easyMultiple SelectObjective-mapped
350-701 Practice Question: Is configuring Cisco Web Security Appliance (WSA)…
A security engineer is configuring Cisco Web Security Appliance (WSA) to block downloads of potentially malicious file types such as .exe and .scr. The engineer wants to ensure that these files are blocked even if they are hosted on trusted websites. Which TWO actions should the engineer take?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an access policy that enables file reputation filtering.
Options A and C are correct because file reputation filtering (A) uses Talos threat intelligence to block files based on their reputation, regardless of the source URL, and file type control (C) allows blocking specific file extensions such as .exe and .scr. Both features are configured within an access policy and apply to all traffic, including trusted websites. Option B (custom URL category) is for categorizing websites, not file types. Option D (HTTPS proxy decryption) is necessary for inspecting encrypted traffic but does not itself block file types. Option E (DLP) is designed for data loss prevention, not file type blocking.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create an access policy that enables file reputation filtering.
Why this is correct
File reputation filtering uses the Cisco Talos reputation to block known malicious files.
- ✗
Create a custom URL category for the file types.
Why it's wrong here
URL categories are used to categorize websites by content, not file types.
- ✓
Enable the file type control feature in the access policy.
Why this is correct
File type control allows blocking of specific file extensions.
- ✗
Configure HTTPS proxy to decrypt traffic for file inspection.
Why it's wrong here
HTTPS proxy enables inspection but does not directly block file types; it must be combined with other controls.
- ✗
Enable Data Loss Prevention (DLP) on the access policy.
Why it's wrong here
DLP is for detecting and preventing data leaks, not for blocking file types.
Go deeper
Related to this question
About these practice questions
This 350-701 question is part of Courseiva's 978-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-701 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-701 exam.