300-320 · Question #433
A network consultant is designing an Internet Edge solution and is providing the details around the flows supporting a local Internet Proxy. How is on-premises web filtering supported?
The correct answer is B. A Cisco ASA redirects HTTP and HTTPS traffic to the WSA using WCCP. On-premises web filtering is supported by having the Cisco ASA redirect HTTP and HTTPS traffic to the Web Security Appliance (WSA) using WCCP (Web Cache Communication Protocol). WCCP is a Cisco-proprietary protocol designed specifically for transparent traffic redirection to…
Question
A network consultant is designing an Internet Edge solution and is providing the details around the flows supporting a local Internet Proxy. How is on-premises web filtering supported?
Options
- AA cisco ASA uses an IPS module to inspect HTTP and HTTPS traffic.
- BA Cisco ASA redirects HTTP and HTTPS traffic to the WSA using WCCP.
- CA Cisco ASA connects to the web security appliance via TLS to monitor HTTP and HTTPS
- DA Cisco ASA redirects HTTP and HTTPS traffic to CWS with a Web Security Connector.
How the community answered
(53 responses)- A2% (1)
- B91% (48)
- C2% (1)
- D6% (3)
Explanation
On-premises web filtering is supported by having the Cisco ASA redirect HTTP and HTTPS traffic to the Web Security Appliance (WSA) using WCCP (Web Cache Communication Protocol). WCCP is a Cisco-proprietary protocol designed specifically for transparent traffic redirection to proxy and caching appliances. The WSA then performs web filtering, URL categorization, and malware inspection. Option A is incorrect because an IPS module inspects for intrusion signatures, not web content filtering. Option C is incorrect because the ASA does not connect to the WSA via TLS for monitoring. Option D describes the Cloud Web Security (CWS) solution, which is a cloud-based approach, not an on-premises local proxy.
Topics
Community Discussion
No community discussion yet for this question.