mediumMultiple ChoiceObjective-mapped
200-201 Practice Question: The cybersecurity analyst for a small business…
You are the cybersecurity analyst for a small business that has a security policy requiring all network traffic to pass through a proxy server for content filtering. Recently, employees have been complaining that some websites are not loading correctly. You check the proxy logs and see that the proxy is blocking traffic that appears to be from non-standard ports. However, upon investigation, you find that the blocked sites are legitimate business tools that use custom ports. Which action aligns with the security policy?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a security exception based on business need and document it.
Creating a documented security exception for the legitimate business tools allows them to function while maintaining the security policy's intent. The policy requires traffic to pass through the proxy for content filtering, but legitimate business needs may necessitate exceptions. Documenting the exception ensures auditability and control. Option A is incorrect because instructing employees to use HTTP instead of the custom ports may not be possible if the tools require specific protocols, and it could introduce security risks. Option B is incorrect because configuring the proxy to allow all traffic on custom ports broadly would bypass content filtering for those ports, potentially allowing malicious traffic. Option C is incorrect because disabling content filtering for affected employees removes the security control entirely, violating the policy.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Instruct employees to access the tools via HTTP instead.
Why it's wrong here
Changing protocols may break functionality or introduce other risks.
- ✗
Configure the proxy to allow all traffic on custom ports for those specific tools.
Why it's wrong here
This could open the network to abuse; exceptions should be targeted and documented.
- ✗
Disable content filtering for the affected employees.
Why it's wrong here
This removes security controls and violates policy for the entire group.
- ✓
Create a security exception based on business need and document it.
Why this is correct
This balances security and usability while maintaining audit trail.
Visual reference
Go deeper
Related to this question
About these practice questions
This 200-201 question is part of Courseiva's 979-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.