Cisco CCNP Security Core (SCOR) 350-701Content SecurityMedium

A security engineer is configuring a Cisco Secure Web Appliance (WSA) to enforce strict acceptable use policies and block access to specific categories of websites (e.g., gambling, adult content). The organization also needs to ensure that users cannot bypass these policies by using anonymizing proxies. Which two WSA features, when used together, are most effective for these requirements?

  1. AThreat Intelligence and Security Intelligence Feeds
  2. BAdvanced Malware Protection (AMP) and File Reputation
  3. CWeb Caching and Bandwidth Management
  4. DURL Filtering and Application Visibility and Control (AVC)
Show answer & explanation

Correct answer: D. URL Filtering and Application Visibility and Control (AVC)

URL Filtering is essential for blocking websites based on categories like gambling or adult content. Application Visibility and Control (AVC) can identify and block anonymizing proxy applications, preventing users from bypassing URL filtering policies.

Why the other options are wrong

  • A. Threat Intelligence and Security Intelligence Feeds block known malicious IPs/URLs, which is different from blocking entire categories or specific bypass applications.
  • B. AMP and File Reputation focus on malware detection in files, not on URL categories or anonymizing proxies.
  • C. Web Caching and Bandwidth Management are performance optimization features, not security controls for website categories or anonymizing proxies.

WSA URL Filtering & AVC

Cisco WSA's URL Filtering blocks web categories, and its Application Visibility and Control (AVC) identifies and manages specific applications, including those used for policy evasion.

  • URL Filtering uses reputation and categorization databases.
  • AVC identifies applications independent of port.
  • Together, they enforce web policies and prevent bypasses.

Memory trick: Filter the URLs, Control the Apps to prevent ghosts.

More Content Security questions