Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco 350-701 Exam - Topic 15 Question 69 Discussion

An engineer enabled SSL decryption for Cisco Umbrella intelligent proxy and needs to ensure that traffic is inspected without alerting end-users. Which action accomplishes this goal?
D) Install the Cisco Umbrella root CA onto the user's device.
A) Restrict access to only websites with trusted third-party signed certificates.
B) Modify the user's browser settings to suppress errors from Cisco Umbrella.
C) Upload the organization root CA to Cisco Umbrella.

Cisco 350-701 Exam - Topic 15 Question 69 Discussion

Actual exam question for Cisco's 350-701 exam
Question #: 69
Topic #: 15
[All 350-701 Questions]

An engineer enabled SSL decryption for Cisco Umbrella intelligent proxy and needs to ensure that traffic is inspected without alerting end-users. Which action accomplishes this goal?

Show Suggested Answer Hide Answer
Suggested Answer: D

Contribute your Thoughts:

0/2000 characters
Lea
10 months ago
A is too limiting, we need flexibility with sites.
upvoted 0 times
...
Jerry
10 months ago
I’m not sure about D, isn’t that a bit invasive?
upvoted 0 times
...
Omer
10 months ago
Wait, why would we suppress errors? Sounds risky.
upvoted 0 times
...
Gilberto
11 months ago
Definitely agree with C! Makes the most sense.
upvoted 0 times
...
Johna
11 months ago
I think option C is the right move here.
upvoted 0 times
...
Delfina
11 months ago
I’m uncertain, but I think restricting access to trusted sites might not fully suppress alerts. It seems like a partial solution.
upvoted 0 times
...
Lavera
11 months ago
I feel like modifying browser settings could lead to issues later on. I’d lean towards installing the CA on the user's device instead.
upvoted 0 times
...
Nickole
11 months ago
I think we practiced a similar question where uploading a CA was involved. It might be option C, but I can't recall the details.
upvoted 0 times
...
Chaya
11 months ago
I remember something about needing a root CA for SSL inspection, but I'm not sure if it's the organization's or the user's device.
upvoted 0 times
...
Alease
11 months ago
This is a good test of my JVM knowledge. I'll go with A and C to cover the basics.
upvoted 0 times
...
Shaquana
11 months ago
Okay, let me think this through. The pattern starts with ^ and ends with $, so it's matching the entire string. The \d+ part matches one or more digits, and the (?:\.[0-9]+)? part matches an optional decimal portion.
upvoted 0 times
...
Twana
11 months ago
Easy peasy! getElementById() is the way to go for this type of targeted element access.
upvoted 0 times
...
Kattie
11 months ago
Okay, I think I've got this. The key is to find a way to optimize the bandwidth usage without increasing it on the WAN links.
upvoted 0 times
...
Yesenia
11 months ago
This question is testing our understanding of service-oriented architecture principles. Based on the information provided, I believe the correct answer is A - True. The passage clearly states that the ability to continually recompose services is fundamental to service-orientation, which requires a composition-centric architecture.
upvoted 0 times
...
Lindsey
11 months ago
I recall a practice question that emphasized the importance of consistent data models in XML communication. That makes me think it's true.
upvoted 0 times
...
Leota
11 months ago
Okay, I've got an idea. "Stop-loss" sounds like it could be the right answer, since that's a common way for providers to cap their financial liability. I'll go with that unless I can think of a better option.
upvoted 0 times
...
Reyes
1 year ago
Trying to hide SSL decryption from users? Sounds like someone's trying to pull a fast one. Option C is the way to go, but I'm keeping an eye on you!
upvoted 0 times
Emiko
1 year ago
Let's make sure everything is done properly and transparently to avoid any suspicion.
upvoted 0 times
...
Huey
1 year ago
I agree, it's important to ensure traffic is inspected without alerting anyone.
upvoted 0 times
...
Renea
1 year ago
Option C is definitely the way to go to hide SSL decryption from end-users.
upvoted 0 times
...
...
Maryln
1 year ago
Restricting access to only trusted third-party websites? What is this, the 90s? Option C is the clear winner here.
upvoted 0 times
...
Malinda
1 year ago
Oh, man, I remember the days of having to install root CAs on every user's device. Talk about a headache! Option C is the way to go for sure.
upvoted 0 times
...
Tawna
1 year ago
I'm not sure why anyone would want to suppress errors from Cisco Umbrella. That just sounds like a recipe for disaster. Option D is the way to go.
upvoted 0 times
Lashon
1 year ago
Yes, but it will also ensure that traffic is inspected without alerting end-users.
upvoted 0 times
...
Nilsa
1 year ago
Restricting access to only websites with trusted third-party signed certificates could also work, but installing the Cisco Umbrella root CA seems like the most secure option.
upvoted 0 times
...
Charlette
1 year ago
But won't that prevent end-users from being alerted to potential security risks?
upvoted 0 times
...
Yuki
1 year ago
I agree, that way the end-users won't be alerted and the traffic can still be inspected. It's a win-win.
upvoted 0 times
...
Dalene
1 year ago
Option D is definitely the best choice. Installing the Cisco Umbrella root CA onto the user's device ensures that traffic is inspected without alerting end-users.
upvoted 0 times
...
Dorothy
1 year ago
Option D: Enable the 'Block Page Bypass' feature in the Cisco Umbrella intelligent proxy settings.
upvoted 0 times
...
...
Nu
1 year ago
Option C seems like the right choice here. Uploading the organization's root CA to Cisco Umbrella will allow the traffic to be inspected without any issues for the end-users.
upvoted 0 times
Kris
1 year ago
C) Upload the organization root CA to Cisco Umbrella.
upvoted 0 times
...
Tonja
1 year ago
A) Restrict access to only websites with trusted third-party signed certificates.
upvoted 0 times
...
...
Ilona
1 year ago
I'm not sure, but I think A) Restrict access to only websites with trusted third-party signed certificates could also be a valid option.
upvoted 0 times
...
Micah
1 year ago
I agree with Laura. By uploading the organization root CA, the traffic can be inspected without alerting end-users.
upvoted 0 times
...
Laura
1 year ago
I think the answer is C) Upload the organization root CA to Cisco Umbrella.
upvoted 0 times
...

Save Cancel