Blue Coat Certified Proxysg Professional Free Sample Questions

20 free sample questions220 in the full practice test

Try simulator

BCCPP Sample Questions

  1. Question 1

    A financial services company is using a ProxySG in explicit mode. To comply with new regulations, all outbound traffic to known financial partner APIs must be logged with full transaction details, while traffic to all other destinations must have user-identifying information stripped from the access logs. An existing global policy layer already sets the logging level for all traffic. How should an administrator configure the Visual Policy Manager (VPM) to meet this requirement without disrupting the existing logging policy for general traffic?

    Answer and explanation

    Correct answer: C

    The correct approach is to create a new, more specific Web Access Layer that is evaluated before the general, global logging layer. By placing the new layer above the existing one, its rules are processed first. A rule matching the specific financial partner APIs can then apply the detailed logging action. Since policy evaluation stops at the first match within a layer for a given action, no further rules are needed in this new layer for other traffic; the request will simply 'fall through' to the next layer (the global one) which handles the logging for all other traffic.

  2. Question 2

    An administrator is troubleshooting a Kerberos authentication issue where users are intermittently failing to authenticate through the ProxySG. A packet capture on the ProxySG shows that for failed requests, the KDC is returning a KRB5KDC_ERR_PREAUTH_REQUIRED error, even though the client's browser is configured correctly for Integrated Windows Authentication. The same users can authenticate successfully when bypassing the proxy. Which ProxySG configuration is the most likely cause of this issue?

    Answer and explanation

    Correct answer: C

    Kerberos is highly sensitive to time synchronization. A time skew of more than five minutes (by default) between the client (in this case, the ProxySG acting on behalf of the user) and the KDC will cause authentication to fail. The KDC error KRB5KDC_ERR_PREAUTH_REQUIRED can be misleading, but it is a common symptom of time synchronization problems, as the timestamp in the authenticator of the AS-REQ packet will be considered invalid by the KDC. Since users can authenticate when bypassing the proxy, the issue lies with the proxy's interaction with the KDC, making time skew the most probable cause.

  3. Question 3

    A network architect is designing a solution for a geographically distributed enterprise. The goal is to reduce latency for web objects that are frequently updated, such as pricing information and news articles. The architect wants to ensure that users always receive the most current version of an object without creating excessive validation traffic to the origin content servers (OCS). Which caching directive, when set in a CPL policy, best achieves this balance?

    Answer and explanation

    Correct answer: D

    The cache.ttl_if_fresher_than(seconds) directive provides an excellent balance for frequently updated content. It instructs the ProxySG to serve the cached object if it is fresher than the specified time (e.g., 300 seconds), but to revalidate it with the OCS if it's older. This avoids constant revalidation for very fresh content (reducing OCS load) while ensuring that content that is likely stale gets checked, thus providing users with up-to-date information without the overhead of checking every single time (always) or relying on potentially long minimum TTLs.

  4. Question 4

    True or False: When using the ssl.forward_proxy(https) action to intercept SSL traffic, the ProxySG uses the Common Name (CN) from the origin server's certificate to dynamically generate a new certificate, which is then signed by the CA certificate specified in the SSL Interception settings.

    Answer and explanation

    Correct answer: A

    This statement is true. During SSL interception, the ProxySG acts as a man-in-the-middle. It establishes a secure session with the origin server, inspects its certificate, and then creates a new certificate on-the-fly. This new certificate emulates the identity of the origin server by copying key fields like the Common Name (CN) and Subject Alternative Name (SAN). This emulated certificate is then signed by the CA certificate installed on the ProxySG and presented to the client browser to establish the client-side secure session.

  5. Question 5

    Multiple answers

    A company has a policy to block executable file downloads. The administrator has created a CPL rule using a File Extension object for .exe. However, users are still able to download executables that have been renamed with a .txt extension. To prevent this, the administrator wants to inspect the actual content of the file. Which TWO of the following policy objects should be used in combination to achieve this? (Select TWO)

    Answer and explanation

    Correct answers: B, F

  6. Question 6

    An administrator needs to create a CPL script that redirects any HTTP request for http://www.example.com/oldpath to https://www.newdomain.com/newpath. Which of the following CPL code snippets correctly performs this redirection?

    Answer and explanation

    Correct answer: D

    The correct syntax uses an action.Redirect object. It's best practice to match on url.domain rather than url.host to be less specific. The action requires the redirect code (e.g., 301 for permanent), the new URL, and optionally, a variable like $(url.query) to preserve any query strings from the original request. The other options use incorrect actions (action.Forward), incorrect syntax, or less precise matching.

  7. Question 7

    A global company uses ProxySG appliances in a reverse proxy configuration to protect and accelerate access to its internal web applications. The security team wants to ensure that any traffic containing signatures of known SQL injection attacks is blocked before it reaches the web servers. This inspection should only happen for POST requests. Which is the most efficient way to implement this using the VPM?

    Answer and explanation

    Correct answer: A

    This is the most direct and efficient method. A Web Content Layer is the appropriate place for content-based decisions. The rule can be precisely targeted using a Request Method object for POST requests. The action would then be to send the request to an integrated Content Analysis System (CAS) via ICAP for scanning. The CAS is designed to detect threats like SQL injection and can instruct the ProxySG to block the request if a threat is found.

  8. Question 8

    During a performance audit of a ProxySG 9000 series appliance, an administrator notices that the CPU utilization for HTTP workers is consistently high, leading to increased latency. The sysinfo file shows a large number of active connections but a relatively low cache hit rate. Which action would be most effective in mitigating the high CPU load on the HTTP workers?

    Answer and explanation

    Correct answer: D

    HTTP workers are responsible for handling client requests, fetching objects from origin servers, and serving them. A low cache hit rate means workers are frequently going to the origin server, which is a CPU-intensive process involving DNS lookups, TCP handshakes, and data transfer. By optimizing caching policies to increase the hit rate, more objects will be served directly from the ProxySG's disk or RAM cache. This significantly reduces the workload on the HTTP workers, leading to lower CPU utilization and improved latency.

  9. Question 9

    A policy trace is being used to debug why a user is being denied access to a specific website. The trace output shows the final decision is DENIED, but the administrator cannot see which specific rule in the VPM is causing the block. What is the most likely reason for this and how can it be resolved?

    flowchart TD A[Start Request] --> B{Layer 1: Auth}; B --> C{Layer 2: Content Filter}; C --> D{Layer 3: Web Access}; D --> E[Decision Point]; E --> F1[ALLOW]; E --> F2[DENY];
    Answer and explanation

    Correct answer: B

    The Visual Policy Manager (VPM) only displays policies created through its interface. It is possible to have CPL code from other sources (like the Local Policy File, a Forwarding Policy File, or CPL layers added via the CLI) that is processed by the SGOS policy engine but is not represented in the VPM GUI. If a trace shows a denial but no corresponding rule is visible in any VPM layer, the most common cause is a rule in one of these non-VPM CPL sources.

  10. Question 10

    A hospital is deploying a ProxySG to enforce acceptable use policies and protect against malware. Due to patient privacy regulations (HIPAA), traffic to specific healthcare-related domains containing Protected Health Information (PHI) must NOT be decrypted or inspected. However, all other SSL/TLS traffic, including to webmail and social media sites, MUST be intercepted and scanned. Which VPM configuration is the best practice to meet these requirements?

    Answer and explanation

    Correct answer: B

    This is the standard and most effective method. The SSL Interception Layer is processed specifically for SSL/TLS handshakes. By placing a 'Do Not Intercept' (bypass) rule at the top for the sensitive healthcare domains, you ensure that traffic is tunneled without decryption. The second, more general 'Intercept' rule then catches all other traffic that did not match the first rule. This top-down processing logic is fundamental to VPM policy evaluation.

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 220 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon