Question 1
A financial services company is experiencing intermittent connectivity issues with a critical banking application that uses mutual TLS (mTLS) for client-server authentication. The issues began after deploying Edge SWG with full SSL interception. A policy trace reveals that the Edge SWG is attempting to intercept the traffic, causing the mTLS handshake to fail. Which configuration change is the most effective and secure method to resolve this issue?
Answer and explanation
Correct answer: C
Mutual TLS (mTLS) requires both the client and server to present valid certificates. SSL interception breaks this process because the Edge SWG presents its own emulated certificate to the client. The correct solution is to bypass interception for this specific traffic. Using the Server Certificate Common Name in the SSL Interception Layer is a precise and secure way to create this bypass, ensuring only the intended application traffic is excluded from inspection. Installing the client's private key on the proxy is a significant security risk, and disabling protocol detection is too broad and may have unintended consequences.