PSE-SASE · Question #65
What is a disadvantage of proxy secure access service edge (SASE) when compared to an inline SASE solution?
The correct answer is D. Exclusive use of web proxies leads to significant blind spots in traffic and an inability to identify. Option D is correct because web proxies are designed specifically for HTTP/HTTPS traffic, meaning any non-web protocols (DNS, non-standard ports, UDP-based apps, etc.) simply bypass the proxy entirely. An inline SASE solution sits directly in the traffic path and inspects all…
Question
What is a disadvantage of proxy secure access service edge (SASE) when compared to an inline SASE solution?
Options
- AProxies force policy actions to be treated as business decisions instead of compromises due to
- BTeams added additional tools to web proxies that promised to solve point problems, resulting in a
- CProxy solutions require an unprecedented level of interconnectivity.
- DExclusive use of web proxies leads to significant blind spots in traffic and an inability to identify
How the community answered
(29 responses)- A17% (5)
- B3% (1)
- C7% (2)
- D72% (21)
Explanation
Option D is correct because web proxies are designed specifically for HTTP/HTTPS traffic, meaning any non-web protocols (DNS, non-standard ports, UDP-based apps, etc.) simply bypass the proxy entirely. An inline SASE solution sits directly in the traffic path and inspects all traffic regardless of protocol or port, eliminating these blind spots and providing full visibility into threats that would otherwise go undetected.
Why the distractors are wrong:
- A is backwards logic - having policy actions tied to business decisions is generally a benefit, not a drawback, of security architecture.
- B describes the historical problem of proxy sprawl (bolt-on tools creating complexity), which is a reason organizations moved toward SASE frameworks, not a specific architectural flaw of proxy SASE vs. inline SASE.
- C is fabricated - proxy solutions don't inherently demand unusual interconnectivity; if anything, inline solutions require more careful network path integration.
Memory tip: Think "PROXY = PARTIAL." A web proxy only sees web traffic - everything else walks right past it. An inline solution puts security IN THE LINE of all traffic, so nothing escapes inspection. If you see "blind spots" or "visibility gaps," proxy architecture is almost always the culprit on exam questions.
Topics
Community Discussion
No community discussion yet for this question.