Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CCIE Security

Domain 4Objective 17

4.17 Access Control and Single Sign-On Using Cisco DUO Security Technology CCIE-SECURITY Practice Questions (Page 5)

Part of the 4.0 Identity Management, Information Exchange, and Access Control domain, which accounts for 25% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 1–1 from this objective — we provide 29 practice questions to prepare you well beyond it. (estimate)

29questions here
6free pages
17concepts
25%of the exam

Questions 21–25

  1. 21expert · hard

    A company is protecting RDP access to a Windows server using Duo. The server is in a DMZ and cannot reach the internet. They have deployed the Duo Authentication Proxy in the DMZ. Users are able to log in with their AD credentials, but the Duo MFA prompt is not appearing. What is the most likely cause?

    Select an answer first
  2. 22application · medium

    An organization is deploying Cisco AnyConnect VPN for remote access and wants to enforce Duo MFA. The VPN concentrator (ASA) only supports RADIUS for external authentication. The security architect needs to integrate Duo with the ASA without changing the existing Active Directory authentication flow. What is the correct deployment architecture?

    Select an answer first
  3. 23application · medium

    A company is adopting Duo Single Sign-On to provide access to a new cloud-based HR application. The application supports SAML 2.0. The identity team wants to ensure users get a consistent and modern authentication experience. Which configuration should be used for the new application in the Duo admin console?

    Select an answer first
  4. 24application · medium

    A company with 5,000 employees is deploying Duo for MFA. They have an on-premises Active Directory environment and want to avoid manually creating user accounts in Duo. They also want to ensure that when an employee is disabled in AD, their Duo access is immediately revoked. Which approach should be taken for user management?

    Select an answer first
  5. 25application · medium

    A system administrator needs to protect SSH access to a fleet of Linux servers. The servers are in a DMZ and cannot directly reach the internet. The company wants to enforce Duo MFA for all SSH logins. What is the most appropriate way to implement this?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.