Question 1
A financial services company is using a ProxySG in explicit mode. To comply with new regulations, all outbound traffic to known financial partner APIs must be logged with full transaction details, while traffic to all other destinations must have user-identifying information stripped from the access logs. An existing global policy layer already sets the logging level for all traffic. How should an administrator configure the Visual Policy Manager (VPM) to meet this requirement without disrupting the existing logging policy for general traffic?
Answer and explanation
Correct answer: C
The correct approach is to create a new, more specific Web Access Layer that is evaluated before the general, global logging layer. By placing the new layer above the existing one, its rules are processed first. A rule matching the specific financial partner APIs can then apply the detailed logging action. Since policy evaluation stops at the first match within a layer for a given action, no further rules are needed in this new layer for other traffic; the request will simply 'fall through' to the next layer (the global one) which handles the logging for all other traffic.