WSA HTTPS Reputation Bypass Decryption
What must be disabled on a Cisco Secure Web Appliance to ensure HTTPS traffic with a good reputation score bypasses decryption?
Community Votes
100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The core trap is confusing policy-level control with access-list filtering; you must disable the Decrypt Policy itself to allow traffic with a good reputation score to pass undecrypted.
This question tests how to configure Cisco Secure Web Appliance (WSA) to bypass SSL decryption for trusted sites. The correct configuration relies on disabling specific Decrypt Policies rather than global ACLs.
Candidates often select 'Decrypt ACL' because it sounds like a filter, but ACLs in WSA typically determine if a policy applies or if traffic is allowed/denied, not specifically the reputation-based bypass mechanism described here.
Community Discussion (5 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Correct answer: B — Disabling Decrypt Policies ensures that HTTPS traffic identified as having a good reputation score bypasses decryption. In Cisco WSA, Decrypt Policies are used to define which traffic is subject to inspection. By disabling these policies for specific criteria (like high reputation), the appliance allows the traffic to pass through without decrypting it, preserving privacy and performance for safe sites.Why the Other Options Are Wrong
Options A, C, and D are incorrect for this specific requirement. A Decrypt ACL (Option A) is generally used to match traffic to apply a policy, but simply disabling an ACL does not inherently trigger a reputation-based bypass logic in the same direct manner as disabling the policy enforcement itself for those users/sites. Options C and D refer to user acknowledgment and notification features, which relate to user experience during interception, not the technical decision to bypass decryption based on reputation.Community Comment Notes
Community consensus strongly supports Option B. As VirtuaTech noted, "Disabling specific decrypt policies allows traffic deemed safe... to bypass decryption altogether." Another commenter referenced the official guide, confirming that bypassing encrypted traffic with a good web reputation score involves managing these policy settings effectively.Official Reference
Exam Strategy
When configuring WSA, distinguish between Access Control Lists (which permit/deny traffic) and Decryption Policies (which dictate inspection). For reputation-based bypasses, focus on how policies are applied or disabled for specific traffic profiles.
Frequently Asked Questions
Why not use Decrypt ACL for reputation bypass?
ACLs match traffic to policies but do not contain the reputation logic itself. Disabling the policy directly prevents inspection for matched traffic.
Does disabling Decrypt Policies affect security?
Yes, it reduces visibility. It should only be done for sites with verified good reputations to balance security and performance.