Sie sind auf Seite 1von 31

Blue Coat BCCPP

BCCPP Blue Coat Certified Proxy Professional, V.3.1.1

Practice Test
Version 3.1

Blue Coat BCCPP: Practice Exam QUESTION NO: 1 Which of the following are true when attempting to deny access to file types? A. MIME type objects are matched against the Content-type request header; File Extension objects are matched against the GET response header; Apparent Data Type objects are matched against request data. B. MIME type objects are matched against the Content-type response header; File Extension objects are matched against the GET request header; Apparent Data Type objects are matched against response data. C. MIME type objects are matched against the Content-encoding response header; File Extension objects are matched against the GET request header; Apparent Data Type objects are matched against response data. D. MIME type objects are matched against the Content-type response header; File Extension objects are matched against the GET request header; Apparent Data Type objects are matched against request data.

QUESTION NO: 2

A. All of the above B. None of the above C. a, b & c only D. b, c & d only Answer: D

QUESTION NO: 3 .Which of the following statements are true? (Choose all that apply) (a) The SGOS object store utilizes a directory structure so that objects in cache can be accessed rapidly (b) Information about a single object in cache be retrieved from the Management console or the CLI "Pass Any Exam. Any Time." - www.actualtests.com 2

Ac

tua

Which of the following steps have to be performed to support Kerberos Authentication? (Choose all that apply) (a) A virtual URL that resolves to the IP of the ProxySG. (b) Registering the BCAAA as a Service Principal Name. (c) Configuring IWA Realm. (d) Configuring Explicit Proxy.

lTe

sts

.co

Answer: C

Blue Coat BCCPP: Practice Exam (c) There are two object caches, the object cache which resides on disk and the object cache which resides in RAM (d) The SGOS object store is separated by protocol (HTTP cache, FTP cache, etc.) A. a, b & c only B. a, c & d only C. b, c & d only D. All of the above Answer: A

QUESTION NO: 4 The ProxySG acts as both an ICAP client and ICAP server. A. True B. False Answer: A

QUESTION NO: 5

A. a, b & c only B. a, c & d only C. b, c & d only D. All of the above Answer: B

QUESTION NO: 6 Which of the following statements are true about ProxySG Protocol Detection feature? (Choose all that apply) (a) Protocol detection is performed on the server's response. (b) Protocol detection is performed on the client's request. "Pass Any Exam. Any Time." - www.actualtests.com 3

Ac

Which of the following statements are true about Reverse Proxy deployment?(Choose all that apply) (a) Forwarding hosts in the forwarding file must be defined as "server" style (b) Default-scheme in forwarding file is supported (c) Protocol conversion between HTTPS <- ->HTTP are automatic (d) ProxySG should be set with default DENY policy

tua

lTe

sts

.co

Blue Coat BCCPP: Practice Exam (c) Enabling Detect Protocol option will automatically enable early intercept attribute in proxy services. (d) Protocol detection is performed by looking at the TCP port number. A. a & b only B. b & c only C. c & d only D. ALL of the above Answer: D

QUESTION NO: 7 url.regex=!\.html$ d\ DENY What is the effect of the above CPL code? A. Deny any URL that ends with html B. Deny any URL that does not end with html C. Deny any URL that ends with htm or html D. Deny any URL that does not end with htm or html Answer: B

QUESTION NO: 8

Which of the following statements are true about dynamic bypass list? (Choose all that apply) (a) Configured polices will not be enforced on client request if the request matches an entry in the bypass list. (b) Dynamic bypass entries are lost when ProxySG is restarted (c) If request made to a site in a forwarding policy is in the bypass list, the site is inaccessible (d) Dynamic bypass parameters can be configured on Management Console and CLI. A. All of the above B. a, b & c only C. b, c & d only D. a, c & d only Answer: B

QUESTION NO: 9

"Pass Any Exam. Any Time." - www.actualtests.com

Ac

tua

lTe

sts

.co

Blue Coat BCCPP: Practice Exam You can NOT use a self-signed certificate when intercepting SSL traffic. A. True B. False Answer: B

QUESTION NO: 10 What criterion is NOT used to determine location awareness of a ProxyClient A. IP address range B. Virtual NICs IP address range C. The IP address of the closest AND concentrator D. DNS server IP address Answer: C

Which method of controlling downloads of certain file types works fastest on ProxySG? A. Apparent Data Type B. MIME Type C. File extension Answer: C

QUESTION NO: 12

A cookie without an expire value will___ A. last until the client cleats cookies from the browser B. last until the client closes the browser session C. last until the client logs off Answer: B

QUESTION NO: 13 Which of the following hostnames are NOT matched by the regular expression "www (0 9) (0-9)? \ .foo\ .com") "Pass Any Exam. Any Time." - www.actualtests.com 5

Ac

tua

lTe

sts

QUESTION NO: 11

.co

Blue Coat BCCPP: Practice Exam A. www.foo.com B. www01.foo.com C. www1.foo.com D. www11.foo.com Answer: A

QUESTION NO: 14 The Content-encoding header is used to declare the MIME type and compression method used in a HTTP response. A. True B. False Answer: A

QUESTION NO: 15

A. All of the above B. a, b& c only C. a, b& d only D. b, c& d only Answer: C

QUESTION NO: 16 Which of these are the features of a Blue Coat Director? (Choose all that apply) (a) Install and update configurations of a group of ProxySG (b) Distribute and control content of a group of ProxySG (c) Managing SSL VPN configuration (d) Monitoring ProxySG Performance "Pass Any Exam. Any Time." - www.actualtests.com

Ac

tua

Which of the following are obvious advantages of having a ProxySG deployed in a Reverse Proxy environment? (Choose all that apply? (a)The ProxySG has built in DOS protection to guard the actual web server from denial-ofservice attacks (b) Increased performance with caching provides an improved Web Experience (c) Consistent default behavior of cache expiration and validation directives (d) SSL termination on ProxySG allow SSL offloading, therefore eliminating bottleneck on the web server side.

lTe

sts

.co

Blue Coat BCCPP: Practice Exam A. a, b & c only B. a, b & d only C. b, c & d only D. a, c & d only Answer: B

QUESTION NO: 17 Which client deployment methods support the 407 Proxy Authentication Required response code? (Choose all that apply) (a) Proxy Auto Configuration files (b) WCCP (c) Proxy settings in browser (d) Inline Bridging A. a & b only B. b & c only C. c & d only D. a & c only E. All of the above Answer: D

QUESTION NO: 18

A. True B. False Answer: A

QUESTION NO: 19 With ProxySG failover, the failover Virtual IP address can be the same as the IP address assigned to the master. A. True B. False "Pass Any Exam. Any Time." - www.actualtests.com 7

Ac

After creating CPL in the local policy file, the policy is imported into the VPM CPL file so that it can be viewed through the Visual Policy Manager.

tua

lTe

sts

.co

Blue Coat BCCPP: Practice Exam Answer: B

QUESTION NO: 20 ProxySG is configured to permit error but guest authentication is not configured. What will happen to a user who initiates a connection to the Internet? A. The user will receive an error notifying unsuccessful authentication. B. The user will be allowed to proceed as a guest user. C. The user will be allowed to proceed as unauthenticated. D. The user will receive an error notifying Access Denied. Answer: A

QUESTION NO: 21

What is the protocol used for Blue Coat Director to communicate with ProxySG? A. SSL B. Telnet C. SSH v2 D. HTTPS Answer: C

QUESTION NO: 22

What are the two functions of configuring forwarding in ProxySG? (Choose all that apply) A. To accelerate application B. Reverse Proxy C. To support Proxy Chaining D. To intercept SSl Answer: A,D

QUESTION NO: 23 When a ProxyClient setup file is manually on a client's computer, what data transfer takes place before ProxyClient is installed?

"Pass Any Exam. Any Time." - www.actualtests.com

Ac

tua

lTe

sts

.co

Blue Coat BCCPP: Practice Exam A. ProxyClient setup program is self-contained; there is no data transfer necessary in order to complete the installation of the ProxyCinent B. ProxyCilent setup program cause download of the most recent updates from a public download site https://hypersonic.bluecoat.com/. C. ProxyClient setup program transfers data form Client Manager ProxySG appliance before it can install successfully. D. ProxyClient setup program transfers data form the AND manager (or backup AND manager) ProxySG appliance before it can install successfully. Answer: C

QUESTION NO: 24 When a backup ProxySG takes over because the master fails, which of the following will occur? A. Policy from the master is replicated on the backup. B. A failover event is logged in the event log. C. An email notification is sent to the ProxySG administrator. D. The backup begins replying to ARPS for the Virtual MAC address. Answer: B

QUESTION NO: 25

A. a, b & c only B. a, c & d only C. b, c & d only D. All of the above Answer: B

QUESTION NO: 26 At which checkpoint does the rewrite () perform the TWURL modification?

"Pass Any Exam. Any Time." - www.actualtests.com

Ac

Health checks are automatically created under which scenarios? (Choose all that apply) (a) When a forwarding host is created. (b) When a failover group is created. (c) When the DRTR is enabled. (d) When a SOCKS gateway is created.

tua

lTe

sts

.co

Blue Coat BCCPP: Practice Exam A. Client In B. Client Out C. Server In D. Server Out Answer: B

QUESTION NO: 27 When creating a TCP tunnel service in explicit mode, you must also configure a forwarding host? A. True B. False

QUESTION NO: 28

Answer: A

QUESTION NO: 29

What are the available actions for any given category, when defining ProxyClient content filtering configuration? (Choose all that apply) (a) Allow (b) Deny (c) Temporanily Allow (d) Warm A. a & b only B. a, b & c only C. a, b & d only D. All of the above Answer: A

"Pass Any Exam. Any Time." - www.actualtests.com

Ac

tua

lTe

A. True B. False

sts

In regards to authentication the ProxySG does not support origin-redirects with CONNECT method.

.co

Answer: A

10

Blue Coat BCCPP: Practice Exam

QUESTION NO: 30 Which statement is correct about WWW-Authenticate header? A. It is request header used only with Basic Authentication to send username and password to a proxy or a Web server B. It is a request header used to send credentials C. It is a response header used with HTTP 401 status code to negotiate method of authentication and send NTLM challenge to the client. Answer: B

QUESTION NO: 31

A. True B. False Answer: B

QUESTION NO: 32

What is the meaning of the metacharacter \ (backslash) in regular expressions? A. escape character B. any character except newline C. zero or character D. zero or more character Answer: A

QUESTION NO: 33 When configuring forwarding in PoxySG, what are the possible load balancing methods? (Choose all that apply) (a) Round Robin (b) Fastest ICMP Reply "Pass Any Exam. Any Time." - www.actualtests.com 11

Ac

tua

lTe

sts

.co

The authentication mode origin-ip-redirect allows an administrator to assign a Time To Live (TTL) for the surrogate credentials. Meanwhile the authentication mode origin-cookie-redirect does not provide this feature.

Blue Coat BCCPP: Practice Exam (c) Least Connections (d) Least Delay A. a & c only B. b & d only C. a & d only D. b & c only Answer: A

QUESTION NO: 34 ICAP responses may be cached on a ProxySG, i.e, for some Web requests ICAP processing may be completed without involving ProxyAV A. True B. False Answer: A

QUESTION NO: 35

A. a & c only B. a & b only C. c only D. All of the above Answer: A

QUESTION NO: 36 When implementing failover with ProxySG appliances, configurations and policies on the master are automatically replicated to members of the failover group.

"Pass Any Exam. Any Time." - www.actualtests.com

Ac

Which of the following are true when enabling the early intercept attribute for a proxy service? (Choose all that apply) (a) It is automatically enabled when the detect protocol attribute is enabled. (b) The ProxySG completes the three-way TCP handshake with the client before establishing a connection to the upstream server. (c) It can be used with any protocol.

tua

lTe

sts

.co

12

Blue Coat BCCPP: Practice Exam A. True B. False Answer: A

QUESTION NO: 37 What are the advantages that you may get in deploying ProxySG with WCCP? (Choose all the apply) (a) Scalability (b) Redundancy (c) Load Balancing (d) Security A. All of the above B. a, b & c only C. b, c & d only D. a, b & d only Answer: A

QUESTION NO: 38

Answer: A

QUESTION NO: 39 Steaming traffic is better managed by using ProxySG's admission control features. A. True B. False Answer: B

"Pass Any Exam. Any Time." - www.actualtests.com

Ac

A. True B. False

tua

ProxySG can cache videos played by Adobe Flash based video player (e.g. on YouTube) as HTTP objects.

lTe

sts

.co

13

Blue Coat BCCPP: Practice Exam QUESTION NO: 40 What is the meaning of the metacharacter * (asterisk) in regular expressions? A. escape character B. any character except newline C. zero or character D. zero or more characters Answer: D

QUESTION NO: 41 Which of the following are some of the general requirements for using Kerberos Authentication? (Choose all that apply) (a) SGOS 4.2x or higher (b) Internet Explorer 5 (c) Transparent Proxy Deployment (d) Windows 2000 and above A. a, b & c only B. b, c & d only C. a, c & d only D. All of the above Answer: C

Which of the following authentication mode will allow you to visibly challenge the user upon inactivity timeout? (Choose all that apply) (a) Form based authentication (b) Cookie Surrogate (c) IP surrogate (d) Session based surrogate a & b only A. a & b only B. b & c only C. c & d only D. d &a only E. All of the above

"Pass Any Exam. Any Time." - www.actualtests.com

Ac

QUESTION NO: 42

tua

lTe

sts

.co

14

Blue Coat BCCPP: Practice Exam Answer: B

QUESTION NO: 43 Which of the following are the benefits of using Bandwidth Management with the ProxySG (Choose all that apply) (a) Ensuring mission critical application receives minimum amount of bandwidth (b) Compressing certain type of traffic classes before transmitting it over the WAN (c) Prioritizing certain traffic classes (d) Rate limiting application to prevent "hogging" of network bandwidth. A. a, b & c only B. a, b & d only C. a, c & d only D. All of the above Answer: C

QUESTION NO: 44

A. All of the above B. a & b only C. c only D. c & d only E. None of the above Answer: A

QUESTION NO: 45 At which checkpoint does the rewrite_url_prefix perform the TWURL modification? A. Client In "Pass Any Exam. Any Time." - www.actualtests.com 15

Ac

tua

The Access Control List (ACL) option in the management console (configured by the menu item Configuration >Authentication >Console access) will be enforced for which types of administrative accounts? (Choose all that apply) (a) LDAP realm account (b) Local realm account (c) Built-in account (d) IWA realm account

lTe

sts

.co

Blue Coat BCCPP: Practice Exam B. Client Out C. Server In D. Server Out Answer: B

QUESTION NO: 46 Which of the following options are configured when implementing failover on ProxySG appliances? (Choose all that apply) (a) Multicast address for advertisements (b) Relative Priority (c) Virtual MAC address (d) Group Secret to hash information sent in multicast announcements A. a, b & c only B. b, c & d only C. a, b & d only D. All of the above Answer: C

QUESTION NO: 47

A. a & b only B. b, & c only C. a & c only D. c & d only E. b & d only Answer: C

QUESTION NO: 48

"Pass Any Exam. Any Time." - www.actualtests.com

Ac

Which of the following format can be used in troubleshooting authortization and authorization related problems in ProxySG? (Choose all that apply) (a) x-sc-authentication-error (b) x-sc-authentication-timeout (c) x-sc-authorlzation-error (d) x-sc-authorization-timeout

tua

lTe

sts

.co

16

Blue Coat BCCPP: Practice Exam Hostname of the BCAAA= serverl DNS suffix =bluecoat.com Hostname of the Bluecoat SG = sgo1 Referring to the above information, what is the correct syntax for the SPN command in the Domain Controller? A. setspn-A HTTP/serverl.bluecoat.com sg01 B. setspn-L HTTP/serverl.bluecoat.com sg01 C. setspn-A HTTP/sg01.bluecoat.com server1 D. setspn-D HTTP/serverl.bluecoat.com sg01 Answer: C

QUESTION NO: 49 In ProxyAV anti-virus scanners are____

A. GRE sends IP payload over IP B. GRE sends either TCP or UDP payload over IPSec C. GRE sends IP payload over data link layer Answer: A

QUESTION NO: 51 Which of the following options are configured when implementing failover on ProxySG appliances? (Choose all that apply) (a) Multicast address for advertisements (b) Relative Priority (c) Virtual MAC address "Pass Any Exam. Any Time." - www.actualtests.com 17

Ac

Which statement best describes the payload that is encapsulated by GRE (Generic RoutingEncapsulation) protocol and what layer GRE uses for delivery

tua

QUESTION NO: 50

lTe

Answer: B

sts

A. multiple parallel threads sharing the same code and the same address space B. multiple parallel processes not sharing the same address space C. asynchronous calls to remote scanner hardware D. synchronous procedure calls within ProxyAV

.co

Blue Coat BCCPP: Practice Exam (d) Group Secret to hash information sent in multicast announcements A. All of the above B. a, b & c only C. a, b & d only D. b, c & d only Answer: C

QUESTION NO: 52 There is a hard coded limit to the number of concurrent connections allowed through the ProxySG..

Answer: B

QUESTION NO: 53

A. a & b only B. b & c only C. c & d only D. All of the above Answer: D

QUESTION NO: 54 Which statement is correct about Proxy-Authorization header? A. It is a response header used by a proxy to negotiate parameters of the credential exchange and to send challenge to the client

"Pass Any Exam. Any Time." - www.actualtests.com

Ac

tua

The ProxySG ICAP implementation is fully compatible with which of the following applications? (Choose all that apply) (a) Finjan SurfinGate (b) Webwasher (c) AntiVirus Scan Engine (SAVSE) (d) Trend Micro InterScan

lTe

sts

.co

A. True B. False

18

Blue Coat BCCPP: Practice Exam B. It is a request header used to pass client's credentials to a proxy server C. It is a response header used by an upstream proxy to ask for credentials from a downstream proxy or user agent Answer: B

QUESTION NO: 55 While configuring Blue Coat directory, what is an Overlay? A. A few selected setting used to replace some of the configuration in ProxySG. B. A snapshot ofall the configuration in ProxySG. Answer: A

CPL is required when creating which types of policy? A. Two-Way URL rewrites B. Policy that utilizes layer guards C. Policy that involves local users and groups Answer: C

QUESTION NO: 57

Which of the following statements are true about Bandwidth Management Hierarchies and Priorities? (Choose all that apply) (a) Child classes can have children of their own. (b) If no limit is set, packets are sent as soon as they arrive. (c) Priorities are set to a class to give precedence over other classes. (d) If there is excess bandwidth, the child class will always get the first opportunity to use it. A. a, b & c only B. a, b & d only C. b, c & d only D. All of the above Answer: A

"Pass Any Exam. Any Time." - www.actualtests.com

Ac

tua

lTe

sts

.co

QUESTION NO: 56

19

Blue Coat BCCPP: Practice Exam QUESTION NO: 58 Which method of controlling downloads of certain file types has the LOWEST efficiency in terms of response time, bandwidth use and execution time on ProxySG A. Apparent Data Type B. MIME Type C. File extension Answer: A

QUESTION NO: 59 Bandwidth minimum does not work in an explicit deployment model. A. True B. False Answer: B

QUESTION NO: 60

Which authentication realm is NOT supported for authenticating administrators to the management console? A. IWA B. Radius C. Local D. Sequence E. All the above are supported Answer: E

QUESTION NO: 61 If a user can not be derived through the Window SSO realm, then the client will . A. be prompted with an authentication dialog box to provide credentials. B. receive an authentication error from the proxy. C. proceed as an unauthenticated user. D. receive an authentication form from the proxy to provide credentials.

"Pass Any Exam. Any Time." - www.actualtests.com

Ac

tua

lTe

sts

.co

20

Blue Coat BCCPP: Practice Exam Answer: C

QUESTION NO: 62 In which of the following ways can Access Logging be enabled? (Choose all that apply.) (a) By a CLI command (b) In the Management Console under Access Logging (C) By adding another layer to VPM policy A. a & b only B. a & c only C. b & c only D. All of the above

QUESTION NO: 63

Answer: D

QUESTION NO: 64 Which server certificate validation errors can be ignored within ProxySG policy? (Choose all that apply) (a) Untrusted issuer (b) Host name mismatch (c) Expiration A. a & b only B. b & c only "Pass Any Exam. Any Time." - www.actualtests.com 21

Ac

A. a & b only B. b & c only C. All of the above D. b only

tua

lTe

Which of the following cashing techniques utilize retrieval workers to keep the contents of the cache fresh? (Choose all that apply.) (a) Cost-based Deletion (b) Asynchronous Adaptive Refresh (c) Popularity Contest

sts

.co

Answer: C

Blue Coat BCCPP: Practice Exam C. a & c only D. All of the above Answer: D

QUESTION NO: 65 When configuring Blue Coat Director, how can an administrator be authenticated? (Choose all that apply.) (a) Local configured accounts and password (b) RADIUS (c) IWA (d) TACACS+ A. All of the above B. a, b & c only C. a, c & d only D. a, b & d only Answer: D

QUESTION NO: 66

Answer: A

QUESTION NO: 67 Which of the following Health Checks can be defined for a forwarding host? (Choose all that apply) (a) ICMP (b) TCP (C) HTTP (d) HTTPS A. a & b only B. b & c only "Pass Any Exam. Any Time." - www.actualtests.com 22

Ac

A. True B. False

tua

Log format variable rs(Content-Type) always refers to Content-type header value sent from the proxySG to the client.

lTe

sts

.co

Blue Coat BCCPP: Practice Exam C. c & d only D. a & d only E. All of the above Answer: E

QUESTION NO: 68 Which of the following is NOT true about global and per-rule policy tracing? A. Each object processed by the ProxySG generates an entry in the global policy trace and appears in a rule-based trace if the object triggers a rule. B. Global policy tracing may severely affect the performance of a production ProxySG. C. You can enable global tracing through the Management Console or CLI. D. You can enable per-rule tracing through the Management Console.

Answer: A

QUESTION NO: 70

Which of the following access log formats are supported by the ProxySG? (Choose all that apply) (a) ELFF (b) SQUID (c) Websense (d) NCSA A. a, b & c only B. a, b & d only C. a, c & d only D. b, c & d only E. All of the above "Pass Any Exam. Any Time." - www.actualtests.com 23

Ac

tua

A. True B. False

lTe

The ProxySG policy engine allows an administrator to create policy based on any MIME type, File Extension or File Signature (first bytes in the response body).

sts

QUESTION NO: 69

.co

Answer: D

Blue Coat BCCPP: Practice Exam Answer: E

QUESTION NO: 71 By default, what type of authentication challenge will the user-agent receive if the authentication node is set to AUTO? A. proxy-ip for explicit and transparent clients B. proxy for explicit and origin-cookie-redirect for transparent clients C. proxy for explicit and transparent clients D. proxy-ip for explicit and origin-ip-redirect for transparent clients E. proxy for explicit and proxy-ip for transparent Answer: E

QUESTION NO: 72

Which types of requests are likely to be served the fastest? A. TCP_MISS B. TCP_NC_MISS C. TCP_HIT D. TCP_MEM_HIT E. TCP_RESCAN_HIT Answer: E

QUESTION NO: 73

When a TCP health check responds as "healthy" then, . A. the SG is able to successfully establish a TCP handshake to the upstream device. B. the SG is able to successfully resolve the hostname of the upstream device. C. the SG is able to successfully connect to the upstream device on port 80. D. the SG is able to successfully ping the upstream device. Answer: B

QUESTION NO: 74

"Pass Any Exam. Any Time." - www.actualtests.com

Ac

tua

lTe

sts

.co

24

Blue Coat BCCPP: Practice Exam What are the possible ways of creating bandwidth classes? (a) Using Management Console (b) Defining them in a JavaScript file and uploading it to ProxySG (c) Using CLI A. a & b only B. a & c only C. b & c only D. All of the above Answer: B

QUESTION NO: 75 What are the two main functions of configuring forwarding in ProxySG? (Choose all that apply) (a) To accelerate application (b) Reverse Proxy (c) To support Proxy Chaining (d) To intercept SSL A. a & b only B. b & c only C. c & d only D. d &a only Answer: B

Which authentication modes would result in a user-agent receiving a HTTP 401-Unauthorized status codes from the proxy? (Choose all that apply) (a) origin-ip-redirect (b) proxy-ip (c) origin-cookie (d) form-cookie-redirect A. a & b only B. a & c only C. b & c only D. c & d only E. None of the above

"Pass Any Exam. Any Time." - www.actualtests.com

Ac

QUESTION NO: 76

tua

lTe

sts

.co

25

Blue Coat BCCPP: Practice Exam Answer: B

QUESTION NO: 77 What is the meaning of the metacharacter? (question mark) in regular expressions? A. escape character B. any character except newline C. zero or one character D. zero or more characters Answer: C

QUESTION NO: 78

Answer: B

QUESTION NO: 79

Apparent Data Type objects can be created in the VPM for which of the following file types? (Choose all that apply) (a) Windows DLL (b) Windows Exe (c) Windows Ocx (d) Windows Cab A. a, b & c only B. b, c & d only C. a, c & d only D. All of the above Answer: D

"Pass Any Exam. Any Time." - www.actualtests.com

Ac

tua

lTe

A. Create a SSL intercept layer in the VPM. B. Enable a SSL service on port 443. C. Assign a key ring to the SSL proxy. D. Create a SSL access layer in the VPM.

sts

.co

Which of the following steps are not required when configuring a transparently deployed ProxySG to intercept HTTPS traffic?

26

Blue Coat BCCPP: Practice Exam QUESTION NO: 80 What type of authentication challenge is issued when using the Policy Substitution Realm? A. 407 proxy Authentication Required B. 401 Unauthorized C. No challenge will be issued D. Not enough information to determine the answer Answer: C

QUESTION NO: 81 A service can be configured to listen in explicit and transparent mode simultaneously. A. True B. False Answer: B

QUESTION NO: 82

A. All of the above B. b, c & d only C. a, c & d only D. a, b & c only Answer: B

QUESTION NO: 83 Which header cannot be sent together with an HTTP 407 status code from the ProxySG? A. Proxy-Authenticate: Basic="MyRealm" B. Proxy-Authenticate: NTLM="MyRealm" "Pass Any Exam. Any Time." - www.actualtests.com 27

Ac

tua

When configuring reverse proxy with SSL, what are the 3 possible options of ensuring host affinity? (Choose all that apply) (a) client-ip (b) ssl-session-id (c) accelerator-cookie (d) server-ip

lTe

sts

.co

Blue Coat BCCPP: Practice Exam C. Proxy- Authenticate: Kerberos="MyRealm" D. proxy-Authenticate: Negotiate="MyRealm" E. All the above headers can be sent with 407 status code Answer: D

QUESTION NO: 84 The bcreportermain_v1 access log format has a configurable ordering of fields, and this custom order is reflected in a log file header. A. True B. False

QUESTION NO: 85

Answer: C

QUESTION NO: 86

In a transparent proxy that is intercepting HTTP, how can an administrator allow instant messaging over HTTP to pass through ProxySG if they do not have IM license on the ProxySG? A. By disabling Detect Protocol B. By disabling Protocol Handoff in IM C. By configuring the proxy services to bypass AOL IM, MSN IM and Yahoo IM services D. By disabling early intercept Answer: B

"Pass Any Exam. Any Time." - www.actualtests.com

Ac

tua

A. Forward B. Cookie C. Location D. Redirect

lTe

sts

When a client receives an HTTP 302 response from a server, the client will form a new request based on the header.

.co

Answer: A

28

Blue Coat BCCPP: Practice Exam QUESTION NO: 87 In explicit proxy, what will happen to a connection that is made when there is no such service running in the ProxySG? A. Connection will be intercepted. B. Connection will be rejected. C. Connection will by be bypassed. D. Connection will be forwarded. Answer: C

QUESTION NO: 88 Which of the following methods can the Windows SSO utilize to derive a user name? (Choose all that apply) (a) Domain Controller Querying (b) Direct Client Querying (c) Direct Client Querying, if unsuccessful then Domain Controller Querying (d) Domain Controller Querying, if unsuccessful then Direct Client Querying A. a & b only B. a & c only C. b & c only D. b & d only E. All of the above Answer: D

QUESTION NO: 89

Which statement is correct about Proxy-Authenticate header A. It is sent by the proxy every time when a HTTP 407 status code is sent B. It is used by a browser to pass credentials to a proxy C. It is used by both client and proxy to negotiate the method of credential exchange Answer: A

QUESTION NO: 90

"Pass Any Exam. Any Time." - www.actualtests.com

Ac

tua

lTe

sts

.co

29

Blue Coat BCCPP: Practice Exam Who plays the role of the trusted third party, when client and server communicate via Kerberos? A. NTLM (NT LAN Manager) B. KDC (Key Distribution Center) C. PKI (Public Key Infrastructure) D. SSL Certificate Authority Answer: B

QUESTION NO: 91 Log format variable s-ip always refers to A. IP address of the HTTP request client B. IP address of the original content server C. IP address of the ProxySG to which client has established a connection Answer: C

QUESTION NO: 92

Answer: C

QUESTION NO: 93

A policy trace can be enabled for any layer type. A. True B. False Answer: A

QUESTION NO: 94 Which regular expression should you test against a URL to match both http and https schemes? "Pass Any Exam. Any Time." - www.actualtests.com 30

Ac

tua

A. The LAN where WCCP router and ProxySG are located should use IPv6 B. No forwarding should be defined for ProxySG C. ProxySG and router should be in the same broadcast domain

lTe

What is a precondition for using L2 MAC rewrite with WCCP?

sts

.co

Blue Coat BCCPP: Practice Exam A. 2https? B. [http][https] C. ^https? D. http[s] Answer: C

"Pass Any Exam. Any Time." - www.actualtests.com

Ac

tua

lTe

sts

.co

31