350-701 · Question #520
Which two protocols must be configured to authenticate end users to the Cisco WSA? (Choose two.)
The correct answer is A. NTLMSSP B. Kerberos. To authenticate end users to the Cisco Web Security Appliance (WSA), NTLMSSP and Kerberos protocols must be configured, especially for integration with Microsoft Active Directory.
Question
Which two protocols must be configured to authenticate end users to the Cisco WSA? (Choose two.)
Exhibit
Options
- ANTLMSSP
- BKerberos
- CCHAP
- DTACACS+
- ERADIUS
How the community answered
(36 responses)- A94% (34)
- C3% (1)
- D3% (1)
Why each option
To authenticate end users to the Cisco Web Security Appliance (WSA), NTLMSSP and Kerberos protocols must be configured, especially for integration with Microsoft Active Directory.
NTLMSSP (NT LAN Manager Security Support Provider) is a common protocol used by Windows systems for authentication, enabling the Cisco WSA to authenticate users against a Windows domain.
Kerberos is the default authentication protocol for Active Directory and is used by the Cisco WSA for secure, transparent user authentication within a Windows domain environment, offering a more secure alternative to NTLM.
CHAP (Challenge-Handshake Authentication Protocol) is an older authentication protocol primarily used for PPP connections, not for authenticating end users to a web proxy like the WSA.
TACACS+ is primarily used for authenticating network device administrators, not for authenticating end users accessing web resources through a WSA.
RADIUS is typically used for network access authentication or for VPN users, but NTLMSSP and Kerberos are the primary protocols for transparent authentication of enterprise users to a Cisco WSA, especially in Active Directory environments.
Concept tested: Cisco WSA user authentication protocols
Source: https://www.cisco.com/c/en/us/products/security/web-security-appliance-wsa/index.html
Topics
Community Discussion
No community discussion yet for this question.
