ExamGecko
Home Home / Cisco / 300-720

Cisco 300-720 Practice Test - Questions Answers, Page 8

Question list
Search
Search

List of questions

Search

Related questions











To comply with a recent audit, an engineer must configure anti-virus message handling options on the incoming mail policies to attach warnings to the subject of an email.

What should be configured to meet this requirement for known viral emails?

A.

Virus Infected Messages

A.

Virus Infected Messages

Answers
B.

Unscannable Messages

B.

Unscannable Messages

Answers
C.

Encrypted Messages

C.

Encrypted Messages

Answers
D.

Positively Identified Messages

D.

Positively Identified Messages

Answers
Suggested answer: A

Explanation:

Message Handling Settings:

Repaired Message Handling Messages are considered repaired if the message was completely scanned and all viruses have been repaired or removed. These messages will be delivered as is.

Encrypted Message Handling

Messages are considered encrypted if the engine is unable to finish the scan due to an encrypted or protected field in the message. Messages that are marked encrypted may also be repaired.

Unscannable Message Handling Messages are considered unscannable if a scanning timeout value has been reached, or the engine becomes unavailable due to an internal error. Messages that are marked unscannable may also be repaired.

Virus Infected Message Handling The system may be unable to drop the attachment or completely repair a message. In these cases, you can configure how the system handles messages that could still contain viruses.

https://www.cisco.com/c/en/us/td/docs/security/esa/esa12-0/user_guide/b_ESA_Admin_Guide_12_0/b_ESA_Admin_Guide_chapter_01011.html#con_1132282

An administrator is managing multiple Cisco ESA devices and wants to view the quarantine emails from all devices in a central location.

How is this accomplished?

A.

Disable the VOF feature before sending SPAM to the external quarantine.

A.

Disable the VOF feature before sending SPAM to the external quarantine.

Answers
B.

Configure a mail policy to determine whether the message is sent to the local or external quarantine.

B.

Configure a mail policy to determine whether the message is sent to the local or external quarantine.

Answers
C.

Disable the local quarantine before sending SPAM to the external quarantine.

C.

Disable the local quarantine before sending SPAM to the external quarantine.

Answers
D.

Configure a user policy to determine whether the message is sent to the local or external quarantine.

D.

Configure a user policy to determine whether the message is sent to the local or external quarantine.

Answers
Suggested answer: C

Explanation:

Disabling the Local Spam Quarantine to Activate the External Quarantine If you were using a local spam quarantine before enabling an external spam quarantine, you must disable the local quarantine in order to send messages to the external quarantine.

https://www.cisco.com/c/en/us/td/docs/security/esa/esa11-1/user_guide/b_ESA_Admin_Guide_11_1/b_ESA_Admin_Guide_chapter_0101010.html?bookSearch=true#con_1172419

A Cisco ESA administrator has several mail policies configured. While testing policy match using a specific sender, the email was not matching the expected policy.

What is the reason of this?

A.

The Tram* header is checked against all policies in a top-down fashion.

A.

The Tram* header is checked against all policies in a top-down fashion.

Answers
B.

The message header with the highest priority is checked against each policy in a top-down fashion.

B.

The message header with the highest priority is checked against each policy in a top-down fashion.

Answers
C.

The To" header is checked against all policies in a top-down fashion.

C.

The To" header is checked against all policies in a top-down fashion.

Answers
D.

The message header with the highest priority is checked against the Default policy in a top-down fashion.

D.

The message header with the highest priority is checked against the Default policy in a top-down fashion.

Answers
Suggested answer: B

Explanation:

The envelope sender and the envelope recipeint have a higher priority over the sender header when you match a message to a mail policy. If you configure a mail policy to match a specific user, the messages are automatically classified into the mail policy based on the envelope sender and the envelope recipient. https://www.cisco.com/c/en/us/td/docs/security/esa/esa11-1/user_guide/b_ESA_Admin_Guide_11_1/b_ESA_Admin_Guide_chapter_01001.html

An administrator identifies that, over the past week, the Cisco ESA is receiving many emails from certain senders and domains which are being consistently quarantined. The administrator wants to ensure that these senders and domain are unable to send anymore emails.

Which feature on Cisco ESA should be used to achieve this?

A.

incoming mail policies

A.

incoming mail policies

Answers
B.

safelist

B.

safelist

Answers
C.

blocklist

C.

blocklist

Answers
D.

S/MIME Sending Profile

D.

S/MIME Sending Profile

Answers
Suggested answer: A

Explanation:

The appliance enforces your organization's policies for messages sent to and from your users through the use of mail policies. These are sets of rules that specify the types of suspect, sensitive, or malicious content that your organization may not want entering or leaving your network. This content may include:

-spam

-legitimate marketing messages

-graymail

-viruses

-phishing and other targeted mail attacks

-confidential corporate data

-personally identifiable information

https://www.cisco.com/c/en/us/td/docs/security/esa/esa11-1/user_guide/b_ESA_Admin_Guide_11_1/b_ESA_Admin_Guide_chapter_01001.html?bookSearch=true

An engineer is testing mail flow on a new Cisco ESA and notices that messages for domain abc.com are stuck in the delivery queue. Upon further investigation, the engineer notices that the messages pending delivery are destined for 192.168.1.11, when they should instead be routed to 192.168.1.10.

What configuration change needed to address this issue?

A.

Add an address list for domain abc.com.

A.

Add an address list for domain abc.com.

Answers
B.

Modify Destination Controls entry for the domain abc.com.

B.

Modify Destination Controls entry for the domain abc.com.

Answers
C.

Modify the SMTP route for the domain and change the IP address to 192.168.1.10.

C.

Modify the SMTP route for the domain and change the IP address to 192.168.1.10.

Answers
D.

Modify the Routing Tables and add a route for IP address to 192.168.1.10.

D.

Modify the Routing Tables and add a route for IP address to 192.168.1.10.

Answers
Suggested answer: C

Explanation:

Reference: https://www.cisco.com/c/en/us/support/docs/security/email-security-appliance/118136-qanda-esa-00.html

You can use the SMTP route feature on Cisco ESA to specify how messages for a specific domain are routed to their destination. You can modify the SMTP route for the domain abc.com and change the IP address to 192.168.1.10 to ensure that messages are delivered correctly3. Reference = Securing Email with Cisco Email Security Appliance (SESA) v3.1

Refer to the exhibit. An engineer is trying to connect to a Cisco ESA using SSH and has been unsuccessful. Upon further inspection, the engineer notices that there is a loss of connectivity to the neighboring switch.

Which connection method should be used to determine the configuration issue?

A.

Telnet

A.

Telnet

Answers
B.

HTTPS

B.

HTTPS

Answers
C.

Ethernet

C.

Ethernet

Answers
D.

serial

D.

serial

Answers
Suggested answer: D

Explanation:

Serial connection is a method that should be used to determine the configuration issue when there is a loss of connectivity to the neighboring switch. Serial connection allows the engineer to access the Cisco ESA console port using a serial cable and a terminal emulator, such as PuTTY or HyperTerminal, without relying on the network connectivity.

The other options are not valid methods to determine the configuration issue when there is a loss of connectivity to the neighboring switch, because they require network connectivity to work.

Reference: Cisco Email Security Appliance C690 Quickstart Guide, page 2.

Refer to the exhibit. How should this configuration be modified to stop delivering Zero Day malware attacks?

A.

Change Unscannable Action from Deliver As Is to Quarantine.

A.

Change Unscannable Action from Deliver As Is to Quarantine.

Answers
B.

Change File Analysis Pending action from Deliver As Is to Quarantine.

B.

Change File Analysis Pending action from Deliver As Is to Quarantine.

Answers
C.

Configure mailbox auto-remediation.

C.

Configure mailbox auto-remediation.

Answers
D.

Apply Prepend on Modify Message Subject under Malware Attachments.

D.

Apply Prepend on Modify Message Subject under Malware Attachments.

Answers
Suggested answer: B

Explanation:

Overview of File Reputation Filtering and File Analysis:

Advanced Malware Protection protects against zero-day and targeted file-based threats in email attachments by:

-Obtaining the reputation of known files.

-Analyzing behavior of certain files that are not yet known to the reputation service.

-Continuously evaluating emerging threats as new information becomes available, and notifying you about files that are determined to be threats after they have entered your network.

-This feature is available for incoming messages and outgoing messages.

https://www.cisco.com/c/en/us/td/docs/security/esa/esa11-1/user_guide/b_ESA_Admin_Guide_11_1/b_ESA_Admin_Guide_chapter_010000.html?bookSearch=true

Which method enables an engineer to deliver a flagged message to a specific virtual gateway address in the most flexible way?

A.

Set up the interface group with the flag.

A.

Set up the interface group with the flag.

Answers
B.

Issue the altsrchost command.

B.

Issue the altsrchost command.

Answers
C.

Map the envelope sender address to the host.

C.

Map the envelope sender address to the host.

Answers
D.

Apply a filter on the message.

D.

Apply a filter on the message.

Answers
Suggested answer: D

Explanation:

A filter is a method that enables an engineer to deliver a flagged message to a specific virtual gateway address in the most flexible way. A filter is a rule that allows Cisco ESA to perform actions on messages based on predefined or custom conditions, such as headers, envelope, body, attachments, etc.

To deliver a flagged message to a specific virtual gateway address using a filter, the engineer can create a content filter or message filter that matches the flag condition and applies an action of "deliver via alternate host" with the virtual gateway address as the parameter.

The other options are not methods that enable an engineer to deliver a flagged message to a specific virtual gateway address in the most flexible way, because they have more limitations or requirements than using a filter.

Reference: User Guide for AsyncOS 15.0 for Cisco Secure Email Gateway, page 8-3 and page 8-7.

A Cisco ESA administrator was notified that a user was not receiving emails from a specific domain.

After reviewing the mail logs, the sender had a negative sender-based reputation score.

What should the administrator do to allow inbound email from that specific domain?

A.

Create a new inbound mail policy with a message filter that overrides Talos.

A.

Create a new inbound mail policy with a message filter that overrides Talos.

Answers
B.

Ask the user to add the sender to the email application's allow list.

B.

Ask the user to add the sender to the email application's allow list.

Answers
C.

Modify the firewall to allow emails from the domain.

C.

Modify the firewall to allow emails from the domain.

Answers
D.

Add the domain into the allow list.

D.

Add the domain into the allow list.

Answers
Suggested answer: D

Explanation:

The allow list is a feature that allows Cisco ESA to accept messages from specific email addresses or domains, regardless of their sender-based reputation score or other reputation filters.

To allow inbound email from that specific domain, the administrator should add the domain into the allow list on Cisco ESA, which can be done from the web user interface by selecting Security Services > Safelist/Blocklist and clicking Add Entry.

The other options are not valid solutions to allow inbound email from that specific domain, because they do not affect the sender-based reputation score or the reputation filters on Cisco ESA.

Reference: User Guide for AsyncOS 15.0 for Cisco Secure Email Gateway, page 6-13 and page 6-14.

An email containing a URL passes through the Cisco ESA that has content filtering disabled for all mail policies. The sender is [email protected], the recipients are [email protected], [email protected], [email protected], and [email protected]. The subject of the email is Test Document395898847. An administrator wants to add a policy to ensure that the Cisco ESA evaluates the web reputation score before permitting this email.

Which two criteria must be used by the administrator to achieve this? (Choose two.)

A.

Subject contains Test Document"

A.

Subject contains Test Document"

Answers
B.

Sender matches test1.com

B.

Sender matches test1.com

Answers
C.

Email body contains a URL

C.

Email body contains a URL

Answers
D.

Date and time of email

D.

Date and time of email

Answers
E.

Email does not match [email protected]

E.

Email does not match [email protected]

Answers
Suggested answer: B, C

Explanation:

Web reputation score is a feature that allows Cisco ESA to evaluate the reputation of URLs in messages based on real-time data from Talos intelligence and apply appropriate actions, such as block, quarantine, or deliver.

To ensure that Cisco ESA evaluates the web reputation score before permitting this email, the administrator should use two criteria to create a content filter or message filter that matches this email and applies an action of "check web reputation":

Sender matches test1.com, which means that the sender's domain name is test1.com.

Email body contains a URL, which means that the message body has one or more URLs in it.

The other options are not valid criteria to ensure that Cisco ESA evaluates the web reputation score before permitting this email, because they do not match this email or they are not relevant to web reputation score.

Reference: User Guide for AsyncOS 15.0 for Cisco Secure Email Gateway, page 8-3 and page 8-7.

Total 148 questions
Go to page: of 15