350-701 · Question #444
An engineer is configuring web filtering for a network using Cisco Umbrella Secure Internet Gateway. The requirement is that all traffic needs to be filtered. Using the SSL decryption feature, which…
The correct answer is C. organization owned root. For SSL decryption on a Cisco Umbrella Secure Internet Gateway, an organization-owned root certificate must be deployed to client devices to ensure trust and prevent browser warnings when Umbrella acts as a Man-in-the-Middle.
Question
An engineer is configuring web filtering for a network using Cisco Umbrella Secure Internet Gateway. The requirement is that all traffic needs to be filtered. Using the SSL decryption feature, which type of certificate should be presented to the end-user to accomplish this goal?
Options
- Athird-party
- Bself-signed
- Corganization owned root
- DSubCA
How the community answered
(40 responses)- A5% (2)
- B15% (6)
- C78% (31)
- D3% (1)
Why each option
For SSL decryption on a Cisco Umbrella Secure Internet Gateway, an organization-owned root certificate must be deployed to client devices to ensure trust and prevent browser warnings when Umbrella acts as a Man-in-the-Middle.
A generic third-party certificate would not be the root certificate owned and managed by the organization for its internal SSL inspection proxy.
A self-signed certificate would cause browser warnings on all end-user devices unless explicitly installed and trusted by each one.
When enabling SSL decryption with Cisco Umbrella Secure Internet Gateway, Umbrella acts as an intermediary, intercepting encrypted traffic, decrypting it for inspection, and then re-encrypting it before forwarding. To avoid browser trust warnings on end-user devices, the organization's owned root certificate (or an intermediate certificate signed by it) must be installed and trusted by client devices, allowing them to trust certificates issued by Umbrella during the decryption process.
A SubCA certificate would still need to be chained back to a trusted root, typically the organization's own root CA that is distributed to clients, making the organization-owned root the more accurate answer for the core trust anchor.
Concept tested: SSL decryption certificate trust
Source: https://docs.umbrella.com/umbrella-user-guide/docs/secure-internet-gateway-prerequisites
Topics
Community Discussion
No community discussion yet for this question.