ExamGecko
Home Home / Cisco / 300-720

Cisco 300-720 Practice Test - Questions Answers, Page 11

Question list
Search
Search

List of questions

Search

Related questions











A Cisco Secure Email Gateway administrator is creating a Mail Flow Policy to receive outbound email from Microsoft Exchange. Which Connection Behavior must be selected to properly process the messages?

A.

Accept

A.

Accept

Answers
B.

Delay

B.

Delay

Answers
C.

Relay

C.

Relay

Answers
D.

Reject

D.

Reject

Answers
Suggested answer: C

Explanation:

Relay is the connection behavior that must be selected to properly process the messages. Relay allows Cisco ESA to accept messages from the specified source and deliver them to the intended destination, without applying any content or reputation filters.

To configure a mail flow policy with relay connection behavior on Cisco ESA, the administrator can follow these steps:

Select Mail Policies > Mail Flow Policies and click Add Policy.

Enter a name and description for the mail flow policy, such as Exchange Outbound.

Under Connection Behavior, select Relay.

Click Submit.

The other options are not valid connection behaviors to properly process the messages, because they either reject, delay, or accept the messages with content or reputation filters applied.

Reference: [User Guide for AsyncOS 15.0 for Cisco Secure Email Gateway], page 6-2 and page 6-3.

An organization wants to prevent proprietary patent documents from being shared externally via email. The network administrator reviewed the DLP policies on the Cisco Secure Email Gateway and could not find an existing policy with the appropriate matching patterns. Which type of DLP policy template must be used to create a policy that meets this requirement?

A.

privacy protection

A.

privacy protection

Answers
B.

custom policy

B.

custom policy

Answers
C.

regulatory compliance

C.

regulatory compliance

Answers
D.

acceptable use

D.

acceptable use

Answers
Suggested answer: B

Explanation:

Custom policy is a type of DLP policy template that must be used to create a policy that meets this requirement. Custom policy allows the administrator to define their own criteria for detecting sensitive or confidential data in messages, such as keywords, regular expressions, file types, etc.

To create a custom DLP policy on Cisco ESA, the administrator can follow these steps:

Select Mail Policies > DLP Policy Manager and click Add Policy.

Enter a name and description for the DLP policy, such as Patent Protection.

Under Policy Template, select Custom Policy.

Click Submit.

Under Content Matching Criteria, click Add Criteria.

Choose a matching type, such as Keyword or Regular Expression, and enter a value that matches the proprietary patent documents, such as "patent number" or "\d{4}/\d{6}".

Click Submit.

The other options are not valid types of DLP policy templates to create a policy that meets this requirement, because they are predefined templates that do not match the proprietary patent documents.

Reference: [User Guide for AsyncOS 15.0 for Cisco Secure Email Gateway], page 9-3 and page 9-5.

When a network engineer is troubleshooting a mail flow issue, they discover that some emails are rejected with an SMTP code of 451 and the error message "#4.7.1 Unable to perform DMARC verification". In the DMARC verification profile on the Cisco Secure Email Gateway appliance, which action must be set for messages that result in temporary failure to prevent these emails from being rejected?

A.

Accept

A.

Accept

Answers
B.

Ignore

B.

Ignore

Answers
C.

Quarantine

C.

Quarantine

Answers
D.

No Action

D.

No Action

Answers
Suggested answer: A

Explanation:

Accept is the action that must be set for messages that result in temporary failure to prevent these emails from being rejected. Accept allows Cisco ESA to deliver the messages without applying any DMARC actions or modifications.

To configure the accept action for messages that result in temporary failure on Cisco ESA, the administrator can follow these steps:

Select Mail Policies > DMARC Verification Profile and click Edit Settings for the DMARC verification profile that applies to the messages.

Under DMARC Actions, select Accept from the drop-down menu for Messages That Result in Temporary Failure.

Click Submit.

The other options are not valid actions for messages that result in temporary failure to prevent these emails from being rejected, because they either apply DMARC actions or modifications or do nothing.

Reference: [User Guide for AsyncOS 15.0 for Cisco Secure Email Gateway], page 11-4 and page 11-5.

A network engineer must tighten up the SPAM control policy of an organization due to a recent SPAM attack. In which scenario does enabling regional scanning improve security for this organization?

A.

when most of the received spam comes from a specific country

A.

when most of the received spam comes from a specific country

Answers
B.

when most of the received spam originates outside of the U.S.

B.

when most of the received spam originates outside of the U.S.

Answers
C.

when most of the received email originates outside of the U.S.

C.

when most of the received email originates outside of the U.S.

Answers
D.

when most of the received email originates from a specific region

D.

when most of the received email originates from a specific region

Answers
Suggested answer: D

Explanation:

Enabling regional scanning improves security for this organization when most of the received email originates from a specific region. Regional scanning is a feature that allows Cisco ESA to apply different spam thresholds and actions based on the geographic region of the sender's IP address, using a database of IP addresses and regions.

To enable regional scanning on Cisco ESA, the administrator can follow these steps:

Select Security Services > IronPort Anti-Spam and click Edit Settings.

Under Regional Scanning, select Enable Regional Scanning.

Click Submit.

Select Security Services > IronPort Anti-Spam > Regional Settings and click Add Region.

Choose a region from the drop-down menu, such as Asia Pacific.

Enter a spam threshold and an action for that region, such as 80 and Drop.

Click Submit.

DRAG DROP

Drag and drop the graymail descriptions from the left onto the verdict categories they belong to on the right.

Question 105
Correct answer: Question 105

A content dictionary was created for use with Forged Email Detection. Proper data that pertains to the CEO Example CEO: <ceo@example com> must be entered. What must be added to the dictionary to accomplish this goal?

A.

example.com

A.

example.com

Answers
B.

Example CEO

B.

Example CEO

Answers
C.

ceo

C.

ceo

Answers
D.

ceo@example com

D.

ceo@example com

Answers
Suggested answer: D

Explanation:

[email protected] is the data that must be added to the dictionary to accomplish this goal. A content dictionary is a list of values that can be used as a condition in a content filter or a message filter. Forged Email Detection is a feature that allows Cisco ESA to detect and prevent email spoofing attacks, where the sender's address or domain is forged to appear as someone else, such as the CEO of the organization.

To create a content dictionary for use with Forged Email Detection on Cisco ESA, the administrator can follow these steps:

Select Mail Policies > Content Dictionaries and click Add Dictionary.

Enter a name and description for the content dictionary, such as CEO Email.

Under Dictionary Values, click Add Value.

Enter the email address of the CEO, such as [email protected].

Click Submit.

A security administrator deployed a Cisco Secure Email Gateway appliance with a mail policy configured to store suspected spam for review. The appliance is the DMZ and only the standard HTTP/HTTPS ports are allowed by the firewall. An administrator wants to ensure that users can view any suspected spam that was blocked. Which action must be taken to meet this requirement?

A.

Enable the external Spam Quarantine and enter the IP address and port for the Secure Email and Web Manager

A.

Enable the external Spam Quarantine and enter the IP address and port for the Secure Email and Web Manager

Answers
B.

Enable the Spam Quarantine and leave the default settings unchanged.

B.

Enable the Spam Quarantine and leave the default settings unchanged.

Answers
C.

Enable End-User Quarantine Access and point to an LDAP server for authentication.

C.

Enable End-User Quarantine Access and point to an LDAP server for authentication.

Answers
D.

Enable the Spam Quarantine and specify port 80 for HTTP and port 443 for HTTPS

D.

Enable the Spam Quarantine and specify port 80 for HTTP and port 443 for HTTPS

Answers
Suggested answer: C

Explanation:

Enabling End-User Quarantine Access and pointing to an LDAP server for authentication is the action that must be taken to meet this requirement. End-User Quarantine Access is a feature that allows users to access their personal quarantine on Cisco ESA using their email address and password, without requiring an administrator account or access to Secure Email and Web Manager.

To enable End-User Quarantine Access on Cisco ESA, the administrator can follow these steps:

Select Security Services > IronPort Anti-Spam > End User Safelist/Blocklist Settings and click Edit Settings.

Under End User Quarantine Access, select Enable End User Quarantine Access.

Under Authentication Server, select LDAP Server from the drop-down menu and choose an LDAP server profile from the drop-down menu.

Click Submit.

An engineer deploys a Cisco Secure Email Gateway appliance with default settings in an organization that permits only standard H feature does not work. Which additional action resolves the issue?

A.

Configure the outbound firewall rule to permit traffic on port 8081

A.

Configure the outbound firewall rule to permit traffic on port 8081

Answers
B.

Enable the Use HTTP option under Advanced Settings for File Reputation.

B.

Enable the Use HTTP option under Advanced Settings for File Reputation.

Answers
C.

Enable the Use SSL option under Advanced Settings for File Reputation.

C.

Enable the Use SSL option under Advanced Settings for File Reputation.

Answers
D.

Configure the outbound firewall rule to permit traffic on port 3237

D.

Configure the outbound firewall rule to permit traffic on port 3237

Answers
E.

TP/HTTPS ports outbound and notices that the AMP file reputation

E.

TP/HTTPS ports outbound and notices that the AMP file reputation

Answers
Suggested answer: E

Explanation:

Configuring the outbound firewall rule to permit traffic on port 3237 is the additional action that resolves the issue. AMP file reputation is a feature that allows Cisco ESA to check files attached to messages against a cloud-based database of known malicious files and apply appropriate actions, such as block, deliver, or quarantine.

By default, AMP file reputation uses TCP port 3237 to communicate with the cloud-based database.

If this port is blocked by a firewall, AMP file reputation will not work properly.

To resolve this issue, the administrator can configure the outbound firewall rule to permit traffic on port 3237 from Cisco ESA.

The other options are not valid actions to resolve the issue, because they do not affect the port used by AMP file reputation.

Reference: [User Guide for AsyncOS 15.0 for Cisco Secure Email Gateway], page 7-5 and page 7-6.

Refer to the exhibit.

A network engineer must set up a content filter to find any messages that failed SPF and send them into quarantine The content filter has been set up and enabled, but all messages except those that have failed SPF are being sent into quarantine. Which section of the filter must be modified to correct this behavior?

A.

skip-filters

A.

skip-filters

Answers
B.

log-entry

B.

log-entry

Answers
C.

spf-status

C.

spf-status

Answers
D.

quarantine

D.

quarantine

Answers
Suggested answer: C

Explanation:

spf-status is the section of the filter that must be modified to correct this behavior. spf-status is a condition that determines whether a message matches the content filter rule based on the result of SPF verification, such as pass, fail, neutral, etc.

The content filter in the exhibit has a spf-status condition set to "Pass", which means that it will match messages that passed SPF verification and apply the action of "Quarantine". This is the opposite of what the network engineer intended to do.

To correct this behavior, the network engineer can modify the spf-status condition to "Fail", which means that it will match messages that failed SPF verification and apply the action of "Quarantine".

The other options are not valid sections of the filter that must be modified to correct this behavior, because they do not affect the spf-status condition.

Reference: [User Guide for AsyncOS 15.0 for Cisco Secure Email Gateway], page 8-3 and page 8-4.

Which restriction is in place for end users accessing the spam quarantine on Cisco Secure Email Gateway appliances?

A.

Access via a link in a notification is mandatory.

A.

Access via a link in a notification is mandatory.

Answers
B.

The end user must be assigned to the Guest role

B.

The end user must be assigned to the Guest role

Answers
C.

Direct access via web browser requires authentication.

C.

Direct access via web browser requires authentication.

Answers
D.

Authentication is required when accessing via a link in a notification.

D.

Authentication is required when accessing via a link in a notification.

Answers
Suggested answer: C

Explanation:

Direct access via web browser requires authentication is the restriction that is in place for end users accessing the spam quarantine on Cisco Secure Email Gateway appliances. Spam quarantine is a feature that allows Cisco ESA to store messages that are suspected to be spam and allow end users or administrators to review them and release or delete them as needed.

End users can access their personal spam quarantine on Cisco ESA either by clicking on a link in a notification email or by entering their email address and password in a web browser. In both cases, authentication is required to ensure security and privacy.

The other options are not valid restrictions that are in place for end users accessing the spam quarantine on Cisco Secure Email Gateway appliances, because they are either not mandatory or not related to authentication.

Reference: [User Guide for AsyncOS 15.0 for Cisco Secure Email Gateway], page 10-2 and page 10-3.

Total 148 questions
Go to page: of 15