Courseiva
ConfigurationhardMultiple ChoiceObjective-mapped

300-710 SNCF Configuration Practice Question

An administrator is configuring SSL Decryption to inspect internal clients browsing external websites. The organization wants to ensure that traffic to financial and health-related websites is bypassed to maintain privacy and regulatory compliance. How should this be configured in the SSL Policy?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Create a rule matching the Financial/Health URL categories with the action 'Do Not Decrypt'.

URL categories can be used as criteria in SSL rules to specify a 'Do Not Decrypt' action for sensitive categories like Finance or Health.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Use an Intrusion Policy rule to drop packets destined for financial URLs.

    Why it's wrong here

    Dropping traffic is not the requirement; the requirement is bypassing decryption.

  • Create a rule matching the Financial/Health URL categories with the action 'Do Not Decrypt'.

    Why this is correct

    URL filtering criteria in SSL policies allows bypassing decryption for specific sensitive categories.

  • Add financial servers to an SSL Decryption Known Key list.

    Why it's wrong here

    Known key decryption is used for inbound servers you own, not arbitrary external websites.

  • Configure a Prefilter policy to fast-path financial URL categories.

    Why it's wrong here

    Prefilter fast-path bypasses all inspection, which might prevent necessary logging or other security controls, whereas SSL policy specifically handles decryption bypass.

About these practice questions

Courseiva writes every 300-710 SNCF question from scratch — 478 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed August 2026 · checked against the official Cisco exam blueprint

This 300-710 SNCF practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-710 SNCF exam.