nerdexam
Cisco

700-281 · Question #36

Which statement about the S-Series native FTP proxy is not true?

The correct answer is C. Authentication is supported in transparent mode. Authentication is not supported in transparent mode for the S-Series native FTP proxy - making C the false statement. Transparent mode intercepts traffic without the client's awareness, so the appliance has no mechanism to issue an authentication challenge; explicit proxy mode…

Implement and Configure Cisco Web Security Appliances

Question

Which statement about the S-Series native FTP proxy is not true?

Options

  • AAccess policies may apply to native FTP traffic.
  • BData loss prevention policies may apply to native FTP traffic
  • CAuthentication is supported in transparent mode.
  • DBoth active and passive mode FTP are supported.
  • EBy default, the FTP proxy uses port 8021.

How the community answered

(33 responses)
  • A
    3% (1)
  • C
    88% (29)
  • D
    3% (1)
  • E
    6% (2)

Explanation

Authentication is not supported in transparent mode for the S-Series native FTP proxy - making C the false statement. Transparent mode intercepts traffic without the client's awareness, so the appliance has no mechanism to issue an authentication challenge; explicit proxy mode is required for authentication to work.

The distractors are all true statements: access policies (A) and DLP policies (B) both apply to native FTP traffic, the proxy handles both active and passive FTP modes (D), and port 8021 is indeed the default port the FTP proxy listens on (E) - distinct from standard FTP port 21.

Memory tip: Link "transparent" to "invisible" - if the proxy is invisible to the client, it cannot ask "Who are you?" Authentication requires the client to know it's talking to a proxy, which only happens in explicit mode.

Topics

#FTP proxy#S-Series#transparent mode#authentication

Community Discussion

No community discussion yet for this question.

Full 700-281 Practice