Courseiva
easyMultiple SelectObjective-mapped

350-701 Practice Question: A security architect is evaluating Cisco Cloud…

A security architect is evaluating Cisco Cloud Security portfolio for SaaS access protection. Which two solutions provide inline traffic inspection for cloud applications? (Choose two.)

⚠ Common exam trap

Cisco often tests the distinction between API-based CASB (like Cloudlock) and inline proxy-based SIG (like Umbrella), where candidates mistakenly assume all cloud security solutions perform inline inspection, but Cloudlock only provides out-of-band API access for compliance and data protection, not real-time traffic inspection.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Cisco Secure Firewall

Cisco Secure Firewall (A) provides inline traffic inspection for cloud applications through its Next-Generation Firewall (NGFW) capabilities, including Application Visibility and Control (AVC) and SSL/TLS decryption, allowing it to inspect and enforce policies on traffic to and from SaaS applications. Cisco Umbrella SIG (B) is a cloud-delivered Secure Internet Gateway (SIG) that performs inline proxy-based inspection of all web traffic, including SaaS applications, by intercepting DNS and HTTP/HTTPS requests to enforce security policies such as URL filtering, malware detection, and data loss prevention.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Cisco Secure Firewall

    Why this is correct

    Secure Firewall can be deployed as a virtual appliance in the cloud for inline traffic inspection.

  • Cisco Umbrella SIG

    Why this is correct

    Umbrella SIG acts as a secure web gateway with inline inspection.

  • Cisco Cloudlock

    Why it's wrong here

    Cloudlock uses API-based scanning, not inline traffic inspection.

  • Cisco DUO

    Why it's wrong here

    DUO is a multi-factor authentication solution, not a traffic inspection platform.

  • Cisco Secure Workload

    Why it's wrong here

    Secure Workload provides microsegmentation and workload protection, not inline traffic inspection.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

Courseiva writes every 350-701 question from scratch — 978 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-701 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-701 exam.