700-281 · Question #13
Which protocol does External Data Loss Protection integration with the Web Security Appliance use?
The correct answer is D. ICAP. ICAP (Internet Content Adaptation Protocol) is the standard protocol used by the Cisco Web Security Appliance (WSA) to communicate with external Data Loss Prevention (DLP) engines - it was purpose-built for offloading content inspection to external services, making it the…
Question
Which protocol does External Data Loss Protection integration with the Web Security Appliance use?
Options
- ASNMP
- BSMTP
- CHTTP
- DICAP
- EICMP
- FLDAP
- GIMAP
How the community answered
(35 responses)- C3% (1)
- D89% (31)
- E3% (1)
- F6% (2)
Explanation
ICAP (Internet Content Adaptation Protocol) is the standard protocol used by the Cisco Web Security Appliance (WSA) to communicate with external Data Loss Prevention (DLP) engines - it was purpose-built for offloading content inspection to external services, making it the natural fit for DLP integration. The WSA forwards HTTP/HTTPS request and response bodies to the external DLP server via ICAP, which scans for sensitive data and returns a verdict (allow/block) back to the appliance.
The distractors are wrong because they serve entirely different purposes: SNMP is for network device monitoring, SMTP is for sending email, HTTP is the web traffic being inspected (not the inspection channel itself), ICMP is for network diagnostics like ping, LDAP is for directory/authentication lookups, and IMAP is for retrieving email from a mail server.
Memory tip: Think of ICAP as a "content inspection middleman" - the acronym itself (Internet Content Adaptation Protocol) signals its job is adapting/inspecting content, which maps directly to what DLP does. If a question involves external content scanning on a proxy or web appliance, ICAP is almost always the answer.
Topics
Community Discussion
No community discussion yet for this question.