Duo and RTC for FTD Remote Access VPN

Describe Rapid Threat Containment (RTC) functionality within Secure Firewall Management Center Configure security policies such as access control, DNS, identity, and network analysis policy in Secure Firewall Management Center
Answer Correct answer: A, E — Cisco FTD remote access VPN supports Duo two-factor authentication using LDAPS and Rapid Threat Containment using RADIUS dynamic authorization.

Which two features can be used with Cisco Secure Firewall Threat Defense remote access VPN? (Choose two.)

  1. enable Duo two-factor authentication using LDAPS Correct Answer
  2. support for Cisco Secure Firewall 4100 Series in cluster mode
  3. SSL remote access VPN supports port sharing with other Cisco FTD features using SSL port 443
  4. use of license utilization for zero-touch network deployment
  5. support for Rapid Threat Containment using RADIUS dynamic authorization Correct Answer

Community Votes

AE
67%
AC
33%

67% of anonymous learners picked answer AE. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests supported features for FTD remote access VPN, specifically Duo 2FA with LDAPS and RTC with RADIUS CoA, with the common trap being port sharing on 443.

Cisco Secure Firewall Threat Defense remote access VPN supports Duo two-factor authentication via LDAPS and Rapid Threat Containment (RTC) via RADIUS dynamic authorization. This page establishes why options A and E are the correct features and why port sharing is invalid.

Choosing C because SSL VPN typically uses port 443, but FTD requires exclusive use of this port and does not support port sharing for RA VPN.

Community Discussion (6 comments)

LC1980 👍 7
Correct answer is A and E. https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/device-config/710/management-center-device-config-71/vpn-remote-access.html
artilling 👍 3 Selected: AE
A. Now LDAPS with Cisco Duo went to End Of Live. But until February 20, 2025 this bundle worked. "VPN users logging into existing LDAPS applications can still complete two-factor authentication. Duo Support teams will continue to troubleshoot LDAPS applications." https://help.duo.com/s/article/8019?language=en_US E. Rapid Threat Containment support using RADIUS CoA or RADIUS dynamic authorization. https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/device-config/710/management-center-device-config-71/vpn-remote-access.html#concept_kkw_sv2_2hb
tinyJoe 👍 3 Selected: AE
Definitely A and E. C is clearly wrong from the following documentation: https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/device-config/760/management-center-device-config-76/vpn-remote-access.html?bookSearch=true#:~:text=These%20ports%20must%20not%20be%20used%20on%20the%20threat%20defense%20device%20before%20configuring%20remote%20access%20VPN%20policy
aaInman 👍 3 Selected: AC
A and C - Cisco is never going to miss an opportunity to sell another one of their services in its certification exam. Configure DUO for LDAP over VPN https://duo.com/docs/ciscoasa-ldap#:~:text=Duo%20Two%2DFactor%20Authentication%20with%20LDAPS%20for%20Cisco%20ASA%20SSL%20VPN%20with%20Browser%20and%C2%A0AnyConnect
LC1980 👍 2
Cer2020, what you say is correct but there aren't other correct choises in the answer, so I prefer A
Cer2020 👍 1
Can't be A - You cannot use a direct connection with the Duo Cloud Service over LDAPS - need an Auth Proxy

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Cisco Secure Firewall Threat Defense (FTD) remote access VPN supports Duo two-factor authentication using LDAPS, allowing integration with Duo's cloud service for secondary authentication. Additionally, FTD RA VPN supports Rapid Threat Containment (RTC) using RADIUS dynamic authorization (Change of Authorization), enabling the firewall to dynamically restrict or terminate user sessions based on threat postures. These two features are explicitly documented as supported for FTD remote access VPN configurations.

Why the Other Options Are Wrong

Option B is incorrect because FTD remote access VPN does not support high availability clustering on the 4100 Series. Option C is a major trap; FTD explicitly prohibits port sharing on SSL port 443 with other features, requiring the port to be exclusively dedicated to the VPN. Option D is incorrect as license utilization for zero-touch network deployment is not a feature of remote access VPN.

Community Comment Notes

Community members strongly agree that A and E are correct. As tinyJoe noted, "C is clearly wrong from the following documentation" which states "These ports must not be used on the threat defense device before configuring remote access VPN policy". artilling also confirmed "Rapid Threat Containment support using RADIUS CoA or RADIUS dynamic authorization" for option E, while acknowledging Duo LDAPS support despite its end-of-life status for direct cloud connections.

Official Reference

Exam Strategy

For FTD remote access VPN questions, remember that SSL port 443 cannot be shared with other features and must be dedicated. Also, recall that RTC relies specifically on RADIUS dynamic authorization (CoA) to function with VPN sessions.

Related Analysis

← Back to 300-710 Study Guide