exam questions

Exam 350-701 All Questions

View all questions & answers for the 350-701 exam

Exam 350-701 topic 1 question 197 discussion

Actual exam question from Cisco's 350-701
Question #: 197
Topic #: 1
[All 350-701 Questions]

What are two differences between a Cisco WSA that is running in transparent mode and one running in explicit mode? (Choose two.)

  • A. The Cisco WSA responds with its own IP address only if it is running in explicit mode.
  • B. The Cisco WSA is configured in a web browser only if it is running in transparent mode.
  • C. The Cisco WSA responds with its own IP address only if it is running in transparent mode.
  • D. The Cisco WSA uses a Layer 3 device to redirect traffic only if it is running in transparent mode.
  • E. When the Cisco WSA is running in transparent mode, it uses the WSA's own IP address as the HTTP request destination.
Show Suggested Answer Hide Answer
Suggested Answer: AD 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
wfexco
Highly Voted 3 years, 11 months ago
A and D are correct. - In explicit proxy mode, users are configured to use a web proxy and the web traffic is sent directly to the Cisco WSA. In contrast, in transparent proxy mode the Cisco WSA intercepts user's web traffic redirected from other network devices, such as switches, routers, or firewalls.
upvoted 21 times
...
Sarbi
Highly Voted 3 years, 9 months ago
A and D is correct. No doubt it.
upvoted 5 times
...
Premium_Pils
Most Recent 9 months, 1 week ago
Selected Answer: AD
I am sure about "D" as a the traffic is redirected on a L3 device with PBR (or similar solution). "A" would be fine without the word "only". The WSA is a full proxy, maintaining separate sessions btw. client - proxy and proxy - webserver. The source IP of the response is surely the ip of the proxy in the client-proxy connection with Explicit mode, when the client directly communicates with the proxy. However, I am not sure the redirected Transparent mode, as again the proxy is sitting in between the client and the webserver. I assume that the client does not get the response directly from the webserver, but rather from the proxy. So the source ip should be from the proxy (or does it spoof the source ip?).
upvoted 1 times
...
squirrelzzz
1 year, 2 months ago
Selected Answer: AD
Transparent means it has no L3 interface
upvoted 1 times
...
Leogxn
1 year, 10 months ago
Selected Answer: CD
Reference: CCNP And CCIE Security Core SCOR 350-701 Official Cert Guide-> Therefore in Transparent mode, WSA uses its own lP address to initiate a new connection the Web Server
upvoted 1 times
Bubu3k
9 months, 3 weeks ago
The only problem is that that quote is nowhere in the OCG... It's AD: actual quote from the OCG: "When the Cisco WSA (as a web proxy) forwards a request, by default it changes the request source IP address to match its own address."
upvoted 2 times
...
...
andrewj511
3 years, 8 months ago
When requests are being redirected to the WSA transparently, the WSA must pretend to be the OCS (origin content server), since the client is unaware of the existence of a proxy. On the contrary, if a request is explicitly sent to the WSA, the WSA will respond with it's own IP information.
upvoted 4 times
...
rad9899
4 years ago
C&E is correct https://www.cisco.com/c/en/us/support/docs/security/web-security-appliance/117940-qa-wsa-00.html
upvoted 1 times
entitty
3 years, 11 months ago
Not C, But A - leaning toward D (wish it stated Layer4) When requests are being redirected to the WSA transparently, the WSA must pretend to be the OCS (origin content server), since the client is unaware of the existence of a proxy. On the contrary, if a request is explicitly sent to the WSA, the WSA will respond with it's own IP information.
upvoted 4 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago