ExamGecko
Home Home / Cisco / 300-720

Cisco 300-720 Practice Test - Questions Answers, Page 10

Question list
Search
Search

List of questions

Search

Related questions











A Cisco ESA administrator has noticed that new messages being sent to the Centralized Policy

Quarantine are being released after one hour. Previously, they were being held for a day before being released.

What was configured that caused this to occur?

A.

The retention period was changed to one hour.

A.

The retention period was changed to one hour.

Answers
B.

The threshold settings were set to override the clock settings.

B.

The threshold settings were set to override the clock settings.

Answers
C.

The retention period was set to default.

C.

The retention period was set to default.

Answers
D.

The threshold settings were set to default.

D.

The threshold settings were set to default.

Answers
Suggested answer: C

Explanation:

You can configure Policy, Virus, and Outbreak Quarantines in any one of the following ways:

Choose Quarantine > Other Quarantine > View > +.

Choose Monitor > Policy, Virus, and Outbreak Quarantines and do one of the following.

Click Add Policy Quarantine.

Keep the following in mind, changing the retention time of the File Analysis quarantine from the default of one hour is not recommended.

https://www.cisco.com/c/en/us/td/docs/security/esa/esa14-0/user_guide/b_ESA_Admin_Guide_14-0/b_ESA_Admin_Guide_12_1_chapter_011111.html?bookSearch=true

What are organizations trying to address when implementing a SPAM quarantine?

A.

true positives

A.

true positives

Answers
B.

false negatives

B.

false negatives

Answers
C.

false positives

C.

false positives

Answers
D.

true negatives

D.

true negatives

Answers
Suggested answer: C

Explanation:

Reference:

https://www.cisco.com/c/en/us/td/docs/security/esa/esa12-0/user_guide/b_ESA_Admin_Guide_12_0/b_ESA_Admin_Guide_12_0_chapter_0100000.html#con_1482874

False positives are legitimate messages that are incorrectly identified as spam by the Cisco ESA. Organizations may want to implement a spam quarantine to reduce the risk of losing false positive messages and allow users or administrators to review and release them2. Reference = User Guide for AsyncOS 12.0 for Cisco Email Security Appliances - GD (General Deployment) - Spam

Quarantine [Cisco Secure Email Gateway] - Cisco

Which two Cisco ESA features are used to control email delivery based on the sender? (Choose two.)

A.

incoming mail policies

A.

incoming mail policies

Answers
B.

spam quarantine

B.

spam quarantine

Answers
C.

outbreak filter

C.

outbreak filter

Answers
D.

safelists

D.

safelists

Answers
E.

blocklists

E.

blocklists

Answers
Suggested answer: D, E

Explanation:

Safelists and blocklists are features on Cisco ESA that allow you to control email delivery based on the sender. Safelists are lists of sender addresses or domains that you want to accept or exempt from certain filtering actions. Blocklists are lists of sender addresses or domains that you want to reject or drop3. Reference = Securing Email with Cisco Email Security Appliance (SESA) v3.1

What is the purpose of checking the CRL during SMTP authentication on a Cisco Secure Email Gateway?

A.

Validate the date to check if the certificate is still valid

A.

Validate the date to check if the certificate is still valid

Answers
B.

Check if the certificate is not revoked.

B.

Check if the certificate is not revoked.

Answers
C.

Confirm that corresponding CA is present

C.

Confirm that corresponding CA is present

Answers
D.

Verify the common name matches user ID

D.

Verify the common name matches user ID

Answers
Suggested answer: B

Explanation:

The purpose of checking the Certificate Revocation List (CRL) during SMTP authentication on a Cisco

Secure Email Gateway is to check if the certificate is not revoked by the issuing Certificate Authority (CA). A revoked certificate means that it is no longer valid and should not be trusted. Reference = [User Guide for AsyncOS 12.0 for Cisco Email Security Appliances - GD (General Deployment) -Configuring SMTP Authentication [Cisco Secure Email Gateway] - Cisco]

An organization wants to designate help desk personnel to assist with tickets that request the release of messages from the spam quarantine because company policy does not permit direct end-user access to the quarantine. Which two roles must be used to allow help desk personnel to release messages while restricting their access to make configuration changes in the Cisco Secure Email Gateway? (Choose two.)

A.

Administrator

A.

Administrator

Answers
B.

Help Desk User

B.

Help Desk User

Answers
C.

Read-Only Operator

C.

Read-Only Operator

Answers
D.

Technician

D.

Technician

Answers
E.

Quarantine Administrator

E.

Quarantine Administrator

Answers
Suggested answer: B, E

Explanation:

All users with administrator privileges can change spam quarantine settings and view and manage messages in the spam quarantine. You do not need to configure spam quarantine access for administrator users.

If you configure access to the spam quarantine for users with the following roles, they can view, release, and delete messages in the spam quarantine:

-Operator

-Read-only operator

-Help desk user

-Guest

-Custom user roles that have spam quarantine privileges

These users cannot access spam quarantine settings.

https://www.cisco.com/c/en/us/td/docs/security/esa/esa14-0/user_guide/b_ESA_Admin_Guide_14-0/b_ESA_Admin_Guide_12_1_chapter_0100000.html?bookSearch=true#con_1624156

When the spam quarantine is configured on the Cisco Secure Email Gateway, which type of query is used to validate non administrative user access to the end-user quarantine via LDAP?

A.

spam quarantine end-user authentication

A.

spam quarantine end-user authentication

Answers
B.

spam quarantine alias consolidation

B.

spam quarantine alias consolidation

Answers
C.

spam quarantine external authorization

C.

spam quarantine external authorization

Answers
D.

local mailbox (IMAP/POP) authentication

D.

local mailbox (IMAP/POP) authentication

Answers
Suggested answer: A

Explanation:

spam quarantine end-user authentication query is used to validate non administrative user access to the end-user quarantine via LDAP1. This query is configured in the System Administration > LDAP > LDAP Server Profile page and can be tested using the smtproutes command in the CLI1. The other queries are not related to this task. The spam quarantine alias consolidation query is used to consolidate multiple email addresses for a user into one login2. The spam quarantine external authorization query is used to authorize users to access an external spam quarantine on a separate Cisco Secure Email and Web Manager3. The local mailbox (IMAP/POP) authentication is an alternative method to authenticate users without using LDAP2.

An administrator notices that incoming emails with certain attachments do not get delivered to all recipients when the emails have multiple recipients in different domains like cisco.com and test.com.

The same emails when sent only to recipients in cisco.com are delivered properly. How must the Cisco Secure Email Gateway be configured to avoid this behavior?

A.

Modify mail policies for cisco.com to ensure that emails are not dropped.

A.

Modify mail policies for cisco.com to ensure that emails are not dropped.

Answers
B.

Modify mail policies so email recipients do not match multiple policies.

B.

Modify mail policies so email recipients do not match multiple policies.

Answers
C.

Modify DLP configuration to ensure that all attachments are permitted for test.com.

C.

Modify DLP configuration to ensure that all attachments are permitted for test.com.

Answers
D.

Modify DLP configuration to exempt DLP scanning for messages sent to test.com domain

D.

Modify DLP configuration to exempt DLP scanning for messages sent to test.com domain

Answers
Suggested answer: B

Explanation:

By modifying the mail policies, specifically the recipient matching criteria, you can ensure that email recipients do not match multiple policies simultaneously. When recipients in the email message belong to different domains (e.g., cisco.com and test.com), it can result in multiple policies being triggered simultaneously, leading to inconsistent delivery of emails with attachments.

DLP is for outgoing mail only and not relevant to incoming mail.

An engineer is tasked with creating a content filter to catch attachments, including credit card numbers, and hold them for review until further action is taken. Which component on a Cisco Secure Email Gateway must be configured to meet this requirement?

A.

Spam Quarantine

A.

Spam Quarantine

Answers
B.

Policy Quarantine

B.

Policy Quarantine

Answers
C.

Outbreak Filter

C.

Outbreak Filter

Answers
D.

Content Filter

D.

Content Filter

Answers
Suggested answer: D

Explanation:

Content filter is a component on a Cisco Secure Email Gateway that must be configured to catch attachments, including credit card numbers, and hold them for review until further action is taken.

Content filter allows you to define rules based on message content and apply actions such as quarantine, encrypt, or modify. Reference = [User Guide for AsyncOS 12.0 for Cisco Email Security Appliances - GD (General Deployment) - Content Filters [Cisco Secure Email Gateway] - Cisco]

Which of the following two steps are required to enable Cisco SecureX integration on a Cisco Secure Email Gateway appliance? (Choose two.)

A.

Paste in the Registration Token generated from the Smart Licensing Account

A.

Paste in the Registration Token generated from the Smart Licensing Account

Answers
B.

Enable the Threat Response service under Network>Cloud Service Settings.

B.

Enable the Threat Response service under Network>Cloud Service Settings.

Answers
C.

Select the correct Threat Response Server based on your region.

C.

Select the correct Threat Response Server based on your region.

Answers
D.

Paste in the Registration Token generated from the Security Services Exchange.

D.

Paste in the Registration Token generated from the Security Services Exchange.

Answers
E.

Enable the Security Services Exchange service under Network>Cloud Service Settings

E.

Enable the Security Services Exchange service under Network>Cloud Service Settings

Answers
Suggested answer: B, C

Explanation:

one of the methods to enable Cisco SecureX integration on a Cisco Secure Email Gateway appliance is to use the Threat Response service1. This service allows the appliance to send telemetry data to the SecureX cloud and provide visibility and response capabilities across multiple security products1. To use this service, the administrator needs to perform the following steps1:

Enable the Threat Response service: The administrator needs to go to Network > Cloud Service Settings and enable the Threat Response service. This will generate a registration token that can be used to register the appliance with SecureX1.

Select the correct Threat Response Server: The administrator needs to select the appropriate Threat Response server based on the region where the appliance is located. The available regions are North America, Europe, and Asia Pacific1.

What are the two different phases in the process of Cisco Secure Email Gateway performing S/MIME encryption? (Choose two.)

A.

Attach the encrypted public key to the message

A.

Attach the encrypted public key to the message

Answers
B.

Encrypt the message body using the session key

B.

Encrypt the message body using the session key

Answers
C.

Send the encrypted message to the sender

C.

Send the encrypted message to the sender

Answers
D.

Attach the encrypted symmetric key to the message

D.

Attach the encrypted symmetric key to the message

Answers
E.

Create a pseudo-random session key.

E.

Create a pseudo-random session key.

Answers
Suggested answer: D, E
Total 148 questions
Go to page: of 15