Cisco Secure Web Appliance Invalid Certificate Handling

Configure Cisco Secure Access Secure Internet Access
Answer Correct answer: A — The Decrypt parameter must be set to allow the Cisco Secure Web Appliance to intercept and inspect HTTPS traffic despite invalid certificates.

Which parameter must be set for an invalid certificate handling on a Cisco Seucure Web Appliance with a policy for HTTPS traffic?

  1. Decrypt Correct Answer
  2. Reject
  3. Accept
  4. Scan

Community Votes

A
60%
C
20%
B
20%

60% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The core concept tested is how SSL/TLS interception works; the common trap is confusing the security posture ('Reject') with the operational requirement for traffic analysis ('Decrypt').

This question addresses the configuration of HTTPS inspection on a Cisco Secure Web Appliance (WSA) regarding invalid certificates, specifically focusing on the 'Decrypt' parameter's role in enabling deep packet inspection.

Most users select 'Reject' because it seems like the most secure option, failing to realize that rejecting the connection prevents the appliance from scanning the content for threats.

Community Discussion (3 comments)

madboy2 👍 1 Selected: B
When configuring a Cisco Secure Web Appliance (formerly Cisco Web Security Appliance - WSA) with a policy for HTTPS traffic, you need to define how the appliance should handle invalid certificates during HTTPS inspection. 🔹 Reject: If a certificate is invalid (expired, mismatched, or otherwise untrusted), the appliance will reject the connection. This is the most secure option, as it prevents potentially malicious traffic from proceeding.
Pierre_Bouvier 👍 1 Selected: C
In the context of invalid certificate handling on the Cisco Secure Web Appliance, the Accept option is used to allow the HTTPS connection to continue even if the certificate is invalid. This option is configured in a way that allows the WSA to handle cases where certificates are not fully trusted or are expired but still allow the connection to proceed.
97c291d 👍 3 Selected: A
https://www.cisco.com/c/en/us/td/docs/security/wsa/wsa-14-5/user-guide/wsa-userguide-14-5/b_WSA_UserGuide_11_7_chapter_01011.html

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

To perform effective web filtering and malware protection, the Cisco WSA must decrypt HTTPS traffic. The 'Decrypt' parameter is the setting that instructs the appliance to proceed with the decryption process even if the server certificate is invalid (e.g., self-signed or expired), allowing the traffic to be inspected further. Without decryption, the WSA cannot see the payload.

Why the Other Options Are Wrong

'Reject' (Option B) would terminate the connection immediately upon detecting an invalid certificate, making inspection impossible. 'Accept' (Option C) might allow the traffic but could imply bypassing security checks or simply trusting the unverified identity without necessarily triggering the full decryption/inspection pipeline required for threat defense. 'Scan' (Option D) is not a standard parameter for certificate validation handling in this specific context.

Community Comment Notes

Community members are divided between 'Decrypt' and 'Reject'. As user madboy2 noted, 'Reject' is often perceived as the 'most secure option', leading to confusion. However, expert analysis confirms that for the purpose of traffic analysis and policy enforcement, 'Decrypt' is the necessary functional parameter.

Official Reference

Exam Strategy

When dealing with security appliances that inspect encrypted traffic, always prioritize the mechanism that enables visibility. If the goal is inspection/filtering, look for settings related to 'Decrypt' or 'Intercept' rather than just blocking.

Frequently Asked Questions

Why can't I just Reject invalid certificates?

Rejecting terminates the connection, preventing the WSA from scanning the content for malware or policy violations.

Does Decrypt ignore all certificate errors?

It allows the decryption process to continue for inspection, though specific trust policies may still apply.

Related Analysis

← Back to 350-701 Study Guide