Cisco CCNP Security Core (SCOR) 350-701Content SecurityMedium
A security engineer is configuring a Cisco Secure Web Appliance (WSA) to provide granular control over web traffic. The organization requires that users are allowed to access most social media sites but must be blocked from uploading any files to these sites. Which WSA feature should the engineer use to achieve this specific requirement?
- AURL Filtering with custom categories
- BData Loss Prevention (DLP) policies
- CAccess Policies with Application Visibility and Control (AVC)
- DHTTPS Inspection with certificate pinning
Show answer & explanationAnswer & explanation
Correct answer: C. Access Policies with Application Visibility and Control (AVC)
To control specific actions within web applications, such as file uploads to social media sites, Application Visibility and Control (AVC) is the appropriate feature on a Cisco WSA. URL filtering only allows or blocks entire sites, while DLP focuses on content of data, not the action itself. HTTPS inspection is a prerequisite for AVC but not the feature that enforces the control.
Why the other options are wrong
- A. URL Filtering allows blocking or permitting entire websites or categories, but not specific actions within them.
- B. DLP policies focus on identifying and preventing sensitive data from leaving the network, not controlling application actions like file uploads.
- D. HTTPS Inspection decrypts traffic for deeper analysis but is not the feature that enforces the application-level control.
WSA Application Control
Cisco Secure Web Appliance's Application Visibility and Control (AVC) feature enables granular control over specific functions within web applications, beyond just allowing or blocking the entire application.
- Controls specific actions (e.g., file upload, chat) within web apps.
- Requires HTTPS inspection for encrypted traffic.
- Integrated into Access Policies on WSA.
Memory trick: WSA's AVC gives you a magnifying glass for app actions.