nerdexam
Cisco

300-740 · Question #18

An administrator received an incident report indicating suspicious activity of a user using a corporate device. The manager requested that the credentials of user [email protected] be reset and synced…

The correct answer is D. Disable the account on the Users tab and reset the password from the Active Directory. Option D is correct because it satisfies all three requirements simultaneously: disabling the account in Duo's Users tab immediately blocks the user from authenticating (stopping the suspicious activity), resetting the password through Active Directory addresses the compromised…

User and Device Security

Question

An administrator received an incident report indicating suspicious activity of a user using a corporate device. The manager requested that the credentials of user [email protected] be reset and synced via the Active Directory. Removing the account should be avoided and used for further investigation on data leak. Which configuration must the administrator apply on the Duo Admin Panel?

Options

  • ADelete the user in the Users tab option and sync it with the domain controller.
  • BQuarantine the user from all the policies on the Policies tab, including associated devices.
  • CRequest the password change on the Device tab on managed devices.
  • DDisable the account on the Users tab and reset the password from the Active Directory.

How the community answered

(55 responses)
  • A
    13% (7)
  • B
    5% (3)
  • C
    2% (1)
  • D
    80% (44)

Explanation

Option D is correct because it satisfies all three requirements simultaneously: disabling the account in Duo's Users tab immediately blocks the user from authenticating (stopping the suspicious activity), resetting the password through Active Directory addresses the compromised credentials and syncs the change, and - critically - the account is disabled, not deleted, preserving it for forensic investigation of the data leak.

Option A is wrong because it explicitly deletes the user account, which directly contradicts the incident requirement to keep the account intact for investigation.

Option B is wrong because Duo does not have a "Quarantine" function on the Policies tab; more importantly, manipulating policies doesn't reset credentials or fulfill the Active Directory sync requirement.

Option C is wrong because Duo's Device tab is for managing enrolled authentication devices (phones, tokens), not for initiating password resets - password management in an AD-integrated environment is performed through Active Directory itself, not through Duo's device management interface.

Memory tip: Remember D-A-D - Disable in Duo, AD resets the password, and you Don't delete. Whenever an incident requires "block but preserve," think disable + credential reset, never delete.

Topics

#Account Management#Incident Response#Credential Reset#Active Directory Integration

Community Discussion

No community discussion yet for this question.

Full 300-740 Practice