BCCPP Blue Coat Certified Proxysg Professional Practice Questions
Prepare for BCCPP with more than an answer.
- Exam fee
- $125 USD
- Time limit
- 120 minutes
- Questions on the exam
- Variable
- Passing score
- 70%
- Level
- Professional
- Valid for
- 2 years
Domains covered on the exam 7
- SGOS Architecture15%
- System Diagnostics and Monitoring15%
- Content Policy Language (CPL)20%
- Policy Management and Tracing15%
- Advanced Authentication15%
- SSL Proxy and Encrypted Traffic10%
- ProxySG Integration10%
- 1
What is the primary function of the
early interceptfeature in a ProxySG service listener?Show answer details
Correct answer: C
Early intercept is a crucial feature for transparent deployments. When a connection arrives at a listener with this feature enabled, the ProxySG intercepts it immediately at the TCP level. It then uses protocol detection to determine the nature of the traffic (e.g., HTTP, SSL, FTP). Based on the detected protocol, it hands the connection off to the appropriate internal proxy service for handling. This allows a single listener (e.g., on port 80) to correctly process multiple protocols without requiring the client to be explicitly configured for a specific proxy protocol.
- 2
A manufacturing company has integrated its ProxySG with a Symantec Content Analysis System (CAS) for malware scanning. The security policy requires that all files identified by CAS as malicious be blocked, and an alert must be sent to the security operations center (SOC). Which of the following are required to implement this solution? (Select THREE)
Show answer details
Correct answer: A, B, C
- 3
True or False: The ProxySG object store maintains a separate cache for each network protocol it proxies (e.g., a distinct HTTP cache, FTP cache, and SOCKS cache).
Show answer details
Correct answer: B
This statement is false. The SGOS object store is a unified caching system. It does not segregate cached objects based on the protocol used to retrieve them. An object retrieved via HTTP can be served to a subsequent FTP request if the URL and object are identical. This unified approach maximizes caching efficiency by preventing redundant storage of the same object fetched via different protocols.
- 4
Case Study:
Global Retail Inc. is deploying ProxySG appliances at its main data center to act as a reverse proxy for its e-commerce platform. The platform consists of multiple web servers (OCS) that serve both static content (images, CSS) and dynamic content (shopping cart, user accounts). The primary goals are to improve performance for global customers, offload SSL processing from the web servers, and protect against web application attacks.
The current setup involves a simple round-robin DNS for load balancing, which provides no health checking or session persistence. The security team is concerned about SSL vulnerabilities on the web servers and wants all client-facing SSL to be terminated at the network edge. The e-commerce application requires that once a user's session is established with a particular web server, all subsequent requests from that user for the duration of their session are sent to the same server.
Which ProxySG configuration best meets all of Global Retail's requirements?
graph TD subgraph Internet User1[User in USA] User2[User in Europe] end subgraph DataCenter_Edge ProxySG[ProxySG Appliance] end subgraph Web_Farm OCS1[Web Server 1] OCS2[Web Server 2] OCS3[Web Server 3] end User1 --> ProxySG User2 --> ProxySG ProxySG --> OCS1 ProxySG --> OCS2 ProxySG --> OCS3Show answer details
Correct answer: D
This solution addresses all requirements. Configuring as a reverse proxy with SSL termination achieves the SSL offload goal. A forwarding host group with health checks provides robust load balancing, taking servers out of rotation if they fail. The 'source-ip-hash' algorithm is a built-in method to provide session persistence by ensuring requests from the same client IP are always sent to the same OCS. Finally, aggressive caching of static content will significantly improve performance. This is the most comprehensive and best-practice approach among the options.
- 5
An administrator needs to create a policy that prevents users from posting content to any website categorized as 'Social Networking', except for the corporate account on
linkedin.com. How should this be constructed in CPL?Show answer details
Correct answer: B
This CPL snippet correctly implements the logic. It creates a rule that matches on three conditions simultaneously: the request's category is 'Social Networking', the URL domain is NOT
linkedin.com, and the HTTP method is POST. Only if all three conditions are true will the DENY action be triggered. This effectively blocks posts to all social networking sites while allowing them for the specified exception. - 6
A financial services company is using a ProxySG in explicit mode. To comply with new regulations, all outbound traffic to known financial partner APIs must be logged with full transaction details, while traffic to all other destinations must have user-identifying information stripped from the access logs. An existing global policy layer already sets the logging level for all traffic. How should an administrator configure the Visual Policy Manager (VPM) to meet this requirement without disrupting the existing logging policy for general traffic?
Show answer details
Correct answer: C
The correct approach is to create a new, more specific Web Access Layer that is evaluated before the general, global logging layer. By placing the new layer above the existing one, its rules are processed first. A rule matching the specific financial partner APIs can then apply the detailed logging action. Since policy evaluation stops at the first match within a layer for a given action, no further rules are needed in this new layer for other traffic; the request will simply 'fall through' to the next layer (the global one) which handles the logging for all other traffic.
- 7
An administrator is troubleshooting a Kerberos authentication issue where users are intermittently failing to authenticate through the ProxySG. A packet capture on the ProxySG shows that for failed requests, the KDC is returning a
KRB5KDC_ERR_PREAUTH_REQUIREDerror, even though the client's browser is configured correctly for Integrated Windows Authentication. The same users can authenticate successfully when bypassing the proxy. Which ProxySG configuration is the most likely cause of this issue?Show answer details
Correct answer: C
Kerberos is highly sensitive to time synchronization. A time skew of more than five minutes (by default) between the client (in this case, the ProxySG acting on behalf of the user) and the KDC will cause authentication to fail. The KDC error
KRB5KDC_ERR_PREAUTH_REQUIREDcan be misleading, but it is a common symptom of time synchronization problems, as the timestamp in the authenticator of the AS-REQ packet will be considered invalid by the KDC. Since users can authenticate when bypassing the proxy, the issue lies with the proxy's interaction with the KDC, making time skew the most probable cause. - 8
A network architect is designing a solution for a geographically distributed enterprise. The goal is to reduce latency for web objects that are frequently updated, such as pricing information and news articles. The architect wants to ensure that users always receive the most current version of an object without creating excessive validation traffic to the origin content servers (OCS). Which caching directive, when set in a CPL policy, best achieves this balance?
Show answer details
Correct answer: D
The
cache.ttl_if_fresher_than(seconds)directive provides an excellent balance for frequently updated content. It instructs the ProxySG to serve the cached object if it is fresher than the specified time (e.g., 300 seconds), but to revalidate it with the OCS if it's older. This avoids constant revalidation for very fresh content (reducing OCS load) while ensuring that content that is likely stale gets checked, thus providing users with up-to-date information without the overhead of checking every single time (always) or relying on potentially long minimum TTLs. - 9
True or False: When using the
ssl.forward_proxy(https)action to intercept SSL traffic, the ProxySG uses the Common Name (CN) from the origin server's certificate to dynamically generate a new certificate, which is then signed by the CA certificate specified in the SSL Interception settings.Show answer details
Correct answer: A
This statement is true. During SSL interception, the ProxySG acts as a man-in-the-middle. It establishes a secure session with the origin server, inspects its certificate, and then creates a new certificate on-the-fly. This new certificate emulates the identity of the origin server by copying key fields like the Common Name (CN) and Subject Alternative Name (SAN). This emulated certificate is then signed by the CA certificate installed on the ProxySG and presented to the client browser to establish the client-side secure session.
- 10
A company has a policy to block executable file downloads. The administrator has created a CPL rule using a File Extension object for
.exe. However, users are still able to download executables that have been renamed with a.txtextension. To prevent this, the administrator wants to inspect the actual content of the file. Which TWO of the following policy objects should be used in combination to achieve this? (Select TWO)Show answer details
Correct answer: B, F
