Cisco CCNP Security Core (SCOR) 350-701Content SecurityHard
A network security architect is designing a content security solution for a large enterprise. The design must ensure that all HTTP/HTTPS traffic is inspected for malware and sensitive data, even if the traffic is encrypted. The solution needs to integrate with existing Active Directory for user-based policies and provide granular reporting on web usage. Where should SSL decryption be performed in the content inspection flow to maximize effectiveness and minimize performance impact?
- AOn the endpoint device via a proxy agent.
- BOn a dedicated content security gateway after initial firewall filtering.
- CWithin the core network router after routing decisions.
- DAt the perimeter firewall before content inspection.
Show answer & explanationAnswer & explanation
Correct answer: B. On a dedicated content security gateway after initial firewall filtering.
Performing SSL decryption on a dedicated content security gateway after initial firewall filtering allows the firewall to handle basic access control and high-volume traffic, offloading resource-intensive decryption and deep content inspection to a specialized device. This optimizes performance and ensures comprehensive inspection of encrypted traffic.
Why the other options are wrong
- A. Endpoint decryption can be problematic for scalability, management, and user experience, and may not cover all traffic types.
- C. Decryption within a core network router is highly inefficient and not its primary function, leading to severe performance degradation.
- D. Decryption on the perimeter firewall can significantly impact its performance, as firewalls are typically optimized for fast packet forwarding and basic rule enforcement, not deep SSL inspection.
SSL Decryption Placement
Strategic placement of SSL decryption capabilities within the network to enable deep inspection of encrypted traffic for security threats or policy enforcement while minimizing performance impact on critical infrastructure.
- Decryption is resource-intensive and requires dedicated hardware/software.
- Best placed on specialized content security gateways (e.g., web proxy, NGFW with advanced capabilities).
- Typically occurs after basic firewalling but before deep content inspection.
Memory trick: Dedicated Gateway Deciphers, Deeply Inspects, Delivers Security.