WSA HTTPS Reputation Bypass Decryption

Implement access control policies, AVC, URL filtering, malware protection, and intrusion prevention using Cisco Secure Firewall (FTD)
Answer Correct answer: B — Disabling Decrypt Policies ensures HTTPS traffic with a good reputation score bypasses decryption.

What must be disabled on a Cisco Secure Web Appliance to ensure HTTPS traffic with a good reputation score bypasses decryption?

  1. Decrypt ACL
  2. Decrypt Policies Correct Answer
  3. Decrypt for End-User Acknowledgment
  4. Decrypt for End-User Notification

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The core trap is confusing policy-level control with access-list filtering; you must disable the Decrypt Policy itself to allow traffic with a good reputation score to pass undecrypted.

This question tests how to configure Cisco Secure Web Appliance (WSA) to bypass SSL decryption for trusted sites. The correct configuration relies on disabling specific Decrypt Policies rather than global ACLs.

Candidates often select 'Decrypt ACL' because it sounds like a filter, but ACLs in WSA typically determine if a policy applies or if traffic is allowed/denied, not specifically the reputation-based bypass mechanism described here.

Community Discussion (5 comments)

BrahimMELLAL 👍 1 Selected: B
there is decrypt ACL with WSA config
houhou12322 👍 1 Selected: B
https://www.cisco.com/c/en/us/td/docs/security/wsa/wsa_14-0/User-Guide/b_WSA_UserGuide_14_0/b_WSA_UserGuide_11_7_appendix_010111.html#task_1316480
kloug 👍 1
Answer b
VirtuaTech 👍 2
B. Decrypt Policies. Disabling specific decrypt policies allows traffic deemed safe (e.g., with a good reputation score) to bypass decryption altogether.
Premium_Pils 👍 1 Selected: B
https://www.cisco.com/c/en/us/td/docs/security/wsa/wsa_14-0/User-Guide/b_WSA_UserGuide_14_0/b_WSA_UserGuide_11_7_chapter_01011.html To bypass encrypted traffic having a good web reputation score, make sure that you disable the Decrypt for Application Detection option in the Decryption Options section of the HTTPS Proxy Settings page. ... Section: Bypassing Decryption for Particular Websites ... Create a Decryption Policy ....

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Correct answer: B — Disabling Decrypt Policies ensures that HTTPS traffic identified as having a good reputation score bypasses decryption. In Cisco WSA, Decrypt Policies are used to define which traffic is subject to inspection. By disabling these policies for specific criteria (like high reputation), the appliance allows the traffic to pass through without decrypting it, preserving privacy and performance for safe sites.

Why the Other Options Are Wrong

Options A, C, and D are incorrect for this specific requirement. A Decrypt ACL (Option A) is generally used to match traffic to apply a policy, but simply disabling an ACL does not inherently trigger a reputation-based bypass logic in the same direct manner as disabling the policy enforcement itself for those users/sites. Options C and D refer to user acknowledgment and notification features, which relate to user experience during interception, not the technical decision to bypass decryption based on reputation.

Community Comment Notes

Community consensus strongly supports Option B. As VirtuaTech noted, "Disabling specific decrypt policies allows traffic deemed safe... to bypass decryption altogether." Another commenter referenced the official guide, confirming that bypassing encrypted traffic with a good web reputation score involves managing these policy settings effectively.

Official Reference

Exam Strategy

When configuring WSA, distinguish between Access Control Lists (which permit/deny traffic) and Decryption Policies (which dictate inspection). For reputation-based bypasses, focus on how policies are applied or disabled for specific traffic profiles.

Frequently Asked Questions

Why not use Decrypt ACL for reputation bypass?

ACLs match traffic to policies but do not contain the reputation logic itself. Disabling the policy directly prevents inspection for matched traffic.

Does disabling Decrypt Policies affect security?

Yes, it reduces visibility. It should only be done for sites with verified good reputations to balance security and performance.

Related Analysis

← Back to 350-701 Study Guide