Courseiva
Content SecurityhardMultiple SelectObjective-mapped

350-701 Content Security Practice Question

A Cisco WSA administrator needs to implement HTTPS inspection for traffic from internal users. The administrator wants to avoid decrypting traffic to financial and healthcare sites due to compliance requirements. Which THREE actions should the administrator take to configure this policy?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Create a decryption policy with action 'Decrypt' for all traffic

To selectively decrypt, the administrator should create a decryption policy that decrypts all traffic, then use URL category exceptions to bypass decryption for finance and health categories. Alternatively, create a policy that explicitly decrypts all else and uses bypass rules. The three actions: create a decryption policy with action 'Decrypt', add bypass rules for the specified categories, and ensure CA certificate is deployed.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Configure the proxy in explicit mode

    Why it's wrong here

    HTTPS inspection works in both modes; not a required action.

  • Create a decryption policy with action 'Decrypt' for all traffic

    Why this is correct

    This enables decryption by default.

  • Install the WSA's CA certificate on all client devices

    Why this is correct

    Installing the WSA’s CA certificate on all client devices establishes trust in the WSA’s generated certificates, enabling the transparent decryption and re-encryption of HTTPS traffic. This satisfies the requirement to inspect internal user traffic while allowing the administrator to apply a bypass rule for financial and healthcare sites, thus avoiding decryption of those compliant destinations.

  • Enable AMP file scanning for decrypted traffic

    Why it's wrong here

    AMP scanning is optional but not required for HTTPS inspection configuration.

  • Add a bypass rule for the URL categories 'Finance' and 'Health'

    Why this is correct

    Bypass rules prevent decryption of those categories.

About these practice questions

Courseiva writes every 350-701 question from scratch — 978 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-701 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-701 exam.