Cisco Secure Web Appliance Deployment Modes Comparison

Select management options for network security solutions (single vs. multidevice manager, in-band vs. out-of-band, on-premises vs. cloud with Cisco Security Cloud Control)
Answer Correct answer: B, D — Onsite web proxy and Layer 4 traffic monitoring are not supported in Cloud Web Security Connector mode.

Which two facts must be considered when deciding whether to deploy the Cisco Secure Web Appliance in Standard mode, Hybrid Web Security mode, or Cloud Web Security Connector mode? (Choose two.)

  1. External DLP is available only in Standard mode and Hybrid Web Security mode.
  2. The onsite web proxy is not supported in Cloud Web Security Connector mode. Correct Answer
  3. Standard mode and Hybrid Web Security mode perform the same actions in response to the application of an individual policy.
  4. Only Standard mode and Hybrid Web Security mode support Layer 4 traffic monitoring. Correct Answer
  5. ISE integration is available only in Standard mode and Hybrid Web Security mode.

Community Votes

BD
75%
AB
25%

75% of anonymous learners picked answer BD. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The exam tests your ability to distinguish feature availability across deployment models, specifically identifying that cloud-only modes lack local hardware acceleration features like Layer-4 monitoring.

This question examines the key differences between Cisco Secure Web Appliance (SWA) Standard, Hybrid, and Cloud modes. It establishes that on-site proxy and Layer-4 monitoring capabilities are exclusive to on-premises deployments.

Candidates often incorrectly select options regarding DLP or ISE integration because they assume these enterprise features are tied strictly to the 'on-prem' vs 'cloud' dichotomy rather than specific appliance capabilities.

Community Discussion (4 comments)

ITVI 👍 1 Selected: BD
Standard Mode: On-site web proxy and Layer-4 traffic monitoring are available. Offers External Data Loss Prevention (DLP) capabilities. Supports ISE integration. Requires physical or virtual appliance deployment. Hybrid Mode: Combines SWA with Cisco Umbrella SIG for policy synchronization. Enforces the same web policies across on-premises and cloud environments. Offers granular policy management through Umbrella SIG. Requires both SWA and Cisco Umbrella SIG. Cloud Web Security Connector: Routes traffic to a CWS proxy for policy enforcement. On-site web proxy and Layer-4 traffic monitoring are not available. Requires no on-site appliance. Does not support native FTP or HTTPS decryption.
aa4a63c 👍 2 Selected: BD
Deployment of the appliance is the same in both standard and Cloud Security mode except that on-site web proxy services and Layer-4 Traffic Monitorservices are not available in Cloud WebSecurity Connector mode.
madboy2 👍 1 Selected: AB
A. External DLP is available only in Standard mode and Hybrid Web Security mode. Data Loss Prevention (DLP) is a critical security feature that monitors and prevents sensitive data exfiltration. External DLP integration (e.g., with third-party DLP solutions) is only supported in Standard Mode and Hybrid Web Security Mode. Cloud Web Security Connector Mode does not support external DLP since it relies on Cisco's cloud-based security services. B. The onsite web proxy is not supported in Cloud Web Security Connector mode. Cloud Web Security Connector Mode forwards web traffic directly to Cisco Umbrella or Cisco Cloud Web Security (CWS), bypassing on-premise proxies. No local proxy is used in this mode because all security processing happens in the cloud. In Standard Mode and Hybrid Mode, the WSA acts as a local proxy for deeper content inspection and policy enforcement.
3ab324f 👍 1
BC with reference to: https://www.cisco.com/c/en/us/td/docs/security/wsa/wsa11-0/user_guide/b_WSA_UserGuide/b_WSA_UserGuide_chapter_01000.pdf Deployment of the appliance is the same in both standard and Cloud Security mode except that on-site web proxy services and Layer-4 Traffic Monitor services are not available in Cloud Web Security Connector mode.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The correct options are B and D. According to Cisco documentation for the Secure Web Appliance (WSA), the Cloud Web Security Connector mode is designed to offload web security to the cloud (Umbrella). Consequently, it does not support onsite web proxy services (Option B) because traffic is redirected to the cloud, nor does it support Layer 4 traffic monitoring (Option D) which relies on local inspection engines. Standard and Hybrid modes run locally and thus support both.

Why the Other Options Are Wrong

Option A is incorrect because External DLP can be configured in various modes depending on the third-party integration; it is not exclusively limited to Standard/Hybrid in a way that defines the deployment choice against Cloud. Option C is false because while policies may synchronize, the enforcement points differ significantly (local vs. cloud). Option E is incorrect because ISE integration is primarily used for authentication and profiling, which can be supported via different mechanisms in cloud modes or is not a primary differentiator for the deployment architecture itself compared to the hard limitations of proxy/L4 monitoring.

Community Comment Notes

Commenters generally agree that the distinction lies in what the appliance can do locally. One user noted, "Deployment of the appliance is the same... except that on-site web proxy services and Layer-4 Traffic Monitor services are not available in Cloud Web Security Connector mode." This aligns perfectly with the official differentiation.

Official Reference

Exam Strategy

When comparing deployment modes, focus on what is lost or gained by moving to the cloud. If an option mentions a hardware-accelerated or local processing feature (like Layer 4 monitoring or local proxying), it is likely unavailable in a pure cloud connector mode.

Frequently Asked Questions

What is the main difference between Hybrid and Cloud Web Security Connector?

Hybrid mode uses an on-prem appliance for caching and inspection while syncing policies with Umbrella. Cloud Connector redirects all traffic to Umbrella without local inspection.

Can I use Layer 4 traffic monitors in Cloud Web Security Connector?

No, Layer 4 traffic monitoring requires local packet inspection which is not performed in Cloud Connector mode as traffic is tunneled to the cloud.

Related Analysis

← Back to 350-701 Study Guide