300-415 Question 229
Single answerA financial organization is deploying Cisco SD-WAN and wants to inspect encrypted traffic for potential threats and policy enforcement. The organization needs to ensure that SSL/TLS traffic can be decrypted, inspected, and re-encrypted without compromising security. Which feature of Cisco SD-WAN should be implemented to fulfill this requirement?
- A
SSL/TLS Proxy
- B
Application-aware Routing
- C
Zero Trust Security Model
- D
Direct Internet Access (DIA)
Show answer and explanation
Correct answer: A
Explanation
The SSL/TLS Proxy feature in Cisco SD-WAN enables encrypted traffic to be decrypted, inspected for threats, and re-encrypted before being forwarded. This is essential for organizations that require deep packet inspection and detailed policy enforcement on encrypted communication. Other options like Application-aware Routing, Zero Trust Security Model, and DIA address different aspects of SD-WAN functionality but do not provide the required SSL/TLS traffic inspection capability.
- A. Correct.
SSL/TLS Proxy is the correct feature for decrypting, inspecting, and re-encrypting encrypted traffic within Cisco SD-WAN. It plays a critical role in applying security policies and detecting threats in encrypted communication.
- B. Incorrect.
Application-aware Routing is used for intelligently routing traffic based on application performance requirements and SLA policies but does not handle SSL/TLS decryption and inspection.
- C. Incorrect.
Zero Trust Security Model focuses on ensuring that all devices and users are authenticated and verified before granting access to the network, but it does not provide SSL/TLS decryption and re-encryption capabilities.
- D. Incorrect.
Direct Internet Access (DIA) allows branch sites to access the internet directly without backhauling traffic through a data center, but it does not involve SSL/TLS decryption or inspection.