700-281 · Question #35
Which of these uses ICAP?
The correct answer is C. Data loss prevention policies. Data loss prevention (DLP) policies use ICAP because the Internet Content Adaptation Protocol is designed to offload content inspection to external servers - precisely the pattern used when a proxy (like Cisco WSA) forwards traffic to a third-party DLP engine for policy…
Question
Which of these uses ICAP?
Options
- ADecryption policies
- BAnti-malware scanning
- CData loss prevention policies
- DCisco IronPort Data Security policies
How the community answered
(50 responses)- A8% (4)
- B4% (2)
- C72% (36)
- D16% (8)
Explanation
Data loss prevention (DLP) policies use ICAP because the Internet Content Adaptation Protocol is designed to offload content inspection to external servers - precisely the pattern used when a proxy (like Cisco WSA) forwards traffic to a third-party DLP engine for policy evaluation before allowing or blocking transmission.
Why the distractors are wrong:
- A (Decryption policies): SSL/TLS decryption is handled by the proxy's own certificate and inspection engine, not routed through an external ICAP server.
- B (Anti-malware scanning): On Cisco WSA, anti-malware is performed by built-in engines (Sophos, Webroot, McAfee/AMP) natively - not via ICAP.
- D (Cisco IronPort Data Security policies): This is the native, on-box DLP - it runs locally without ICAP. ICAP is specifically the integration path for external/third-party DLP servers, not Cisco's own built-in policy engine.
Memory tip: Think of ICAP as a relay to an outside referee - whenever content needs to be handed off to an external system for judgment (like a third-party DLP server), that's ICAP. If Cisco's own engine handles it internally, ICAP isn't involved.
Topics
Community Discussion
No community discussion yet for this question.