nerdexam
Cisco

350-701 · Question #507

Which two criteria must a certificate meet before the Cisco Secure Web Appliance uses it to decrypt application traffic? (Choose two.)

The correct answer is B. It must reside in the trusted store of the Secure Web Appliance. C. It must reside in the trusted store of the endpoint. It must reside in the trusted store of the endpoint: The certificate used by the Secure Web Appliance for HTTPS decryption must be trusted by the client devices (endpoints). This ensures that the endpoints recognize the appliance as a trusted intermediary and do not display…

Submitted by kim_seoul· Mar 30, 2026

Question

Which two criteria must a certificate meet before the Cisco Secure Web Appliance uses it to decrypt application traffic? (Choose two.)

Options

  • AIt must include the current date.
  • BIt must reside in the trusted store of the Secure Web Appliance.
  • CIt must reside in the trusted store of the endpoint.
  • DIt must have been signed by an internal CA.
  • Eit must contain a SAN.

How the community answered

(31 responses)
  • A
    3% (1)
  • B
    87% (27)
  • D
    6% (2)
  • E
    3% (1)

Explanation

It must reside in the trusted store of the endpoint: The certificate used by the Secure Web Appliance for HTTPS decryption must be trusted by the client devices (endpoints). This ensures that the endpoints recognize the appliance as a trusted intermediary and do not display certificate It must reside in the trusted store of the Secure Web Appliance: The appliance itself must have access to the certificate, including the private key, in its trusted certificate store to use it for decrypting and re-encrypting traffic.

Topics

#Cisco SWA#SSL decryption#certificate trust#certificate requirements

Community Discussion

No community discussion yet for this question.

Full 350-701 Practice