Courseiva
easyMultiple ChoiceObjective-mapped

350-701 Practice Question: A company's Cisco WSA is configured with explicit…

A company's Cisco WSA is configured with explicit proxy mode. Users report that they can browse the internet but cannot access internal websites hosted on the company's intranet. What is the most likely cause?

⚠ Common exam trap

Cisco often tests the distinction between explicit and transparent proxy modes, and the trap here is that candidates assume authentication or SSL decryption is the cause, when the real issue is the proxy bypass list not covering internal destinations.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The internal websites are not in the proxy bypass list.

In explicit proxy mode, the WSA requires clients to be configured to send traffic to it. If internal websites are not added to the proxy bypass list (or the WSA's PAC file does not direct internal traffic directly), the WSA will attempt to proxy requests for internal sites, which may fail because the WSA cannot route to internal IPs or the internal DNS resolution fails. This is the most likely cause because users can browse the internet (proxied traffic works) but cannot reach internal sites (which should bypass the proxy).

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The WSA is in transparent proxy mode.

    Why it's wrong here

    Explicit mode is configured.

  • Users are not authenticated to the WSA.

    Why it's wrong here

    Authentication not required for access.

  • The internal websites are not in the proxy bypass list.

    Why this is correct

    Proxy bypass list needed for internal traffic.

  • SSL decryption is blocking the internal sites.

    Why it's wrong here

    SSL decryption is for HTTPS inspection.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

Courseiva writes every 350-701 question from scratch — 978 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-701 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-701 exam.