Q: 9
An administrator needs to SSL inspect all traffic but one specific URL category. The administrator
decides to create two policies, one to inspect all traffic and another one to bypass the specific
category. What is the logical sequence in which they have to appear in the list?
Options
Discussion
Hard to say, B. You want the exception rule up top or the "inspect all" would catch everything first. ZIA is always first-match, top-down.
B
Had something like this in a mock. ZIA evaluates policies from top to bottom, so you need the exception (bypass) rule above the generic inspect-all one. If you put the catch-all first, nothing else gets a chance to match. Pretty sure that's the logic here but let me know if I missed something.
Had something like this in a mock. ZIA evaluates policies from top to bottom, so you need the exception (bypass) rule above the generic inspect-all one. If you put the catch-all first, nothing else gets a chance to match. Pretty sure that's the logic here but let me know if I missed something.
Option B that's how ZIA processes policy lists, top down so the bypass needs to come first.
Always weird how vendors make you stress over rule order. B
Be respectful. No spam.