ExamGecko
Home Home / Cisco / 300-720

Cisco 300-720 Practice Test - Questions Answers, Page 3

Question list
Search
Search

Related questions











When email authentication is configured on Cisco ESA, which two key types should be selected on the signing profile? (Choose two.)

A.

DKIM

A.

DKIM

Answers
B.

Public Keys

B.

Public Keys

Answers
C.

Domain Keys

C.

Domain Keys

Answers
D.

Symmetric Keys

D.

Symmetric Keys

Answers
E.

Private Keys

E.

Private Keys

Answers
Suggested answer: B, E

Explanation:

With DomainKeys or DKIM email authentication, the sender signs the email using public key cryptography. Configuring DomainKeys and DKIM Signing A signing key is the private key stored on the appliance. https://www.cisco.com/c/en/us/td/docs/security/esa/esa11-1/user_guide/b_ESA_Admin_Guide_11_1/b_ESA_Admin_Guide_chapter_010101.html?bookSearch=true

What are two phases of the Cisco ESA email pipeline? (Choose two.)

A.

reject

A.

reject

Answers
B.

workqueue

B.

workqueue

Answers
C.

action

C.

action

Answers
D.

delivery

D.

delivery

Answers
E.

quarantine

E.

quarantine

Answers
Suggested answer: B, D

Explanation:

With DomainKeys or DKIM email authentication, the sender signs the email using public key cryptography. Configuring DomainKeys and DKIM Signing A signing key is the private key stored on the appliance. https://www.cisco.com/c/en/us/td/docs/security/esa/esa11-1/user_guide/b_ESA_Admin_Guide_11_1/b_ESA_Admin_Guide_chapter_010101.html?bookSearch=true

Reference: https://www.cisco.com/c/en/us/td/docs/security/esa/esa12-1/user_guide/b_ESA_Admin_Guide_12_1/b_ESA_Admin_Guide_12_1_chapter_011.pdf (p.1)

Which two action types are performed by Cisco ESA message filters? (Choose two.)

A.

non-final actions

A.

non-final actions

Answers
B.

filter actions

B.

filter actions

Answers
C.

discard actions

C.

discard actions

Answers
D.

final actions

D.

final actions

Answers
E.

quarantine actions

E.

quarantine actions

Answers
Suggested answer: A, D

Explanation:

Non-final actions are actions that do not terminate the message filter evaluation, such as adding headers, setting variables, logging, etc. Final actions are actions that end the message filter evaluation and determine the fate of the message, such as accept, drop, bounce, quarantine, etc.

Reference: User Guide for AsyncOS 15.0 for Cisco Secure Email Gateway, page 3-4.

Reference: https://www.cisco.com/c/en/us/td/docs/security/esa/esa11-1/user_guide/b_ESA_Admin_Guide_11_1/b_ESA_Admin_Guide_chapter_01000.html

Which setting affects the aggressiveness of spam detection?

A.

protection level

A.

protection level

Answers
B.

spam threshold

B.

spam threshold

Answers
C.

spam timeout

C.

spam timeout

Answers
D.

maximum depth of recursion scan

D.

maximum depth of recursion scan

Answers
Suggested answer: B

Explanation:

Spam threshold is a setting that determines the minimum score that a message must have to be classified as spam by Cisco ESA. The lower the threshold, the more aggressive the spam detection is.

Reference: User Guide for AsyncOS 15.0 for Cisco Secure Email Gateway, page 6-5.

Reference: https://www.cisco.com/c/en/us/support/docs/security/email-security-appliance/118220-technote- esa-00.html

What is the order of virus scanning when multilayer antivirus scanning is configured?

A.

The default engine scans for viruses first and the McAfee engine scans for viruses second.

A.

The default engine scans for viruses first and the McAfee engine scans for viruses second.

Answers
B.

The Sophos engine scans for viruses first and the McAfee engine scans for viruses second.

B.

The Sophos engine scans for viruses first and the McAfee engine scans for viruses second.

Answers
C.

The McAfee engine scans for viruses first and the default engine scans for viruses second.

C.

The McAfee engine scans for viruses first and the default engine scans for viruses second.

Answers
D.

The McAfee engine scans for viruses first and the Sophos engine scans for viruses second.

D.

The McAfee engine scans for viruses first and the Sophos engine scans for viruses second.

Answers
Suggested answer: D

Explanation:

https://www.cisco.com/c/en/us/td/docs/security/esa/esa12-0/user_guide/b_ESA_Admin_Guide_12_0/b_ESA_Admin_Guide_chapter_01011.html

According to the User Guide for AsyncOS 12.0 for Cisco Email Security Appliances2, the order of virus scanning when multilayer antivirus scanning is configured is as follows:

The McAfee engine scans the message first. If the McAfee engine detects a virus, the message is dropped or repaired, depending on the configuration. If the McAfee engine does not detect a virus, the message is passed to the next layer of scanning.

The Sophos engine scans the message second. If the Sophos engine detects a virus, the message is dropped or repaired, depending on the configuration. If the Sophos engine does not detect a virus, the message is delivered to the recipient.

Which antispam feature is utilized to give end users control to allow emails that are spam to be delivered to their inbox, overriding any spam verdict and action on the Cisco ESA?

A.

end user allow list

A.

end user allow list

Answers
B.

end user spam quarantine access

B.

end user spam quarantine access

Answers
C.

end user passthrough list

C.

end user passthrough list

Answers
D.

end user safelist

D.

end user safelist

Answers
Suggested answer: D

Explanation:

End user safelist is a feature that allows end users to specify email addresses or domains that they want to receive messages from, regardless of the spam verdict or action assigned by Cisco ESA.

Messages from senders on the end user safelist are delivered to the end user's inbox without any spam filtering.

Reference: User Guide for AsyncOS 15.0 for Cisco Secure Email Gateway, page 10-13.

What are two prerequisites for implementing undesirable URL protection in Cisco ESA? (Choose two.)

A.

Enable outbreak filters.

A.

Enable outbreak filters.

Answers
B.

Enable email relay.

B.

Enable email relay.

Answers
C.

Enable antispam scanning.

C.

Enable antispam scanning.

Answers
D.

Enable port bouncing.

D.

Enable port bouncing.

Answers
E.

Enable antivirus scanning.

E.

Enable antivirus scanning.

Answers
Suggested answer: A, C

Explanation:

Undesirable URL protection is a feature that allows Cisco ESA to detect and block messages that contain URLs that lead to malicious or unwanted websites, such as phishing, malware, or adult content sites. To enable this feature, outbreak filters and antispam scanning must be enabled on Cisco ESA.

Reference: User Guide for AsyncOS 15.0 for Cisco Secure Email Gateway, page 6-17.

Reference: https://www.cisco.com/c/en/us/td/docs/security/esa/esa12-0/user_guide/b_ESA_Admin_Guide_12_0/b_ESA_Admin_Guide_chapter_01111.html

DRAG DROP

Drag and drop the steps to configure Cisco ESA to use SPF/SIDF verification from the left into the correct order on the right.

Question 28
Correct answer: Question 28

Explanation:


Which suboption must be selected when LDAP is configured for Spam Quarantine End-User Authentication?

A.

Designate as the active query

A.

Designate as the active query

Answers
B.

Update Frequency

B.

Update Frequency

Answers
C.

Server Priority

C.

Server Priority

Answers
D.

Entity ID

D.

Entity ID

Answers
Suggested answer: A

Explanation:

According to the User Guide1, the steps to configure End-User Access to the Spam Quarantine via LDAP are as follows:

On the ESA, choose System Administration > LDAP > LDAP Server Profile page.

Click Add LDAP Server Profile.

Enter a name for the profile and click Submit.

Click Add Query.

Enter a name for the query and click Submit.

Configure the query settings, such as server address, port number, base DN, scope, filter, and attributes.

Check the Spam Quarantine End-User Authentication Query check box. This is the suboption that enables LDAP authentication for end users who access the spam quarantine.

Check the Designate as the active query check box. This is the suboption that specifies which query to use for end-user authentication. Only one query can be active at a time.

Click Submit and commit changes.

On the ESA, choose Monitor > Spam Quarantine > End-User Quarantine Access.

Check the Enable End-User Quarantine Access check box.

Choose LDAP from the End-User Authentication drop-down list.

Select the LDAP profile and query that you created earlier from the drop-down lists.

Click Submit and commit changes.

Reference: https://www.cisco.com/c/en/us/td/docs/security/security_management/sma/sma11-5/user_guide/ b_SMA_Admin_Guide_11_5/b_SMA_Admin_Guide_11_5_chapter_01010.html

Which action must be taken before a custom quarantine that is being used can be deleted?

A.

Delete the quarantine that is assigned to a filter.

A.

Delete the quarantine that is assigned to a filter.

Answers
B.

Delete the quarantine that is not assigned to a filter.

B.

Delete the quarantine that is not assigned to a filter.

Answers
C.

Delete only the unused quarantine.

C.

Delete only the unused quarantine.

Answers
D.

Remove the quarantine from the message action of a filter.

D.

Remove the quarantine from the message action of a filter.

Answers
Suggested answer: D

Explanation:

Before a custom quarantine that is being used can be deleted, it must be removed from the message action of any filter that is using it on Cisco ESA. Otherwise, an error message will appear stating that the quarantine cannot be deleted because it is in use.

Reference: User Guide for AsyncOS 15.0 for Cisco Secure Email Gateway, page 10-5.

Reference: https://www.cisco.com/c/en/us/td/docs/security/esa/esa12-0/user_guide/b_ESA_Admin_Guide_12_0/b_ESA_Admin_Guide_12_0_chapter_011111.html

Total 148 questions
Go to page: of 15