Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CCIE Security

Domain 4Objective 17

4.17 Access Control and Single Sign-On Using Cisco DUO Security Technology CCIE-SECURITY Practice Questions (Page 3)

Part of the 4.0 Identity Management, Information Exchange, and Access Control domain, which accounts for 25% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 1–1 from this objective — we provide 29 practice questions to prepare you well beyond it. (estimate)

29questions here
6free pages
17concepts
25%of the exam

Questions 11–15

  1. 11foundation · easy

    Which administrative role in Cisco Duo is limited to viewing reports and authentication logs without the ability to modify configurations?

    Select an answer first
  2. 12foundation · easy

    What is the primary purpose of the 'Authentication Log' report in Cisco Duo?

    Select an answer first
  3. 13application · medium

    A company's security team is configuring Duo access policies for a group of remote employees who access a critical application. The policy must require a higher level of assurance when users are accessing from an unmanaged device outside the corporate network, but allow a simpler authentication experience when they are on a trusted corporate device. Which Duo policy configuration best meets this requirement?

    Select an answer first
  4. 14application · medium

    A network administrator wants to protect administrative access to a network switch that supports RADIUS authentication. The switch is in a secure data center and can reach the corporate network. The administrator wants to use Duo MFA for all admin logins. What is the simplest way to achieve this?

    Select an answer first
  5. 15expert · hard

    A large enterprise is deploying Duo to protect multiple RADIUS-based services, including a Cisco ASA VPN and a wireless LAN controller (WLC). They have two data centers (DC1 and DC2) and want to ensure high availability. They plan to deploy two Authentication Proxies in each data center. The VPN concentrator in DC1 is configured with a primary RADIUS server pointing to the proxy in DC1 and a secondary pointing to the proxy in DC2. The WLC in DC1 is configured similarly. What is a critical consideration for this design?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.