Cisco 300-720 Practice Test - Questions Answers
List of questions
Related questions
Question 1
Spreadsheets containing credit card numbers are being allowed to bypass the Cisco ESA.
Which outgoing mail policy feature should be configured to catch this content before it leaves the network?
file reputation filtering
outbreak filtering
data loss prevention
file analysis
Explanation:
Data Loss Prevention (DLP) is an outgoing mail policy feature that should be configured to catch this content before it leaves the network. DLP allows Cisco ESA to scan outgoing messages for sensitive or confidential data, such as credit card numbers, social security numbers, health records, etc., and apply appropriate actions, such as encrypt, quarantine, notify, etc., to prevent data leakage or loss.
The other options are not valid outgoing mail policy features to catch this content before it leaves the network, because they do not scan for sensitive or confidential data in messages.
Reference: User Guide for AsyncOS 15.0 for Cisco Secure Email Gateway, page 9-2 and page 9-3.
Question 2
Refer to the exhibit. Which configuration on the scan behavior must be updated to allow the attachment to be scanned on the Cisco ESA?
Add an additional mapping for attachment type for zip files.
Enable assume match pattern if the email was not scanned for any reason.
Increase the maximum recursion depth from 5 to a larger value.
Increase the maximum attachment size to scan to a larger value.
Explanation:
The maximum attachment size to scan is a configuration on the scan behavior that determines the maximum size of an attachment that Cisco ESA will scan for viruses and malware. If an attachment exceeds this size, Cisco ESA will apply the configured action for unscannable messages, such as deliver, drop, or quarantine.
To allow the attachment to be scanned on the Cisco ESA, this configuration must be updated to a larger value than the attachment size, which is 10 MB according to the message header.
The other options are not valid configurations to allow the attachment to be scanned on the Cisco ESA, because they do not affect the maximum attachment size to scan.
Reference: User Guide for AsyncOS 15.0 for Cisco Secure Email Gateway, page 7-3 and page 7-4.
Question 3
Which type of query must be configured when setting up the Spam Quarantine while merging notifications?
Spam Quarantine Alias Routing Query
Spam Quarantine Alias Consolidation Query
Spam Quarantine Alias Authentication Query
Spam Quarantine Alias Masquerading Query
Explanation:
Spam Quarantine Alias Consolidation Query is a type of query that must be configured when setting up the Spam Quarantine while merging notifications on Cisco ESA. This query allows Cisco ESA to consolidate multiple email addresses that belong to the same end user into one entry in the Spam
Quarantine, and send only one notification email to that end user with all the quarantined messages for all their email addresses.
Reference: User Guide for AsyncOS 15.0 for Cisco Secure Email Gateway, page 10-10.
Question 4
Which two factors must be considered when message filter processing is configured? (Choose two.)
message-filter order
lateral processing
structure of the combined packet
mail policies
MIME structure of the message
Explanation:
Message-filter order and MIME structure of the message are two factors that must be considered when message filter processing is configured on Cisco ESA. Message-filter order determines the sequence in which message filters are evaluated and applied to incoming messages, which can affect the final outcome of the filtering process. MIME structure of the message determines how message filters match against different parts of the message, such as headers, body, attachments, etc., which can affect the accuracy and performance of the filtering process.
Reference: User Guide for AsyncOS 15.0 for Cisco Secure Email Gateway, page 3-3 and page 3-5.
Reference: https://www.cisco.com/c/en/us/td/docs/security/esa/esa12-0/user_guide/b_ESA_Admin_Guide_12_0/b_ESA_Admin_Guide_chapter_01000.html
Question 5
How does the graymail safe unsubscribe feature function?
It strips the malicious content of the URI before unsubscribing.
It checks the URI reputation and category and allows the content filter to take an action on it.
It redirects the end user who clicks the unsubscribe button to a sandbox environment to allow a safe unsubscribe.
It checks the reputation of the URI and performs the unsubscribe process on behalf of the end user.
Explanation:
Secure unsubscribe option for end users. Mimicking an unsubscribe option is a popular phishing technique. For this reason, the end users are generally wary of clicking unknown unsubscribe links.
For such scenarios, the cloud-based Unsubscribe Service extracts the original unsubscribe URI, checks the reputation of the URI, and then performs the unsubscribe process on behalf of the end user. This protects end users from malicious threats masquerading as unsubscribe links.
https://www.cisco.com/c/en/us/td/docs/security/esa/esa14-2-1/User_Guide/b_ESA_Admin_Guide_14-2-1/b_ESA_Admin_Guide_12_1_chapter_01110.html#id_101033
Reference: https://www.cisco.com/c/en/us/support/docs/security/email-security-appliance/200383-Graymail- Detection-and-Safe-Unsubscribin.html
Question 6
Which method enables an engineer to deliver a flagged message to a specific virtual gateway address in the most flexible way?
Set up the interface group with the flag.
Issue the altsrchost command.
Map the envelope sender address to the host.
Apply a filter on the message.
Explanation:
The altsrchost command enables an engineer to deliver a flagged message to a specific virtual gateway address in the most flexible way. This command allows you to specify an alternate source host for messages that match a message filter. You can use this command to route messages to different virtual gateways based on the message content or attributes.
Reference: Securing Email with Cisco Email Security Appliance (SESA) v3.1, Module 5: Using Message Filters to Enforce Email Policies, Lesson 1: Using Message Filters
Reference: https://www.cisco.com/c/en/us/td/docs/security/esa/esa11-1/user_guide/b_ESA_Admin_Guide_11_1/b_ESA_Admin_Guide_chapter_01000.html#con_1133810
Question 7
An administrator is trying to enable centralized PVO but receives the error, "Unable to proceed with
Centralized Policy, Virus and Outbreak Quarantines configuration as esa1 in Cluster has content filters / DLP actions available at a level different from the cluster level."
What is the cause of this error?
Content filters are configured at the machine-level on esa1.
DLP is configured at the cluster-level on esa2.
DLP is configured at the domain-level on esa1.
DLP is not configured on host1.
Explanation:
The PVO cannot be enabled and shows this type of error message.
Unable to proceed with Centralized Policy, Virus and Outbreak Quarantines configuration as host1 and host2 in Cluster have content filters / DLP actions available at a level different from the cluster Level.
The error message can indicate that one of the hosts does not have a DLP feature key applied and DLP is disabled. The solution is to add the missing feature key and apply DLP settings identical as on the host that has the feature key applied. This feature key inconsistency might have the same effect with Outbreak Filters, Sophos Antivirus, and other feature keys.
https://www.cisco.com/c/en/us/support/docs/security/email-security-appliance/118026-technoteesa-00.html
Reference: https://www.cisco.com/c/en/us/support/docs/security/email-security-appliance/118026-technote- esa-00.html
Question 8
Which feature must be configured before an administrator can use the outbreak filter for nonviral threats?
quarantine threat level
antispam
data loss prevention
antivirus
Explanation:
The feature that must be configured before an administrator can use the outbreak filter for nonviral threats is antispam. The outbreak filter relies on the antispam engine to detect and block nonviral threats, such as phishing, malware, or spam campaigns. You need to enable antispam scanning and configure the antispam settings before you can use the outbreak filter.
Reference: Securing Email with Cisco Email Security Appliance (SESA) v3.1, Module 8: Using Anti-Virus and Outbreak Filters, Lesson 2: Configuring Outbreak Filters
Reference: https://www.cisco.com/c/en/us/td/docs/security/esa/esa12-0/user_guide/b_ESA_Admin_Guide_12_0/b_ESA_Admin_Guide_chapter_01110.html
Question 9
Which type of attack is prevented by configuring file reputation filtering and file analysis features?
denial of service
zero-day
backscatter
phishing
Explanation:
The type of attack that is prevented by configuring file reputation filtering and file analysis features is zero-day. Zero-day attacks are those that exploit unknown vulnerabilities in software or systems before they are patched or fixed. File reputation filtering and file analysis features help to protect against zero-day attacks by checking the reputation of files attached to email messages and sending them to a cloud-based service for dynamic analysis.
Reference: Securing Email with Cisco Email Security Appliance (SESA) v3.1, Module 9: Using Advanced Malware Protection, Lesson 1: Configuring File Reputation Filtering and File Analysis
Reference: https://www.cisco.com/c/en/us/td/docs/security/esa/esa12-0/user_guide/b_ESA_Admin_Guide_12_0/b_ESA_Admin_Guide_chapter_010000.html#con_1809885
Question 10
Users have been complaining of a higher volume of emails containing profanity. The network administrator will need to leverage dictionaries and create specific conditions to reduce the number of inappropriate emails.
Which two filters should be configured to address this? (Choose two.)
message
spam
VOF
sender group
content
Explanation:
Message filter and content filter are two filters that should be configured to address this issue.
Message filter and content filter are rules that allow Cisco ESA to perform actions on messages based on predefined or custom conditions, such as headers, envelope, body, attachments, etc.
To reduce the number of inappropriate emails containing profanity, the network administrator can create a dictionary that contains a list of profane words or phrases and use it as a condition in a message filter or content filter that applies an action of "drop", "quarantine", or "modify subject" on the matching messages.
The other options are not valid filters to address this issue, because they do not use dictionaries or conditions based on message content.
Reference: User Guide for AsyncOS 15.0 for Cisco Secure Email Gateway, page 8-3 and page 8-7.
Question