350-701 · Question #727
What must be disabled on a Cisco Secure Web Appliance to ensure HTTPS traffic with a good reputation score bypasses decryption?
The correct answer is B. Decrypt Policies. To prevent a Cisco Secure Web Appliance from decrypting HTTPS traffic with a good reputation, the relevant decryption policies must be configured to bypass such traffic.
Question
What must be disabled on a Cisco Secure Web Appliance to ensure HTTPS traffic with a good reputation score bypasses decryption?
Options
- ADecrypt ACL
- BDecrypt Policies
- CDecrypt for End-User Acknowledgment
- DDecrypt for End-User Notification
How the community answered
(29 responses)- A7% (2)
- B76% (22)
- C3% (1)
- D14% (4)
Why each option
To prevent a Cisco Secure Web Appliance from decrypting HTTPS traffic with a good reputation, the relevant decryption policies must be configured to bypass such traffic.
A Decrypt ACL (Access Control List) is a component of a decryption policy, but disabling the entire policy provides the overarching control for bypassing decryption.
On a Cisco Secure Web Appliance, decryption policies define which HTTPS traffic is subject to decryption. To ensure HTTPS traffic with a good reputation score bypasses decryption, the decryption policies must be configured or disabled to specifically exclude this traffic, allowing selective decryption based on reputation or other criteria.
Decrypt for End-User Acknowledgment is a feature for user notification, not a mechanism to control whether traffic with a good reputation bypasses decryption.
Decrypt for End-User Notification is also a notification feature, not a setting to bypass decryption based on a good reputation score.
Concept tested: Cisco Secure Web Appliance HTTPS decryption policies
Source: https://www.cisco.com/c/en/us/td/docs/security/wsa/wsa_11-7/user_guide/b_WSA_Features_11_7_1/b_WSA_Features_11_7_1_chapter_010.html
Topics
Community Discussion
No community discussion yet for this question.