BCCPP Sample Questions

BCCPP Sample Questions & Answers

The exam leans hardest on safe-search rules written in Content Policy Language, then moves through SGOS architecture and HTTP worker processes, performance diagnostics, VPM policy tracing, Kerberos logins, SSL proxy for encrypted sessions, and product integration.

Launch the full BCCPP simulator →

Showing 10 of 20 free samples.

  1. Question 1Intermediate

    Content Policy Language (CPL) · CPL Redirection

    An administrator needs to create a CPL script that redirects any HTTP request for http://www.example.com/oldpath to https://www.newdomain.com/newpath. Which of the following CPL code snippets correctly performs this redirection?

    Show answer & explanation

    Correct answer: D

    The correct syntax uses an action.Redirect object. It's best practice to match on url.domain rather than url.host to be less specific. The action requires the redirect code (e.g., 301 for permanent), the new URL, and optionally, a variable like $(url.query) to preserve any query strings from the original request. The other options use incorrect actions (action.Forward), incorrect syntax, or less precise matching.

  2. Question 2Advanced

    ProxySG Integration · Content Analysis Integration

    A global company uses ProxySG appliances in a reverse proxy configuration to protect and accelerate access to its internal web applications. The security team wants to ensure that any traffic containing signatures of known SQL injection attacks is blocked before it reaches the web servers. This inspection should only happen for POST requests. Which is the most efficient way to implement this using the VPM?

    Show answer & explanation

    Correct answer: A

    This is the most direct and efficient method. A Web Content Layer is the appropriate place for content-based decisions. The rule can be precisely targeted using a Request Method object for POST requests. The action would then be to send the request to an integrated Content Analysis System (CAS) via ICAP for scanning. The CAS is designed to detect threats like SQL injection and can instruct the ProxySG to block the request if a threat is found.

  3. Question 3Advanced

    SGOS Architecture · Performance Tuning and HTTP Workers

    During a performance audit of a ProxySG 9000 series appliance, an administrator notices that the CPU utilization for HTTP workers is consistently high, leading to increased latency. The sysinfo file shows a large number of active connections but a relatively low cache hit rate. Which action would be most effective in mitigating the high CPU load on the HTTP workers?

    Show answer & explanation

    Correct answer: D

    HTTP workers are responsible for handling client requests, fetching objects from origin servers, and serving them. A low cache hit rate means workers are frequently going to the origin server, which is a CPU-intensive process involving DNS lookups, TCP handshakes, and data transfer. By optimizing caching policies to increase the hit rate, more objects will be served directly from the ProxySG's disk or RAM cache. This significantly reduces the workload on the HTTP workers, leading to lower CPU utilization and improved latency.

  4. Question 4Intermediate

    System Diagnostics and Monitoring · Policy Tracing

    A policy trace is being used to debug why a user is being denied access to a specific website. The trace output shows the final decision is DENIED, but the administrator cannot see which specific rule in the VPM is causing the block. What is the most likely reason for this and how can it be resolved?

    flowchart TD A[Start Request] --> B{Layer 1: Auth}; B --> C{Layer 2: Content Filter}; C --> D{Layer 3: Web Access}; D --> E[Decision Point]; E --> F1[ALLOW]; E --> F2[DENY];
    Show answer & explanation

    Correct answer: B

    The Visual Policy Manager (VPM) only displays policies created through its interface. It is possible to have CPL code from other sources (like the Local Policy File, a Forwarding Policy File, or CPL layers added via the CLI) that is processed by the SGOS policy engine but is not represented in the VPM GUI. If a trace shows a denial but no corresponding rule is visible in any VPM layer, the most common cause is a rule in one of these non-VPM CPL sources.

  5. Question 5Intermediate

    Advanced Encrypted Traffic Management · SSL Interception Policy

    A hospital is deploying a ProxySG to enforce acceptable use policies and protect against malware. Due to patient privacy regulations (HIPAA), traffic to specific healthcare-related domains containing Protected Health Information (PHI) must NOT be decrypted or inspected. However, all other SSL/TLS traffic, including to webmail and social media sites, MUST be intercepted and scanned. Which VPM configuration is the best practice to meet these requirements?

    Show answer & explanation

    Correct answer: B

    This is the standard and most effective method. The SSL Interception Layer is processed specifically for SSL/TLS handshakes. By placing a 'Do Not Intercept' (bypass) rule at the top for the sensitive healthcare domains, you ensure that traffic is tunneled without decryption. The second, more general 'Intercept' rule then catches all other traffic that did not match the first rule. This top-down processing logic is fundamental to VPM policy evaluation.

  6. Question 6Advanced

    Advanced Authentication · Kerberos Constrained Delegation

    An organization has configured Kerberos constrained delegation to allow the ProxySG to authenticate users to a downstream web application. However, authentication is failing. A Kerberos expert analyzes the traffic and determines that the Service-for-User-to-Proxy (S4U2proxy) extension is not being successfully utilized. Which of the following is a critical prerequisite for S4U2proxy to function correctly in this scenario?

    Show answer & explanation

    Correct answer: D

    Kerberos constrained delegation with protocol transition (S4U2proxy) requires very specific configuration in Active Directory. The account under which the ProxySG service runs must be trusted for delegation, but only to specific services (the downstream web application's SPN). Crucially, the 'Use any authentication protocol' option must be selected for that delegation entry. This enables Protocol Transition, allowing the ProxySG to take a user's credential from a non-Kerberos authentication method (like basic or NTLM) and transition it to a Kerberos ticket for the backend service.

  7. Question 7Intermediate

    Advanced Authentication · Authentication Policy Logic

    A university wants to provide unauthenticated guest network access but enforce strict content filtering, while authenticated staff members should have less restrictive filtering. Both user groups are on the same network segment. How can a ProxySG be configured to differentiate between these user groups and apply the correct policies?

    Show answer & explanation

    Correct answer: B

    This is a common and effective design pattern. The IWA realm is configured to authenticate users. If authentication succeeds, the user is identified as a staff member and their group memberships can be used in policy. If authentication fails for any reason (e.g., the user is on a non-domain machine), the 'fail open' configuration allows the connection to proceed, but without an authenticated user identity. Subsequent policy layers can then use the condition user.authenticated=false to identify these users as guests and apply the more restrictive filtering policy.

  8. Question 8Beginner

    SGOS Architecture · High Availability (HA)

    When a ProxySG is deployed in a high-availability (HA) pair using VRRP, what happens to existing TCP connections if the master ProxySG fails and the backup unit takes over?

    Show answer & explanation

    Correct answer: B

    VRRP provides Layer 3 failover by transferring a virtual IP address from the master to the backup unit. However, it does not synchronize Layer 4 connection state information. When the master fails, the backup takes over the VIP, but it has no knowledge of the TCP sessions that were established with the master. Therefore, all existing connections are broken and client applications (like web browsers) must initiate new TCP connections to the virtual IP, which will now be handled by the newly active proxy.

  9. Question 9Intermediate

    Content Policy Language (CPL) · Forwarding and Policy

    To comply with data sovereignty laws, a multinational corporation needs to ensure that traffic originating from its European Union (EU) branch offices is only sent to an upstream proxy located within the EU. Traffic from US offices should use a US-based upstream proxy. Which ProxySG feature is designed to handle this type of location-based policy enforcement?

    Show answer & explanation

    Correct answer: D

    The forwarding policy file is the correct mechanism for making dynamic, policy-based decisions about where to send traffic. By defining forwarding hosts for the EU and US proxies, an administrator can write rules that use the client.address condition to match traffic originating from the known IP subnets of the EU and US offices. This allows the ProxySG to direct traffic to the geographically appropriate upstream proxy, thereby satisfying the data sovereignty requirement.

  10. Question 10Advanced

    System Diagnostics and Monitoring · Policy Trace Analysis

    An administrator observes that the ProxySG is re-fetching objects from an origin web server even though the Cache-Control: max-age header is set to a long duration. A policy trace reveals the message REFRESH_SERV_IMS. What does this message indicate about the caching decision?

    Show answer & explanation

    Correct answer: B

    REFRESH_SERV_IMS specifically means the proxy is performing a refresh by sending a request to the origin server with an If-Modified-Since (IMS) header. This happens when the object is present in the cache, but its Time-To-Live (TTL) has expired according to the caching rules. Instead of downloading the full object again, it asks the server if the object has changed since it was last cached. If the server responds with a 304 Not Modified, the proxy serves the cached object and resets its TTL. If the server provides a new object, the proxy caches it and serves it to the client.

Ready for the real thing?

The full BCCPP simulator has every exam-style question, timed mode, and instant scoring.

Go to the BCCPP simulator →