ExamGecko
Question list
Search
Search

Question 176 - 350-701 discussion

Report
Export

What are two differences between a Cisco WSA that is running in transparent mode and one running in explicit mode? (Choose two)

A.

When the Cisco WSA is running in transparent mode, it uses the WSA's own IP address as the HTTP request destination.

Answers
A.

When the Cisco WSA is running in transparent mode, it uses the WSA's own IP address as the HTTP request destination.

B.

The Cisco WSA responds with its own IP address only if it is running in explicit mode.

Answers
B.

The Cisco WSA responds with its own IP address only if it is running in explicit mode.

C.

The Cisco WSA is configured in a web browser only if it is running in transparent mode.

Answers
C.

The Cisco WSA is configured in a web browser only if it is running in transparent mode.

D.

The Cisco WSA uses a Layer 3 device to redirect traffic only if it is running in transparent mode.

Answers
D.

The Cisco WSA uses a Layer 3 device to redirect traffic only if it is running in transparent mode.

E.

The Cisco WSA responds with its own IP address only if it is running in transparent mode.

Answers
E.

The Cisco WSA responds with its own IP address only if it is running in transparent mode.

Suggested answer: B, D

Explanation:

The Cisco Web Security Appliance (WSA) includes a web proxy, a threat analytics engine, antimalware engine, policy management, and reporting in a single physical or virtual appliance. The main use of the Cisco WSA is to protect users from accessing malicious websites and being infected by malware.

You can deploy the Cisco WSA in two different modes:

– Explicit forward mode

– Transparent mode

In explicit forward mode, the client is configured to explicitly use the proxy, subsequently sending all web traffic to the proxy. Because the client knows there is a proxy and sends all traffic to the proxy in explicit forward mode, the client does not perform a DNS lookup of the domain before requesting the URL. The Cisco WSA is responsible for DNS resolution, as well.

When you configure the Cisco WSA in explicit mode, you do not need to configure any other network infrastructure devices to redirect client requests to the Cisco WSA. However, you must configure each client to send traffic to the Cisco WSA.

-> Therefore in explicit mode, WSA only checks the traffic between client & web server. WSA does not use its own IP address to request -> Answer B is not correct.

When the Cisco WSA is in transparent mode, clients do not know there is a proxy deployed. Network infrastructure devices are configured to forward traffic to the Cisco WSA. In transparent mode deployments, network infrastructure devices redirect web traffic to the proxy. Web traffic redirection can be done using policybased routing (PBR)—available on many routers —or using Cisco's Web Cache Communication Protocol (WCCP) on Cisco ASA, Cisco routers, or switches.

The Web Cache Communication Protocol (WCCP), developed by Cisco Systems, specifies interactions between one or more switches) and one or more web-caches. The purpose of the interaction is to establish and maintain the transparent redirectio of traffic flowing through a group of routers.

Reference: https://www.cisco.com/c/en/us/tech/content-networking/web-cache-communicationsprotocol-wccp/index.html->Therefore answer D is correct as redirection can be done on Layer 3 device only.

In transparent mode, the client is unaware its traffic is being sent to a proxy (Cisco WSA) and, as a result, the client uses DNS to resolve the domain name in the URL and send the web request destined for the web server (not the proxy).

When you configure the Cisco WSA in transparent mode, you need to identify a network choke point with a redirection device (a Cisco ASA) to redirect traffic to the proxy.

WSA in Transparent mode

Reference: CCNP And CCIE Security Core SCOR 350-701 Official Cert Guide -> Therefore in Transparent mode, WSA uses its own IP address to initiate a new connection the Web Server (in step 4 above) -> Answer E is correct.

Answer C is surely not correct as WSA cannot be configured in a web browser in either mode.

Answer A seems to be correct but it is not. This answer is correct if it states "When the Cisco WSA is running in transparent mode, it uses the WSA's own IP address as the HTTP request source" (not destination).

asked 10/10/2024
San Min Oo
40 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first