700-281 · Question #62
Which of these user ICAP?
The correct answer is B. data loss prevention polices. Data loss prevention (DLP) policies use ICAP (Internet Content Adaptation Protocol) because ICAP is designed to offload content inspection to external servers - DLP solutions integrate via ICAP to inspect outbound traffic for sensitive data before it leaves the network. Why the…
Question
Which of these user ICAP?
Options
- Aanti-malware scanning
- Bdata loss prevention polices
- Cdecryption policies
- DCiscoIronPort Data Security policies
How the community answered
(41 responses)- A2% (1)
- B90% (37)
- C2% (1)
- D5% (2)
Explanation
Data loss prevention (DLP) policies use ICAP (Internet Content Adaptation Protocol) because ICAP is designed to offload content inspection to external servers - DLP solutions integrate via ICAP to inspect outbound traffic for sensitive data before it leaves the network.
Why the distractors are wrong:
- A (anti-malware scanning): Cisco WSA performs anti-malware scanning using native integrated engines (Sophos, McAfee), not ICAP.
- C (decryption policies): SSL/TLS decryption is handled through the appliance's own certificate infrastructure, not ICAP.
- D (Cisco IronPort Data Security policies): This is Cisco's built-in DLP solution - it operates natively on the appliance and does not require ICAP. ICAP is for external DLP integrations.
Memory tip: Think of ICAP as the "outsourcing protocol" - it's specifically for when the appliance needs to hand off content to an external server for inspection. DLP via ICAP = external DLP engine; IronPort Data Security = internal/native. If the exam says "ICAP," think external DLP integration.
Topics
Community Discussion
No community discussion yet for this question.