Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CCIE Security

Domain 4Objective 17

4.17 Access Control and Single Sign-On Using Cisco DUO Security Technology CCIE-SECURITY Practice Questions (Page 4)

Part of the 4.0 Identity Management, Information Exchange, and Access Control domain, which accounts for 25% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 1–1 from this objective — we provide 29 practice questions to prepare you well beyond it. (estimate)

29questions here
6free pages
17concepts
25%of the exam

Questions 16–20

  1. 16expert · hard · select all that apply

    A company is using Duo Single Sign-On to protect a suite of cloud applications. They have configured a new application that supports both SAML 2.0 and OIDC. The identity team wants to leverage the Duo Universal Prompt and also wants to be able to pass a custom attribute (e.g., 'department') to the application for authorization decisions. Which protocol and configuration should they choose?

    Select an answer first
  2. 17expert · hard

    A security administrator is configuring Duo access policies for a highly sensitive application. The policy must require a hardware token for all users. However, the administrator notices that some users are able to authenticate with Duo Push, even though the policy seems to be configured correctly. What is the most likely cause of this issue?

    Select an answer first
  3. 18expert · hard

    An organization is deploying Duo for AnyConnect VPN. They have two ASA firewalls in an active/standby failover pair. They have deployed a single Duo Authentication Proxy. During a test, they shut down the primary ASA, and the standby ASA takes over. However, VPN users are now unable to authenticate with Duo. What is the most likely cause?

    Select an answer first
  4. 19expert · hard

    A security team is reviewing Duo authentication logs and notices a high number of 'denied' authentication attempts for a specific user account. The attempts are coming from a foreign IP address. The user's primary authentication (e.g., AD password) is succeeding, but the Duo MFA is being denied. What is the best immediate action to take?

    Select an answer first
  5. 20expert · hard

    A company is integrating Duo with a legacy VPN concentrator that only supports RADIUS. They have deployed the Duo Authentication Proxy. The VPN concentrator is configured to use the proxy as its RADIUS server. Users are able to authenticate with their primary credentials, but the Duo MFA prompt is not appearing. What is the most likely cause?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.