success/Failure)
C.The user's browser history
D.The timestamp of the authentication attempt
E.The username of the authenticated user
AnswersB, D, E

Essential for troubleshooting.

Why this answer

The logs contain the time, the username, and the result (success/failure) of the transaction.

4
MCQmedium

A user's device is marked as 'Out-of-Date' in Duo. How does the system determine this status?

A.By analyzing the user's browser user-agent string
B.By querying the Active Directory server for the last patch date
C.By the Duo Device Health application reporting the OS version to the Duo Cloud
D.By checking the device's public IP address geolocation
AnswerC

The Health application actively reports the version, which the policy evaluates.

Why this answer

The Duo Device Health application collects system information and compares the OS version against the policy defined in the Duo Admin Panel.

5
MCQmedium

A security engineer is configuring Duo Authentication for Microsoft 365. The organization requires that users must be prompted for MFA only when accessing cloud resources from outside the corporate network. Which configuration setting in the Duo Admin Panel achieves this?

A.Enable 'Duo Device Health' on the Microsoft 365 application object
B.Set the global MFA mode to 'Bypass' in the Duo Application settings
C.Apply a 'Remembered Device' setting of 30 days to the entire group
D.Configure a New Authentication Policy with 'Authorized Networks' set to the corporate office IP range
AnswerD

The Authorized Networks feature in Duo policies allows defining specific ranges where MFA can be bypassed.

Why this answer

Duo Network Policies allow for location-based access control, permitting bypass or mandatory MFA based on IP ranges.

6
Multi-Selectmedium

Which TWO pieces of information are used by the Duo Authentication Proxy to identify which application is sending an auth request?

Select 2 answers
A.The user's email address
B.The RADIUS secret
C.The Duo API key of the user
D.The device's MAC address
E.The IP address or port of the incoming request
AnswersB, E

Matches the client to the configuration.

Why this answer

The proxy identifies incoming traffic by the shared secret and the IP address or port of the sending device.

7
MCQmedium

When integrating Duo with an application that uses the OIDC protocol, where are the 'Client ID' and 'Client Secret' configured?

A.In the local workstation registry
B.In the Duo Admin Panel application settings
C.In the user's browser settings
D.In the Duo Authentication Proxy config file
AnswerB

This is where the OIDC parameters are created.

Why this answer

The client ID and secret are generated within the Duo Admin Panel application configuration and provided to the OIDC-compliant application.

8
Multi-Selecthard

Which THREE settings are part of the 'Authentication Policy' in the Duo Admin Panel?

Select 3 answers
A.Hardware token assignment
B.MFA prompt behavior (e.g., auto-push)
C.Authorized networks
D.AD forest trust configuration
E.Remembered devices duration
AnswersB, C, E

Controls user experience during MFA.

Why this answer

Authentication policies control the MFA prompt, remembered device settings, and location-based access.

9
MCQmedium

An organization wants to restrict access to Salesforce to specific IP addresses. Where should this policy be configured?

A.In the global organization settings
B.In the Duo Admin Panel under the Salesforce application policy
C.In the Salesforce administrative console only
D.In the local workstation host file
AnswerB

Policies in the Duo Admin Panel are assigned to specific applications.

Why this answer

Policies are applied per application in the Duo Admin Panel to ensure granular control.

10
MCQhard

An organization wants to use Duo for both Windows Logon and Cloud SSO. What is the difference in deployment?

A.Windows Logon requires an installed agent on the endpoint
B.Cloud SSO requires a local agent
C.Both use the same local agent
D.Both require a RADIUS server
AnswerA

The Windows Logon agent is a mandatory local installation.

Why this answer

Windows Logon requires the Duo Authentication for Windows agent, whereas Cloud SSO uses the Duo cloud IDP.

11
MCQmedium

How does Duo protect an application that does not support modern authentication protocols?

A.By installing a local agent on the cloud application server
B.By using the Authentication Proxy to perform RADIUS/LDAP validation
C.By redirecting the user to a SAML 2.0 gateway
D.By forcing the user to use a VPN
AnswerB

This is the classic way to protect legacy systems.

Why this answer

Duo uses the Authentication Proxy to wrap or intercept traffic (like RADIUS) and force an MFA prompt.

12
MCQeasy

What is the primary benefit of the Duo Universal Prompt compared to the traditional iframe-based prompt?

A.It is a hosted redirect that provides a more secure and consistent experience
B.It supports offline authentication only
C.It removes the need for mobile devices
D.It requires less bandwidth
AnswerA

The redirect ensures the user interacts with a secure, Duo-controlled domain.

Why this answer

The Universal Prompt is a modern, hosted redirect that improves security and provides a consistent interface across all applications.

13
MCQhard

A security auditor notices that Duo authentication logs show an 'Authentication Succeeded' status, but the user was denied access to the SaaS application. Which policy setting is the most likely cause?

A.Device health policy violation detected after MFA
B.Incorrect username provided during MFA
C.Duo Authentication Proxy is down
D.Expired Duo license
AnswerA

Duo permits the MFA request to pass, then checks the health policy before passing the claim to the service provider.

Why this answer

If authentication succeeds but access is denied, the Duo policy likely includes a post-authentication check, such as device health or geo-blocking, that failed.

14
MCQmedium

During a Duo enrollment phase, a user is required to install the Duo Mobile app. What is the main security purpose of the app in the MFA flow?

A.To track the user's location at all times
B.To facilitate encrypted push notifications and act as a secure token
C.To scan the user's local network for unauthorized devices
D.To act as a remote desktop client for cloud apps
AnswerB

The app acts as a verified, trusted device for MFA.

Why this answer

The app provides a secure channel for Push notifications and generates TOTP codes, enabling cryptographically secure identity verification.

15
Multi-Selecthard

Which THREE actions can be taken by an administrator if a user's mobile device is reported as stolen?

Select 3 answers
A.Force re-enrollment for the user
B.Deactivate the specific mobile device in the Duo Admin Panel
C.Wipe the device remotely
D.Block the user account temporarily
E.Disable the user's AD account via the Duo dashboard
AnswersA, B, D

Ensures the user sets up a new, safe device.

Why this answer

Administrators can deactivate the device, force a re-enrollment, or block the user account entirely to prevent unauthorized access.

16
MCQmedium

You are deploying Duo Passwordless authentication. Which factor must be verified on the endpoint before a user can successfully authenticate?

A.The user must be connected to the corporate VPN
B.The endpoint must have a Cisco AnyConnect client installed
C.The endpoint must have the Duo Authentication Proxy installed
D.The endpoint must have an active WebAuthn-compliant platform authenticator
AnswerD

WebAuthn platform authenticators such as Windows Hello or TouchID are mandatory for passwordless.

Why this answer

Duo Passwordless requires WebAuthn-compatible platforms (like macOS TouchID or Windows Hello) to store the cryptographic keys.

17
MCQhard

An administrator wants to audit all Duo administrative actions. Which log provides this information?

A.Authentication Log
B.Telephony Log
C.Trust Monitor Log
D.Administrator Actions Log
AnswerD

This logs all changes to policy, users, and applications by admins.

Why this answer

The 'Administrator Actions' log in the Duo Admin Panel specifically tracks changes made by administrators.

18
MCQhard

A security engineer is worried about 'MFA fatigue' attacks. Which Duo configuration is the best defense?

A.Disabling Duo Push and requiring phone calls only
B.Increasing the MFA timeout to 60 seconds
C.Enabling Duo Push with Number Matching
D.Setting 'Remembered Devices' to 1 year
AnswerC

This requires explicit input from the user.

Why this answer

Number matching requires the user to interact with the login screen, proving they are looking at the actual request.

19
MCQmedium

What is the primary function of the 'Duo Network Gateway'?

A.To act as a firewall for the cloud application
B.To sync local AD groups to the cloud
C.To perform load balancing for the Duo service
D.To provide secure access to on-premises apps without a VPN
AnswerD

It creates a secure tunnel for web-based apps.

Why this answer

The Duo Network Gateway is a remote access solution that allows users to access private, on-premises applications without a VPN.

20
MCQeasy

Which of the following describes the 'Duo Central' portal?

A.A local server component for handling RADIUS
B.A security tool for scanning endpoints
C.A user-facing portal that provides a single point of access to apps
D.A tool for administrators to manage Duo policies
AnswerC

It provides a consistent experience for accessing cloud apps.

Why this answer

Duo Central is a user-facing dashboard that provides a single, secure gateway for users to access their applications.

21
Multi-Selectmedium

Which TWO things must be done to successfully protect a legacy VPN with Duo?

Select 2 answers
A.Join the VPN to the Active Directory domain
B.Configure the VPN to use the Authentication Proxy as its RADIUS server
C.Install the Duo agent on the VPN headend device
D.Define the VPN device as a RADIUS client in the Duo Admin Panel
E.Enable SAML on the VPN device
AnswersB, D

VPN sends auth requests via RADIUS to the proxy.

Why this answer

You need to configure the VPN to point to the Duo Authentication Proxy for RADIUS, and define the proxy as a RADIUS client in the Duo Admin Panel.

22
Multi-Selecthard

Which THREE factors can be evaluated by Duo Device Health during an access request?

Select 3 answers
A.Active Internet connection speed
B.OS version and patch level
C.User's current GPS location
D.Disk Encryption status
E.Antivirus status
AnswersB, D, E

Standard check for managed devices.

Why this answer

Duo Device Health inspects disk encryption, OS updates, and antivirus status as part of its posture assessment.

23
Multi-Selectmedium

Which TWO configuration parameters are required when setting up the Duo Authentication Proxy for an LDAP source?

Select 2 answers
A.The user's personal Duo device ID
B.The LDAP server hostname or IP address
C.The public DNS server address
D.The bind credentials (distinguished name and password)
E.The root password of the Active Directory domain
AnswersB, D

Necessary for connectivity.

Why this answer

To connect to LDAP, the proxy needs the server address and the service account credentials to perform searches.

24
MCQmedium

When configuring Duo Trust Monitor, what is the primary purpose of 'Baseline' behavior?

A.To identify normal authentication patterns for users
B.To enforce MFA for every authentication attempt
C.To synchronize identity sources from LDAP
D.To define the static list of allowed IP addresses
AnswerA

Trust Monitor learns user behavior patterns to flag anomalies.

Why this answer

Trust Monitor establishes a baseline of normal user activity to detect deviations that may indicate an account compromise.

25
MCQmedium

In the context of the Duo Authentication Proxy, what is the 'fail_mode' parameter used for?

A.To decide whether to permit local password caching
B.To set the timeout for LDAP queries
C.To define how to handle requests when the cloud service is unreachable
D.To enable logging for failed authentication attempts
AnswerC

Safe mode allows access; closed mode denies it.

Why this answer

The 'fail_mode' (safe or closed) determines whether the proxy allows or denies access when it cannot communicate with the Duo cloud.

26
MCQhard

A company wants to prevent users from using personal devices for work. Which Duo policy is most effective for this?

A.Browser version policy
B.Geographic location policy
C.MFA prompt frequency policy
D.Trusted Endpoints policy with certificate requirement
AnswerD

Certificates act as a unique identifier for managed devices.

Why this answer

By enforcing 'Trusted Endpoints' and requiring a device certificate, only IT-provisioned and managed devices will be permitted.

27
MCQhard

An organization uses Duo Access Gateway (DAG) to protect on-premises applications. They want to transition to Duo SSO. What is the primary difference in architecture?

A.Duo SSO eliminates the need for on-premises server infrastructure for the identity provider
B.Duo SSO supports only SAML 1.0 protocols
C.Duo SSO requires a dedicated hardware appliance
D.Duo SSO requires the installation of the Duo Authentication Proxy on a local server
AnswerA

Duo SSO moves the IDP function to the cloud.

Why this answer

Duo SSO is a cloud-native IDP, whereas DAG acts as a local proxy requiring on-premises server infrastructure.

28
MCQmedium

A user is attempting to access a cloud application protected by Duo SSO. The Duo prompt shows 'Access Denied: Your device is not running a supported browser'. Where is this restriction defined?

A.In the Active Directory GPO for the user
B.In the Duo Authentication Proxy configuration file
C.In the Duo Application configuration under 'Browser Restrictions'
D.In the local browser settings of the client machine
AnswerC

Duo policies allow administrators to restrict access based on browser versions and types.

Why this answer

Browser restrictions are defined within the Duo Policy applied to the specific application or user group.

29
MCQeasy

What is the purpose of the 'Enrollment Email' sent by Duo?

A.To notify the user of a security breach
B.To allow the user to register their authentication device
C.To provide instructions on how to use VPN
D.To reset the user's domain password
AnswerB

This simplifies the onboarding process.

Why this answer

The enrollment email allows users to self-register their devices, reducing the burden on IT support teams.

30
Multi-Selecthard

Which THREE of the following are components of the Duo 'Trusted Endpoints' solution?

Select 3 answers
A.An MDM/UEM solution for device management
B.Duo policy configured to require trusted endpoints
C.Local firewall on the endpoint
D.Device certificate on the endpoint
E.Active Directory domain controller
AnswersA, B, D

Provides the management state.

Why this answer

Trusted endpoints rely on device certificates, an management platform (like MDM), and the Duo policy to verify device identity.

31
MCQeasy

Which Duo feature allows an administrator to visualize the percentage of users who have successfully registered their mobile devices?

A.Duo Authentication Log
B.Duo Dashboard
C.Duo Policy Editor
D.Duo Trust Monitor
AnswerB

The dashboard displays high-level enrollment statistics.

Why this answer

The Duo Admin Panel Dashboard provides analytics and reporting on enrollment progress.

32
MCQeasy

Which Duo feature helps prevent phishing attacks by requiring the user to tap a button only after a verified authentication request?

A.Duo Phone Callback
B.Duo Push with number matching
C.Duo Hardware Tokens
D.Duo Passwordless
AnswerB

The user must enter a number displayed on the login screen into the Duo Mobile app.

Why this answer

Duo Push with number matching ensures the user is actively responding to the specific login event, preventing 'MFA fatigue' and accidental approvals.

33
Multi-Selectmedium

Which TWO pieces of information are required in the Duo Admin Panel to configure a new SAML application integration?

Select 2 answers
A.The Assertion Consumer Service (ACS) URL
B.The local RADIUS shared secret
C.The application's Entity ID
D.The server's public IP address
E.The user's Active Directory password
AnswersA, C

Required for SAML assertion delivery.

Why this answer

To link a SAML app, you need the Metadata file from the app or the manual entry of the Entity ID and Assertion Consumer Service (ACS) URL.

34
Multi-Selectmedium

Which TWO of the following scenarios would lead to an 'Access Denied' message in the Duo Authentication Log?

Select 2 answers
A.The user has not enrolled a device yet
B.The user denied the push notification on their phone
C.The user forgot their password
D.The user's device did not meet the mandatory OS version policy
E.The Duo service is temporarily down
AnswersB, D

Result is access denied.

Why this answer

An access denied message can be triggered by a policy failure (like geo-blocking) or a user explicitly canceling the push request.

35
MCQmedium

A user is prompted for MFA but their phone is dead. Which administrative feature allows for a temporary bypass?

A.Issue a temporary bypass code in the Duo Admin Panel
B.Disable the user's account in Active Directory
C.Enable the 'Remembered Device' setting
D.Reset the user's password
AnswerA

This allows the user to bypass the prompt for a limited time/count.

Why this answer

Administrators can issue a temporary 'bypass code' that is valid for a single use or a set duration.

36
MCQmedium

Which mechanism does Duo use to integrate with non-SAML cloud applications?

A.Duo API Gateway
B.Duo Universal Prompt
C.Duo Authentication Proxy for RADIUS/LDAP
D.Direct integration via browser extension
AnswerC

The proxy allows legacy protocols to be protected by Duo MFA.

Why this answer

For applications that do not support SAML/OIDC, Duo uses the Authentication Proxy to bridge RADIUS or LDAP requests to the Duo cloud.

37
MCQeasy

Which of the following is a requirement for using the Duo 'Remembered Devices' feature?

A.The user must be on the corporate network
B.The user must have a registered hardware token
C.The endpoint must be joined to a domain
D.The user's browser must accept cookies from the Duo domain
AnswerD

The session persistence relies on browser cookies.

Why this answer

Remembered Devices works by setting a cookie in the user's browser, which requires the browser to accept cookies from the Duo domain.

38
MCQmedium

You are implementing Cisco Duo Device Health for a Windows fleet. Users report that they are blocked from accessing cloud apps despite having valid credentials. The Duo Health app reports a missing OS security patch. Which component is responsible for enforcing this posture check during the authentication flow?

A.Microsoft Conditional Access Policy
B.Duo Access Policy
C.Duo Authentication Proxy
D.Duo Device Health Application
AnswerB

Policies configured in the Duo Admin Panel enforce the specific requirement for OS security patches.

Why this answer

The Duo Central/Duo Access Gateway (DAG) or Duo SSO evaluate the health status passed by the Duo Device Health application before granting access.

39
MCQmedium

Which Duo log would be most useful for troubleshooting a failure during the initial push notification delivery?

A.Directory Sync Log
B.Telephony Log
C.Administrative Actions Log
D.Authentication Log
AnswerD

This provides transaction-level detail, including MFA method success/failure.

Why this answer

The Authentication Log provides a detailed breakdown of each step in the MFA process, including push delivery status.

40
MCQmedium

You are investigating an authentication failure. The log shows 'Error: User not found in directory'. What does this imply?

A.The user is not present in the Active Directory group synced to Duo
B.The Duo Authentication Proxy cannot reach the AD server
C.The user's password is expired in AD
D.The Duo service is experiencing an outage
AnswerA

The lookup fails because the user is missing in the synced directory object.

Why this answer

This error occurs when the Duo cloud service attempts to check a user's status against the synced directory, but the user does not exist or was not successfully synced.

41
MCQhard

An administrator needs to ensure that only managed devices can access SaaS applications via Cisco Duo. Which configuration step is mandatory in the Duo Admin Panel to ensure the device is recognized as 'Managed'?

A.Configure the Duo Authentication Proxy for RADIUS bypass
B.Enable 'Trusted Endpoints' in the Duo Admin panel without certificate deployment
C.Enable 'Require Device Health' in the application policy and ensure the Duo Device Health application is installed
D.Assign a static IP address to every endpoint
AnswerC

This combination ensures the endpoint reports its health data and identity to the Duo cloud.

Why this answer

To identify a device as managed, the administrator must deploy the Duo Device Health application and ensure the device certificate is present.

42
Multi-Selecthard

Which THREE factors influence the user experience when using Duo Passwordless?

Select 3 answers
A.The browser or platform's support for WebAuthn
B.The presence of a platform authenticator (e.g., Windows Hello)
C.The user's active directory password strength
D.The Duo Policy settings for the application
E.The user's network speed
AnswersA, B, D

Essential for the protocol.

Why this answer

Duo Passwordless experience is shaped by the platform authenticator, the configured policy, and the application's support for WebAuthn.

43
Multi-Selecthard

Which THREE conditions must be met for a user to be able to use the 'Self-Service Portal' for device enrollment?

Select 3 answers
A.Self-enrollment must be enabled in the global settings
B.The user must be in a synced directory group
C.The Duo Authentication Proxy must be in 'Bypass' mode
D.The device must be joined to the domain
E.The user must have an active email address
AnswersA, B, E

This is the policy trigger.

Why this answer

Self-service enrollment requires directory integration, an accessible URL, and an enabled policy.

44
MCQmedium

What is the primary function of the Duo 'Telephony Credits'?

A.To unlock premium reporting features
B.To provide hardware tokens to employees
C.To cover the costs of SMS and voice call authentication
D.To pay for the monthly Duo license fee
AnswerC

These methods consume telephony credits.

Why this answer

Telephony credits are used specifically for SMS and voice-call-based MFA, as these incur costs from telecommunication providers.

45
Multi-Selectmedium

Which TWO of the following are benefits of using the Duo Authentication Proxy for on-premises AD integration?

Select 2 answers
A.Local storage of user credentials
B.Provides an offline authentication database
C.Secure transport of authentication requests to Duo Cloud
D.Automated synchronization of AD users and groups to Duo
E.Direct replacement of the Active Directory domain controller
AnswersC, D

The proxy encrypts all traffic to the cloud.

Why this answer

The proxy handles directory syncing and provides a secure, encrypted tunnel to the Duo cloud.

46
MCQhard

A administrator wants to implement 'Strict' device health checks. What happens if a device reports an unknown OS version?

A.The user is redirected to a temporary guest portal
B.The user is prompted to upgrade the OS manually
C.The user is granted read-only access
D.The access attempt is blocked by the policy
AnswerD

Strict policies enforce a 'deny' if the device does not explicitly meet health requirements.

Why this answer

Under a 'Strict' policy, if the device health app cannot confirm a supported, patched OS, the access request is denied.

47
MCQmedium

When syncing users from Active Directory to Duo, what is the role of the 'Duo Authentication Proxy'?

A.To facilitate directory synchronization between AD and Duo
B.To enforce hardware-based encryption on AD servers
C.To store user passwords locally
D.To serve as the primary identity provider for the cloud
AnswerA

The proxy is used to sync directory objects to the cloud.

Why this answer

The proxy acts as the bridge that performs LDAP/AD queries and pushes user objects to the Duo cloud.

48
Multi-Selectmedium

Which TWO methods can be used to bypass Duo authentication in an emergency?

Select 2 answers
A.Rename the user's AD account
B.Reset the user's password to '12345'
C.Add the user to a group that has a 'Bypass' policy applied
D.Set the global MFA mode to 'Bypass' for all users
E.Issue a temporary bypass code to the user
AnswersC, E

Effective method for temporary emergency access.

Why this answer

Temporary bypass codes and a 'Bypass' policy setting for a specific user group are the standard emergency options.

49
Multi-Selecthard

Which THREE of the following are supported by the Duo Authentication Proxy?

Select 3 answers
A.Windows Logon authentication
B.Direct SAML 2.0 Identity Provider hosting
C.LDAP authentication
D.SQL database direct authentication
E.RADIUS authentication
AnswersA, C, E

Supported via specific agent/proxy workflows.

Why this answer

The proxy supports RADIUS, LDAP, and generic HTTP-based integrations for authentication.

50
MCQmedium

A user is traveling and needs to access a cloud application. The user has no cellular service but has Wi-Fi. Which authentication method is best suited for this scenario?

A.Duo Mobile generated passcode (TOTP)
B.Duo Push
C.SMS Passcode
D.Duo Phone Callback
AnswerA

TOTP codes work offline on the device.

Why this answer

Duo Mobile can generate TOTP (Time-based One-Time Password) codes offline, which can be entered into the prompt.

Ready to test yourself?

Try a timed practice session using only User And Device Security questions.