300-740 · Question #38
An engineer configures trusted endpoints with Active Directory with Device Health to determine if an endpoint complies with the policy posture. After a week, an alert is received by one user…
The correct answer is D. Verify the Cisco Secure Endpoint admin panel, check the Inbox tab, verify the status of the. Option D is correct because the error message explicitly directs the engineer to Cisco Secure Endpoint - not Duo - to investigate the failed check. The Inbox tab in the Cisco Secure Endpoint admin panel displays active security events, detections, and policy violations for…
Question
An engineer configures trusted endpoints with Active Directory with Device Health to determine if an endpoint complies with the policy posture. After a week, an alert is received by one user, reporting problems accessing an application. When the engineer verifies the authentication report, this error is found:
"Endpoint is not trusted because Cisco Secure Endpoint check failed, Check user's endpoint in Cisco Secure Endpoint." Which action must the engineer take to permit access to the application again?
Options
- AVerify the Cisco Secure Endpoint admin panel and approve the access to the user on the
- BVerify the Trusted Endpoints policy to verify the status of the machine, and after a complete
- CVerify the Duo admin panel, check the EndPoints tab, verify the status of the machine, and after a
- DVerify the Cisco Secure Endpoint admin panel, check the Inbox tab, verify the status of the
How the community answered
(62 responses)- A8% (5)
- B15% (9)
- C3% (2)
- D74% (46)
Explanation
Option D is correct because the error message explicitly directs the engineer to Cisco Secure Endpoint - not Duo - to investigate the failed check. The Inbox tab in the Cisco Secure Endpoint admin panel displays active security events, detections, and policy violations for managed endpoints, making it the right place to diagnose why the endpoint is flagged and remediate the issue (e.g., clearing malware, resolving a quarantine, or confirming the agent is healthy) before access can be restored.
Why the distractors fail:
- A is wrong because you cannot simply "approve access" in Cisco Secure Endpoint - the underlying health issue must be identified and remediated first.
- B is wrong because re-checking the Trusted Endpoints policy in Duo addresses configuration, not the endpoint's health status; the policy itself isn't the problem here.
- C is the most tempting distractor, but checking the Duo admin panel's Endpoints tab shows device registration status in Duo - it won't reveal why the Cisco Secure Endpoint agent check failed.
Memory tip: Let the error message be your compass - it literally says "Check user's endpoint in Cisco Secure Endpoint." On exam questions involving integration failures, the tool named in the error message is almost always where you start remediation.
Topics
Community Discussion
No community discussion yet for this question.