ExamGecko
Home Home / Cisco / 300-720

Cisco 300-720 Practice Test - Questions Answers, Page 15

Question list
Search
Search

Related questions











A list of company executives is routinely being spoofed, which puts the company at risk of malicious email attacks An administrator must ensure that executive messages are originating from legitimate sending addresses Which two steps must be taken to accomplish this task? (Choose two.)

A.

Create an incoming content filter with SPF detection.

A.

Create an incoming content filter with SPF detection.

Answers
B.

Enable the Forged Email Detection feature under Security Settings.

B.

Enable the Forged Email Detection feature under Security Settings.

Answers
C.

Enable DMARC feature under Mail Policies.

C.

Enable DMARC feature under Mail Policies.

Answers
D.

Create an incoming content filter with the Forged Email Detection condition

D.

Create an incoming content filter with the Forged Email Detection condition

Answers
E.

Create a content dictionary including a list of the names that are being spoofed.

E.

Create a content dictionary including a list of the names that are being spoofed.

Answers
Suggested answer: D, E

Explanation:

To ensure that executive messages are originating from legitimate sending addresses, the administrator must take two steps:

Create an incoming content filter with the Forged Email Detection condition. This will allow the administrator to detect and block messages that have a forged "From: header" that matches or is similar to any of the names in a content dictionary.

Create a content dictionary including a list of the names that are being spoofed. This will allow the administrator to specify the names of the executives that are being targeted by spoofing attacks and use them in the Forged Email Detection condition. The other options are not relevant or sufficient for this task. Reference: [Cisco Secure Email Gateway Administrator Guide - Forged Email Detection] and [Cisco Secure Email Gateway Administrator Guide - Creating Content Dictionaries]

Refer to the exhibit.

An administrator has configured File Reputation and File Analysis on the Cisco Secure Email Gateway appliance however it does not function as expected What must be configured on the appliance for this to function?

A.

Upload the Root CA certificate for the File Reputation cloud to the Cisco Secure Email Gateway.

A.

Upload the Root CA certificate for the File Reputation cloud to the Cisco Secure Email Gateway.

Answers
B.

Open port 443 on the firewall for the Cisco Secure Email Gateway to connect to the File Reputation cloud.

B.

Open port 443 on the firewall for the Cisco Secure Email Gateway to connect to the File Reputation cloud.

Answers
C.

Configure the Cisco Secure Email Gateway to use SSL for the connection to the File Reputation server

C.

Configure the Cisco Secure Email Gateway to use SSL for the connection to the File Reputation server

Answers
D.

Restart the File Reputation service to force the scanning engine to connect to the File Reputation cloud.

D.

Restart the File Reputation service to force the scanning engine to connect to the File Reputation cloud.

Answers
Suggested answer: C

Explanation:

To enable File Reputation and File Analysis on the Cisco Secure Email Gateway appliance, the administrator must configure the appliance to use SSL for the connection to the File Reputation server. This will ensure that the communication between the appliance and the cloud service is secure and encrypted. The administrator must also upload a valid certificate from a trusted CA on the appliance for this purpose. The other options are not required or effective for this task. Reference:

[Cisco Secure Email Gateway Administrator Guide - Configuring File Reputation and File Analysis]

Which action do Outbreak Filters take to stop small-scale and nonviral attacks, such as phishing scams and malware distribution sites?

A.

Rewrite URLs to redirect traffic to potentially harmful websites through a web security proxy

A.

Rewrite URLs to redirect traffic to potentially harmful websites through a web security proxy

Answers
B.

Block all emails from email domains associated with potentially harmful websites.

B.

Block all emails from email domains associated with potentially harmful websites.

Answers
C.

Strip all attachments from email domains associated with potentially harmful websites.

C.

Strip all attachments from email domains associated with potentially harmful websites.

Answers
D.

Quarantine messages that contain links to potentially harmful websites until the site is taken offline

D.

Quarantine messages that contain links to potentially harmful websites until the site is taken offline

Answers
Suggested answer: A

Explanation:

Outbreak Filters can take the action of rewriting URLs to redirect traffic to potentially harmful websites through a web security proxy. This allows the Cisco Secure Email Gateway to scan the content of the websites and block or warn the user if they are malicious or undesirable. This action can stop small-scale and nonviral attacks, such as phishing scams and malware distribution sites, that may not be detected by other filters. Reference: [Cisco Secure Email Gateway Administrator Guide -Configuring Outbreak Filters]

What is the default method of remotely accessing a newly deployed Cisco Secure Email Virtual Gateway when a DHCP server is not available?

A.

Manual configuration of an IP address is required through the serial port before remote access

A.

Manual configuration of an IP address is required through the serial port before remote access

Answers
B.

DHCP is required for the initial IP address assignment

B.

DHCP is required for the initial IP address assignment

Answers
C.

Use the IP address of 192.168 42 42 via the Management port

C.

Use the IP address of 192.168 42 42 via the Management port

Answers
D.

Manual configuration of an IP address is required through the hypervisor console before remote access

D.

Manual configuration of an IP address is required through the hypervisor console before remote access

Answers
Suggested answer: C

Explanation:

The default method of remotely accessing a newly deployed Cisco Secure Email Virtual Gateway when a DHCP server is not available is to use the IP address of 192.168.42.42 via the Management port. This IP address is assigned by default to the Management port of the virtual gateway and can be used to access the web user interface or the command-line interface of the appliance. Reference: [Cisco Secure Email Gateway Installation and Upgrade Guide - Configuring Network Settings]

DRAG DROP

Drag and drop authentication options for End-User Quarantine Access from the left onto the corresponding configuration steps on the right.

Question 145
Correct answer: Question 145

A network administrator enabled McAfee antivirus scanning on a Cisco Secure Email Gateway and configured the virus scanning action of "scan for viruses only" If the scanner finds a virus in an attachment for an incoming email, what action will be applied to this message?

A.

The email and attachment are forwarded to the network administrator.

A.

The email and attachment are forwarded to the network administrator.

Answers
B.

No repair is attempted, and the attachment is either dropped or delivered

B.

No repair is attempted, and the attachment is either dropped or delivered

Answers
C.

The attachment is dropped and replaced with a "Removed Attachment" file

C.

The attachment is dropped and replaced with a "Removed Attachment" file

Answers
D.

The system will attempt to repair the attachment

D.

The system will attempt to repair the attachment

Answers
Suggested answer: B

Explanation:

If the McAfee antivirus scanning is enabled on the Cisco Secure Email Gateway and the virus scanning action is set to "scan for viruses only", then no repair is attempted, and the attachment is either dropped or delivered based on the antivirus policy settings. The administrator can choose to drop or deliver the infected attachment by selecting the appropriate action in the antivirus policy. Reference: [Cisco Secure Email Gateway Administrator Guide - Configuring McAfee Antivirus Scanning]

What is a benefit of deploying Cisco Secure Email and Web Manager?

A.

centralized management of software updates for Cisco Secure Email Gateway

A.

centralized management of software updates for Cisco Secure Email Gateway

Answers
B.

centralized management of logs for Cisco Secure Email Gateway

B.

centralized management of logs for Cisco Secure Email Gateway

Answers
C.

centralized management of quarantined email

C.

centralized management of quarantined email

Answers
D.

centralized management of botnet directories

D.

centralized management of botnet directories

Answers
Suggested answer: C

Explanation:

One of the benefits of deploying Cisco Secure Email and Web Manager is that it provides centralized management of quarantined email for multiple Cisco Secure Email Gateway appliances. The administrator can use the Cisco Secure Email and Web Manager to view, search, release, delete, or forward quarantined messages from a single web interface. Reference: [Cisco Secure Email and Web Manager User Guide - Configuring Centralized Spam Quarantine]

An organization wants to use its existing Cisco ESA to host a new domain and enforce a separate corporate policy for that domain.

What should be done on the Cisco ESA to achieve this?

A.

Use the altrchost command to add a separate gateway for the new domain.

A.

Use the altrchost command to add a separate gateway for the new domain.

Answers
B.

Use the deli very config command to configure mail delivery for the new domain.

B.

Use the deli very config command to configure mail delivery for the new domain.

Answers
C.

Use the dsestconf command to add a separate destination for the new domain.

C.

Use the dsestconf command to add a separate destination for the new domain.

Answers
D.

Use the smtproutes command to configure a SMTP route for the new domain.

D.

Use the smtproutes command to configure a SMTP route for the new domain.

Answers
Suggested answer: D

Explanation:

Reference:

https://www.cisco.com/c/en/us/td/docs/security/esa/esa12-0/user_guide/b_ESA_Admin_Guide_12_0/b_ESA_Admin_Guide_12_0_chapter_011001.html one of the steps to accept mail for additional internal domains on the Cisco ESA is to choose Network > SMTP Routes and enter the new domain and the corresponding destination host IP address1. This can also be done using the smtproutes command in the CLI1. The other commands (deliveryconfig, dsestconf, and altrchost) are not related to this task.

Total 148 questions
Go to page: of 15