ETExamTower
Q9Decryption Policies to Control HTTPS Traffic

Drag the actions into the order in which they occur as an HTTPS session passes through the Cisco WSA. <DragDrop items={["Server replies with server certificate to Cisco WSA","Encryption data channel is established","Client sends the session key, which is encrypted by using public key of the server certificate","Client sends a hello message to Cisco WSA","Cisco WSA replies with a proxied certificate of the destination server to the client"]} slots={[{"answer":"Client sends a hello message to Cisco WSA","id":"step1","label":"step 1"},{"answer":"Server replies with server certificate to Cisco WSA","id":"step2","label":"step 2"},{"answer":"Cisco WSA replies with a proxied certificate of the destination server to the client","id":"step3","label":"step 3"},{"answer":"Client sends the session key, which is encrypted by using public key of the server certificate","id":"step4","label":"step 4"},{"answer":"Encryption data channel is established","id":"step5","label":"step 5"}]} explanation={"For HTTPS proxy/decryption, Cisco WSA first receives the client TLS hello and establishes the corresponding connection to the destination server, which supplies its certificate. WSA then sends the client a proxied certificate for that destination, allowing the client to encrypt and send the session key. Once the TLS key exchange completes, the encrypted data channel is established."} reuse={false} />

← → navigate · a answer
Discussion · 5
7
The order must be: -Client sends hello message to cisco wsa --server responds with server certificate to Cisco WSA -Cisco WSA replies with a proxied certificate of the destination server to the client. -Client sends the session key, wich is encrypted by using public key of the server certificate. -Encrypted data channel is stablished.
2
[1] Client sends hello message to cisco wsa ( WSA is trying to determine whether the server certificate is valid ) [2] server responds with server certificate to Cisco WSA [3] Cisco WSA responds with a proxied certificate of the destination server to the client. [4] Client sends the session key, wich is encrypted by using public key of the server certificate. [5] Encrypted data channel is stablished.
1
How can it reply with server certificate key in step 2 when the key is received in step 5? this is not correct!
1
In fact it´s correct, the step says - client sends the session key, wich is encrypted using ---------public key------ of the ------server certificate----------. Every one can use the public key of a public server, because as the name say ¡its public!. Be careful when you read a question, in Cisco always have a tricky word.
1
then what is the correct answser ? is it the one on the capture or the one on your last response ?