Cisco CCNP Security Core (SCOR) 350-701Content SecurityEasy
A network security architect is designing a content security solution for a large enterprise that requires inspecting encrypted traffic for threats without compromising user privacy or application functionality. Which content security technology is best suited to achieve this by acting as a trusted intermediary?
- ANetwork Access Control (NAC)
- BSSL/TLS Inspection Proxy
- CFirewall with Application Visibility Control (AVC)
- DIntrusion Prevention System (IPS)
Show answer & explanationAnswer & explanation
Correct answer: B. SSL/TLS Inspection Proxy
An SSL/TLS Inspection Proxy is specifically designed to decrypt, inspect, and re-encrypt encrypted traffic, enabling content security devices to analyze the payload for threats. This process allows for deep packet inspection of otherwise opaque traffic flows.
Why the other options are wrong
- A. NAC focuses on endpoint compliance and authentication before network access is granted, not on inspecting content within encrypted traffic streams.
- C. While a firewall with AVC can identify applications, it generally cannot decrypt and inspect the content within encrypted sessions without a dedicated SSL/TLS inspection component.
- D. An IPS primarily detects and prevents known attacks based on signatures and behavioral analysis, but it typically does not decrypt SSL/TLS traffic itself.
SSL/TLS Inspection
The process of decrypting SSL/TLS encrypted traffic to inspect its contents for security threats, then re-encrypting it before forwarding.
- Enables deep packet inspection of encrypted data.
- Requires a trusted certificate authority.
- Can be resource-intensive.
Memory trick: Deciphering the secret message requires a trusted intermediary.