▸case-18 Security operations wants to ingest real-time authentication events and policy decisions from Duo into Splunk. What logs should be forwarded from the Duo Admin Panel to the SIEM, and what specific suspicious authentication patterns should be alerted on? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-08 When installing Duo Authentication for Windows Logon on domain controllers and jump hosts, database service accounts and scheduled task accounts are failing interactive logins or service startups. How should Duo Windows Logon be configured to handle service accounts without breaking automated tasks? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-05 When deploying Duo Verified Push to prevent push exhaustion attacks, what specific prompt interaction does the user perform in the Duo Mobile app to complete authentication? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-15 When integrating a custom application or server with Duo via the Duo API or Authentication Proxy, what three API configuration parameters generated in the Duo Admin Panel must be provided? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-23 We are installing FreeRADIUS on an Ubuntu 22.04 server to authenticate network switches via EAP-TTLS against an internal OpenLDAP directory. Provide the `/etc/freeradius/3.0/sites-available/default` configuration structure for OpenLDAP backend binding. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-14 We are deploying a new Duo Authentication Proxy instance to bridge RADIUS requests from our VPN to Active Directory. What primary authentication protocol sources can be configured in `authproxy.cfg` to validate primary user credentials? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-04 An enterprise is seeing a rise in prompt-bombing attacks where attackers repeatedly trigger standard Duo Push requests until users approve them. The team wants to keep mobile app authentication without switching everyone to physical security keys. What Duo feature specifically combats MFA fatigue by forcing the user to enter numbers shown on the login screen into the Duo Mobile app? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-22 We are setting up authentication policies strictly inside Microsoft Entra ID (formerly Azure AD) without any third-party MFA proxy or external integration. How do we configure Microsoft Entra Conditional Access to enforce FIDO2 security keys for Entra ID roles? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-07 We need to set up the default Duo adaptive policy for regular full-time employees accessing internal SaaS applications. What are the recommended settings for allowed authentication factors and remembered device duration for standard users? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-24 Our hardware deployment team needs to provision YubiKey 5 Series hardware tokens using YubiKey Manager CLI (`ykman`) to program PIV certificates and FIDO2 PINs on physical keys before distribution. What `ykman` commands format the key and configure the FIDO2 PIN? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-12 Which NIST SP 800-53 Rev. 5 security control specifically governs multi-factor authentication requirements for privileged account access across enterprise infrastructure? | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-17 Field engineers frequently log into Windows laptops with Duo Authentication for Windows Logon installed while traveling without internet access. How should the Windows Logon policy be configured to handle offline scenarios securely? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-13 Which NIST SP 800-53 Rev. 5 control covers device identification and trust assessment when checking endpoint posture prior to granting network access? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-11 During an audit against NIST SP 800-53 Rev. 5 controls, the auditor asks which specific control requirement is addressed by deploying replay-resistant authenticators like WebAuthn keys in Duo. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-19 Our network security team wants to reduce step-up MFA prompts for employees working inside corporate offices while stepping up security for external connections. What policy configuration in Duo should be used to bypass or lower friction based on IP address? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-20 Rank the following four Duo authentication methods from highest security strength to lowest security strength: SMS, Duo Push, WebAuthn/FIDO2, and Duo Verified Push. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-02 During the rollout of Duo Authentication Proxy for corporate VPN, the team is discussing the `failmode` parameter in `authproxy.cfg`. Some engineers recommend setting `failmode = safe` so users are not blocked if the proxy loses connection to Duo's cloud servers. What failmode setting should be enforced in a high-security production environment, and why? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-06 We are defining Duo adaptive access policies for external contractors who require access to corporate web applications. The HR team asked to enable remembered devices for 30 days on contractor accounts to reduce friction. What policy configuration should be enforced for contractors regarding authentication factors and remembered devices? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-01 We are setting up the Duo Authentication Proxy on a RHEL server to handle automatic secondary authentication for our Cisco AnyConnect VPN users connecting via RADIUS. The network administrator suggested using `[radius_server_iframe]` in the proxy configuration file. How should the server section be configured in `authproxy.cfg` to automatically trigger Duo Push upon RADIUS authentication? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-03 Our security operations team is updating authentication policies for domain administrators accessing sensitive jump boxes. A vendor recommended standard Duo Push notifications to minimize login friction for sysadmins. Which Duo authentication factor or mechanism should be required for privileged administrators to provide phishing-resistant authentication aligned with NIST 800-63B AAL3? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-09 An IT helpdesk lead proposes configuring SMS text messages as the default secondary authentication factor across all corporate accounts because every employee has a mobile phone number registered. What is the recommended guidance regarding SMS / Phone call MFA factors in Duo? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-10 We are configuring Duo Device Health checks for endpoints connecting to our network. To meet enterprise endpoint security standards, what three specific endpoint security posture requirements should be enforced in the device health policy before allowing authentication? | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-16 We need to add Duo MFA to SSH logins across our Linux server fleet running Ubuntu and RHEL. Which Duo integration software component provides PAM-based multi-factor authentication for SSH sessions on Linux systems? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-21 An executive lost their mobile device while abroad and needs urgent access to critical systems. What procedure should the Duo administrator execute in the Duo Admin Panel to grant temporary access safely, and what operational safeguard must follow? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |