ExamGecko
Home Home / Cisco / 300-720

Cisco 300-720 Practice Test - Questions Answers, Page 7

Question list
Search
Search

Related questions











What is a benefit of implementing URL filtering on the Cisco ESA?

A.

removes threats from malicious URLs

A.

removes threats from malicious URLs

Answers
B.

blacklists spam

B.

blacklists spam

Answers
C.

provides URL reputation protection

C.

provides URL reputation protection

Answers
D.

enhances reputation against malicious URLs

D.

enhances reputation against malicious URLs

Answers
Suggested answer: C

Explanation:

A benefit of implementing URL filtering on the ESA is that it provides URL reputation protection. URL filtering uses SenderBase, a web-based service that collects information about URLs and domains from various sources, to assign a reputation score and a category to each URL. Based on these attributes, you can configure content or message filters to take actions on messages containing malicious or undesirable URLs.

Reference: User Guide for AsyncOS 12.0 for Cisco Email Security Appliances - GD (General Deployment), Chapter: Protecting Against Malicious or Undesirable URLs, Section: URL-Related Protections and Controls Reference: https://www.cisco.com/c/en/us/support/docs/security/email-security-appliance/118775-technote- esa-00.html

Refer to the exhibit.

Which SPF record is valid for mycompany.com?

A.

v=spf1 a mx ip4:199.209.31.2 -all

A.

v=spf1 a mx ip4:199.209.31.2 -all

Answers
B.

v=spf1 a mx ip4:10.1.10.23 -all

B.

v=spf1 a mx ip4:10.1.10.23 -all

Answers
C.

v=spf1 a mx ip4:199.209.31.21 -all

C.

v=spf1 a mx ip4:199.209.31.21 -all

Answers
D.

v=spf1 a mx ip4:172.16.18.230 -all

D.

v=spf1 a mx ip4:172.16.18.230 -all

Answers
Suggested answer: C

Explanation:

The SPF record for mycompany.com is shown in the exhibit as:

v=spf1 a mx ip4:199.209.31.21 -all

This means that the domain mycompany.com authorizes the following sources to send email on its behalf:

The A record of mycompany.com, which resolves to 199.209.31.21

The MX record of mycompany.com, which points to mail.mycompany.com, which also resolves to 199.209.31.21

The IP address 199.209.31.21

The -all qualifier means that any other source is not authorized and should be rejected.

Therefore, the correct answer is C.

Reference:

SPF Record Syntax

Define your SPF recordasic setup

What is a valid content filter action?

A.

decrypt on delivery

A.

decrypt on delivery

Answers
B.

quarantine

B.

quarantine

Answers
C.

skip antispam

C.

skip antispam

Answers
D.

archive

D.

archive

Answers
Suggested answer: B

Explanation:

A content filter action is an operation that Cisco ESA performs on a message if it matches the conditions of a content filter rule, such as headers, envelope, body, attachments, etc.

Quarantine is a valid content filter action that allows Cisco ESA to store the message in a quarantine area for further review or release by an administrator or an end user.

The other options are not valid content filter actions on Cisco ESA.

Reference: User Guide for AsyncOS 15.0 for Cisco Secure Email Gateway, page 8-3 and page 8-7.

Reference: https://www.cisco.com/c/en/us/td/docs/security/esa/esa12-0/user_guide/b_ESA_Admin_Guide_12_0/b_ESA_Admin_Guide_chapter_01010.html#con_1158022

When virtual gateways are configured, which two distinct attributes are allocated to each virtual gateway address? (Choose two.)

A.

domain

A.

domain

Answers
B.

IP address

B.

IP address

Answers
C.

DNS server address

C.

DNS server address

Answers
D.

DHCP server address

D.

DHCP server address

Answers
E.

external spam quarantine

E.

external spam quarantine

Answers
Suggested answer: A, B

Explanation:

Virtual gateways are a feature that allows Cisco ESA to host multiple email domains on a single physical interface, using different IP addresses and hostnames for each domain.

When virtual gateways are configured, two distinct attributes are allocated to each virtual gateway address:

Domain, which is the email domain name that is associated with the virtual gateway address, such as mycompany.com or mydomain.com.

IP address, which is the IPv4 or IPv6 address that is assigned to the virtual gateway address, such as 199.209.31.X or 2001:db8::X.

The other options are not attributes that are allocated to each virtual gateway address on Cisco ESA.

Reference: User Guide for AsyncOS 15.0 for Cisco Secure Email Gateway, page 5-14 and page 5-15.

Reference: https://www.cisco.com/c/en/us/support/docs/security/email-security-appliance/118542-qa-esa- 00.html

When the Cisco ESA is configured to perform antivirus scanning, what is the default timeout value?

A.

30 seconds

A.

30 seconds

Answers
B.

90 seconds

B.

90 seconds

Answers
C.

60 seconds

C.

60 seconds

Answers
D.

120 seconds

D.

120 seconds

Answers
Suggested answer: C

Explanation:

When Cisco ESA is configured to perform antivirus scanning, the default timeout value is 60 seconds, which means that Cisco ESA will wait for 60 seconds for the antivirus engine to scan a message before applying the configured action for unscannable messages, such as deliver, drop, or quarantine.

Reference: User Guide for AsyncOS 15.0 for Cisco Secure Email Gateway, page 7-3.

Reference: https://www.cisco.com/c/en/us/td/docs/security/esa/esa12-0/user_guide/b_ESA_Admin_Guide_12_0/b_ESA_Admin_Guide_chapter_01011.html

Which global setting is configured under Cisco ESA Scan Behavior?

A.

minimum attachment size to scan

A.

minimum attachment size to scan

Answers
B.

attachment scanning timeout

B.

attachment scanning timeout

Answers
C.

actions for unscannable messages due to attachment type

C.

actions for unscannable messages due to attachment type

Answers
D.

minimum depth of attachment recursion to scan

D.

minimum depth of attachment recursion to scan

Answers
Suggested answer: C

Explanation:

The global setting that is configured under Cisco ESA Scan Behavior is the actions for unscannable messages due to attachment type. This setting allows the administrator to specify what action to take when a message contains an attachment that cannot be scanned by the appliance, such as encrypted or password-protected files. The possible actions are:

Deliver - Deliver the message normally.

Drop - Drop the message silently without notifying the sender or recipient.

Quarantine - Quarantine the message in a specified policy quarantine.

Bounce - Bounce the message back to the sender with a specified reason.

Reference:

Scan Behavior

Reference: https://community.cisco.com/t5/email-security/cisco-ironport-esa-security-services-scanbehavior-impact-on-av/td-p/3923243

Which action on the Cisco ESA provides direct access to view the safelist/blocklist?

A.

Show the SLBL cache on the CLI.

A.

Show the SLBL cache on the CLI.

Answers
B.

Monitor Incoming/Outgoing Listener.

B.

Monitor Incoming/Outgoing Listener.

Answers
C.

Export the SLBL to a .csv file.

C.

Export the SLBL to a .csv file.

Answers
D.

Debug the mail flow policy.

D.

Debug the mail flow policy.

Answers
Suggested answer: C

Explanation:

The safelist/blocklist (SLBL) is a feature that allows Cisco ESA to accept or reject messages from specific email addresses or domains, based on the configuration of mail flow policies or end user preferences.

The action that provides direct access to view the SLBL on Cisco ESA is to export the SLBL to a .csv file, which can be done from the web user interface by selecting Security Services > Safelist/Blocklist and clicking Export.

The other options do not provide direct access to view the SLBL on Cisco ESA.

Reference: User Guide for AsyncOS 15.0 for Cisco Secure Email Gateway, page 6-13 and page 6-14.

Reference: https://www.cisco.com/c/en/us/support/docs/security/email-security-appliance/117922-technote- esa-00.html

Which scenario prevents a message from being sent to the quarantine as an action in the scan behavior on Cisco ESA?

A.

A policy quarantine is missing.

A.

A policy quarantine is missing.

Answers
B.

More than one email pipeline is defined.

B.

More than one email pipeline is defined.

Answers
C.

The "modify the message subject" is already set.

C.

The "modify the message subject" is already set.

Answers
D.

The "add custom header" action is performed first.

D.

The "add custom header" action is performed first.

Answers
Suggested answer: A

Explanation:

A policy quarantine is a type of quarantine that allows Cisco ESA to store messages that match certain criteria, such as virus, spam, or DLP verdicts, for further review or release by an administrator or an end user.

A scenario that prevents a message from being sent to the quarantine as an action in the scan behavior on Cisco ESA is when a policy quarantine is missing, which means that no policy quarantine has been created or enabled on Cisco ESA.

The other options do not prevent a message from being sent to the quarantine as an action in the scan behavior on Cisco ESA.

Reference: User Guide for AsyncOS 15.0 for Cisco Secure Email Gateway, page 10-2 and page 10-3.

What are two primary components of content filters? (Choose two.)

A.

conditions

A.

conditions

Answers
B.

subject

B.

subject

Answers
C.

content

C.

content

Answers
D.

actions

D.

actions

Answers
E.

policies

E.

policies

Answers
Suggested answer: A, D

Explanation:

Content filters are rules that allow Cisco ESA to perform actions on messages based on predefined or custom conditions, such as headers, envelope, body, attachments, etc.

The two primary components of content filters are:

Conditions, which are the criteria that determine whether a message matches a content filter rule or not, such as message size, sender address, attachment type, etc.

Actions, which are the operations that Cisco ESA performs on a message if it matches the conditions of a content filter rule, such as deliver, drop, quarantine, encrypt, etc.

The other options are not primary components of content filters on Cisco ESA.

Reference: User Guide for AsyncOS 15.0 for Cisco Secure Email Gateway, page 8-3 and page 8-4.

Reference: https://www.cisco.com/c/en/us/td/docs/security/ces/user_guide/esa_user_guide_11-1/b_ESA_Admin_Guide_ces_11_1/b_ESA_Admin_Guide_chapter_01010.pdf

A network administrator is modifying an outgoing mail policy to enable domain protection for the organization. A DNS entry is created that has the public key.

Which two headers will be used as matching criteria in the outgoing mail policy? (Choose two.)

A.

message-ID

A.

message-ID

Answers
B.

sender

B.

sender

Answers
C.

URL reputation

C.

URL reputation

Answers
D.

from

D.

from

Answers
E.

mail-from

E.

mail-from

Answers
Suggested answer: B, D

Explanation:

To enable domain protection for the organization, the administrator must configure an outgoing mail policy that matches the sender and the from headers of the email. The sender header is the envelope sender address that is used by SMTP to route the email. The from header is the address that is displayed to the recipient as the source of the email. These headers are used to generate and verify a DomainKeys Identified Mail (DKIM) signature, which is a cryptographic method of validating the authenticity and integrity of an email message.

The other headers are not relevant for domain protection. The message-ID header is a unique identifier for each email message. The URL reputation header is a score that indicates the likelihood of a URL being malicious. The mail-from header is an alias for the sender header.

Reference:

Domain Protection

DKIM Signing

Total 148 questions
Go to page: of 15