nerdexam
Cisco

700-281 · Question #35

Which of these uses ICAP?

The correct answer is C. Data loss prevention policies. Data loss prevention (DLP) policies use ICAP because the Internet Content Adaptation Protocol is designed to offload content inspection to external servers - precisely the pattern used when a proxy (like Cisco WSA) forwards traffic to a third-party DLP engine for policy…

Describe Cisco Web Security Solutions

Question

Which of these uses ICAP?

Options

  • ADecryption policies
  • BAnti-malware scanning
  • CData loss prevention policies
  • DCisco IronPort Data Security policies

How the community answered

(50 responses)
  • A
    8% (4)
  • B
    4% (2)
  • C
    72% (36)
  • D
    16% (8)

Explanation

Data loss prevention (DLP) policies use ICAP because the Internet Content Adaptation Protocol is designed to offload content inspection to external servers - precisely the pattern used when a proxy (like Cisco WSA) forwards traffic to a third-party DLP engine for policy evaluation before allowing or blocking transmission.

Why the distractors are wrong:

  • A (Decryption policies): SSL/TLS decryption is handled by the proxy's own certificate and inspection engine, not routed through an external ICAP server.
  • B (Anti-malware scanning): On Cisco WSA, anti-malware is performed by built-in engines (Sophos, Webroot, McAfee/AMP) natively - not via ICAP.
  • D (Cisco IronPort Data Security policies): This is the native, on-box DLP - it runs locally without ICAP. ICAP is specifically the integration path for external/third-party DLP servers, not Cisco's own built-in policy engine.

Memory tip: Think of ICAP as a relay to an outside referee - whenever content needs to be handed off to an external system for judgment (like a third-party DLP server), that's ICAP. If Cisco's own engine handles it internally, ICAP isn't involved.

Topics

#ICAP#Data Loss Prevention#Content Adaptation#Cisco Web Security

Community Discussion

No community discussion yet for this question.

Full 700-281 Practice