nerdexam
Cisco

700-281 · Question #8

Which authentication protocol takes precedence by default when WSA uses AD authentication?

The correct answer is F. NTLMSSP. NTLMSSP (NT LAN Manager Security Support Provider) is the default authentication protocol that takes precedence on Cisco WSA when integrated with Active Directory, because WSA relies on Windows' native challenge-response mechanism for AD authentication without requiring…

Implement and Configure Cisco Web Security Appliances

Question

Which authentication protocol takes precedence by default when WSA uses AD authentication?

Options

  • ALDAPS
  • BKerberos
  • CNTLMv3
  • DNTLMv2
  • ELDAP
  • FNTLMSSP

How the community answered

(17 responses)
  • D
    6% (1)
  • F
    94% (16)

Explanation

NTLMSSP (NT LAN Manager Security Support Provider) is the default authentication protocol that takes precedence on Cisco WSA when integrated with Active Directory, because WSA relies on Windows' native challenge-response mechanism for AD authentication without requiring additional Kerberos configuration. Kerberos (B) is capable but must be explicitly configured and is not the default priority on WSA. LDAP and LDAPS (A, E) are directory query protocols used to look up user/group information, not primary authentication protocols. NTLMv2 (D) is a specific version of the NTLM protocol, while NTLMSSP is the negotiation wrapper that governs the overall NTLM authentication exchange - and NTLMv3 (C) does not exist as a real protocol, making it a pure distractor.

Memory tip: Think "WSA + AD = SSP by default" - the Security Support Provider is Windows' built-in mechanism, so WSA leans on it automatically. If Kerberos were the answer, you'd need to remember that extra configuration was done; the absence of that config means NTLMSSP wins.

Topics

#Active Directory authentication#NTLMSSP#WSA authentication precedence#authentication protocols

Community Discussion

No community discussion yet for this question.

Full 700-281 Practice