nerdexam
Palo_Alto_Networks

PSE-SASE · Question #65

What is a disadvantage of proxy secure access service edge (SASE) when compared to an inline SASE solution?

The correct answer is D. Exclusive use of web proxies leads to significant blind spots in traffic and an inability to identify. Option D is correct because web proxies are designed specifically for HTTP/HTTPS traffic, meaning any non-web protocols (DNS, non-standard ports, UDP-based apps, etc.) simply bypass the proxy entirely. An inline SASE solution sits directly in the traffic path and inspects all…

SASE Architecture and Concepts

Question

What is a disadvantage of proxy secure access service edge (SASE) when compared to an inline SASE solution?

Options

  • AProxies force policy actions to be treated as business decisions instead of compromises due to
  • BTeams added additional tools to web proxies that promised to solve point problems, resulting in a
  • CProxy solutions require an unprecedented level of interconnectivity.
  • DExclusive use of web proxies leads to significant blind spots in traffic and an inability to identify

How the community answered

(29 responses)
  • A
    17% (5)
  • B
    3% (1)
  • C
    7% (2)
  • D
    72% (21)

Explanation

Option D is correct because web proxies are designed specifically for HTTP/HTTPS traffic, meaning any non-web protocols (DNS, non-standard ports, UDP-based apps, etc.) simply bypass the proxy entirely. An inline SASE solution sits directly in the traffic path and inspects all traffic regardless of protocol or port, eliminating these blind spots and providing full visibility into threats that would otherwise go undetected.

Why the distractors are wrong:

  • A is backwards logic - having policy actions tied to business decisions is generally a benefit, not a drawback, of security architecture.
  • B describes the historical problem of proxy sprawl (bolt-on tools creating complexity), which is a reason organizations moved toward SASE frameworks, not a specific architectural flaw of proxy SASE vs. inline SASE.
  • C is fabricated - proxy solutions don't inherently demand unusual interconnectivity; if anything, inline solutions require more careful network path integration.

Memory tip: Think "PROXY = PARTIAL." A web proxy only sees web traffic - everything else walks right past it. An inline solution puts security IN THE LINE of all traffic, so nothing escapes inspection. If you see "blind spots" or "visibility gaps," proxy architecture is almost always the culprit on exam questions.

Topics

#proxy SASE#inline SASE#traffic visibility#security blind spots

Community Discussion

No community discussion yet for this question.

Full PSE-SASE Practice