You are implementing Cisco Umbrella CASB to restrict file uploads to unsanctioned SaaS applications. You have configured an App Control rule, but users can still upload files to a cloud storage service. What is the most likely cause?
Trap 1: The SSL inspection certificate is not installed on the server.
SSL inspection certificates must be installed on the client, not the server.
Trap 2: The SaaS application is whitelisted in the Global Settings.
While possible, the most common operational failure is the lack of proxy enforcement for DLP.
Trap 3: The DNS policy is not configured for the user group.
DNS policy would block the domain, not the specific file upload action.
- A
The Intelligent Proxy is disabled in the Web Policy.
Without the intelligent proxy enabled, Umbrella cannot inspect the file contents or enforce granular upload controls.
- B
The SSL inspection certificate is not installed on the server.
Why wrong: SSL inspection certificates must be installed on the client, not the server.
- C
The SaaS application is whitelisted in the Global Settings.
Why wrong: While possible, the most common operational failure is the lack of proxy enforcement for DLP.
- D
The DNS policy is not configured for the user group.
Why wrong: DNS policy would block the domain, not the specific file upload action.