Cisco CCNP Security Core (SCOR) 350-701Content SecurityMedium

A large organization is implementing a content security strategy across its global network. They need to ensure consistent security policies are applied to all web traffic, regardless of user location (on-premise, remote, or branch office), and that threat intelligence is shared in real-time across all security enforcement points. Which architectural approach best addresses these requirements?

  1. AVPN-centric access with centralized firewalls
  2. BDecentralized security appliances at each location
  3. CCloud-native Secure Web Gateway (SWG)
  4. DTraditional on-premise proxy servers
Show answer & explanation

Correct answer: C. Cloud-native Secure Web Gateway (SWG)

A cloud-native Secure Web Gateway (SWG) provides consistent web security policies and real-time threat intelligence regardless of user location by routing all web traffic through a cloud-based security service. This aligns with modern SASE principles for distributed workforces.

Why the other options are wrong

  • A. While VPNs provide secure access, they typically backhaul all traffic to a central point, which can introduce latency and doesn't inherently provide consistent web content security policies at the edge for remote users without additional SWG capabilities.
  • B. Decentralized appliances can lead to inconsistent policies and fragmented threat intelligence across locations, increasing management overhead.
  • D. Traditional on-premise proxy servers are not designed for a distributed workforce and would not provide consistent security or real-time threat intelligence for remote users.

Cloud-Native Secure Web Gateway (SWG)

A security service delivered from the cloud that protects users from web-based threats and enforces internet use policies, regardless of location.

  • Provides consistent web security for all users.
  • Leverages cloud scalability and global presence.
  • Often integrates with other SASE components.

Memory trick: Cloud-SWG: Global Security, Unified Policies, Real-time Intelligence.

More Content Security questions