Correct Answer: Centralized TLS termination for backend application protection, selective decryption of outbound user traffic that excludes privacy-sensitive categories, and adequately sized decryption infrastructure to avoid becoming a performance bottleneck
Explanation: Centralized termination, privacy-aware selective decryption, and adequate capacity planning together provide effective, appropriately scoped protection, unlike indiscriminate decryption with no capacity planning, offloading with no centralized certificate management, undersized infrastructure, inconsistent bypass rules, or disabling offloading entirely.
Correct Answer: Centralized TLS termination for backend application protection, selective decryption of outbound user traffic that excludes privacy-sensitive categories, and adequately sized decryption infrastructure to avoid becoming a performance bottleneck
Explanation: Centralized termination, privacy-aware selective decryption, and adequate capacity planning together provide effective, appropriately scoped protection, unlike indiscriminate decryption with no capacity planning, offloading with no centralized certificate management, undersized infrastructure, inconsistent bypass rules, or disabling offloading entirely.