Courseiva
Cloud Security ArchitecturemediumMultiple ChoiceObjective-mapped

SCAZT Cloud Security Architecture Practice Question

An organization is deploying Cisco Umbrella SIG to enforce Zero Trust access. You must configure the selective decryption policy. Which setting ensures that specific sensitive traffic, such as financial and healthcare sites, is bypassed for inspection to comply with privacy regulations?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Configure a Web Policy rule with a 'Decrypt' action and specify the sensitive categories in the 'Bypass' list.

Within the Cisco Umbrella dashboard, the SSL Decryption policy allows administrators to define bypass lists for specific categories or domains to prevent sensitive traffic from being decrypted.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Apply a 'Transparent Proxy' setting on the local Cisco ASA firewall.

    Why it's wrong here

    This is a hardware-based configuration, not a cloud-native Umbrella SIG setting.

  • Configure a Web Policy rule with a 'Decrypt' action and specify the sensitive categories in the 'Bypass' list.

    Why this is correct

    This is the correct procedural step in Umbrella to exclude traffic from inspection.

  • Enable 'HTTPS Inspection' in the Cloud Security global settings and select 'Bypass All' for all categories.

    Why it's wrong here

    This is a global setting and does not allow granular category-based bypass.

  • Set the 'Block' action for sensitive categories in the Destination Lists.

    Why it's wrong here

    Blocking does not decrypt traffic; it drops the connection.

About these practice questions

Courseiva writes every SCAZT question from scratch — 316 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed August 2026 · checked against the official Cisco exam blueprint

This SCAZT practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCAZT exam.