Cisco Secure Web Appliance Invalid Certificate Handling
Which parameter must be set for an invalid certificate handling on a Cisco Seucure Web Appliance with a policy for HTTPS traffic?
Community Votes
60% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The core concept tested is how SSL/TLS interception works; the common trap is confusing the security posture ('Reject') with the operational requirement for traffic analysis ('Decrypt').
This question addresses the configuration of HTTPS inspection on a Cisco Secure Web Appliance (WSA) regarding invalid certificates, specifically focusing on the 'Decrypt' parameter's role in enabling deep packet inspection.
Most users select 'Reject' because it seems like the most secure option, failing to realize that rejecting the connection prevents the appliance from scanning the content for threats.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
To perform effective web filtering and malware protection, the Cisco WSA must decrypt HTTPS traffic. The 'Decrypt' parameter is the setting that instructs the appliance to proceed with the decryption process even if the server certificate is invalid (e.g., self-signed or expired), allowing the traffic to be inspected further. Without decryption, the WSA cannot see the payload.Why the Other Options Are Wrong
'Reject' (Option B) would terminate the connection immediately upon detecting an invalid certificate, making inspection impossible. 'Accept' (Option C) might allow the traffic but could imply bypassing security checks or simply trusting the unverified identity without necessarily triggering the full decryption/inspection pipeline required for threat defense. 'Scan' (Option D) is not a standard parameter for certificate validation handling in this specific context.Community Comment Notes
Community members are divided between 'Decrypt' and 'Reject'. As user madboy2 noted, 'Reject' is often perceived as the 'most secure option', leading to confusion. However, expert analysis confirms that for the purpose of traffic analysis and policy enforcement, 'Decrypt' is the necessary functional parameter.Official Reference
Exam Strategy
When dealing with security appliances that inspect encrypted traffic, always prioritize the mechanism that enables visibility. If the goal is inspection/filtering, look for settings related to 'Decrypt' or 'Intercept' rather than just blocking.
Frequently Asked Questions
Why can't I just Reject invalid certificates?
Rejecting terminates the connection, preventing the WSA from scanning the content for malware or policy violations.
Does Decrypt ignore all certificate errors?
It allows the decryption process to continue for inspection, though specific trust policies may still apply.