Get 100% Authentic Cisco 300-720 Dumps with Correct Answers
New Training Course 300-720 Tutorial Preparation Guide
NEW QUESTION # 84
An engineer is tasked with reviewing mail logs to confirm that messages sent from domain abc.com are passing SPF verification and being accepted by the Cisco ESA. The engineer notices that SPF verification is not being performed and that SPF is not being referenced in the logs for messages sent from domain abc.com.
Why is the verification not working properly?
- A. SPF verification is disabled on the Mail Flow Policy.
- B. The SPF conformance level is set to SIDF compatible on the Mail Flow Policy.
- C. SPF verification is disabled in the Recipient Access Table.
- D. An SPF verification Content Filter has not been created.
Answer: D
NEW QUESTION # 85
An administrator is trying to enable centralized PVO but receives the error, "Unable to proceed with Centralized Policy, Virus and Outbreak Quarantines configuration as esa1 in Cluster has content filters / DLP actions available at a level different from the cluster level." What is the cause of this error?
- A. DLP is not configured on host1.
- B. DLP is configured at the domain-level on esa1.
- C. DLP is configured at the cluster-level on esa2.
- D. Content filters are configured at the machine-level on esa1.
Answer: A
Explanation:
Reference:
https://www.cisco.com/c/en/us/support/docs/security/email-security-appliance/118026-technote- esa-00.html
NEW QUESTION # 86
An analyst creates a new content dictionary to use with Forged Email Detection.
Which entry will be added into the dictionary?
- A. mycompany.com
- B. [email protected]
- C. Alpha Beta
- D. ^Alpha\ Beta$
Answer: C
Explanation:
https://www.cisco.com/c/en/us/td/docs/security/esa/esa13-
0/user_guide/b_ESA_Admin_Guide_13-0.pdf p.675
NEW QUESTION # 87
The CEO added a sender to a safelist but does not receive an important message expected from the trusted sender. An engineer evaluates message tracking on the Cisco Secure Email Gateway appliance and determines that the message was dropped by the antivirus engine. What is the reason for this behavior?
- A. The sender is included in an ISP blocklist
- B. End-user safelists apply to antispam engines only.
- C. Administrative access is required to create a safelist.
- D. The sender didn't mark the message as urgent
Answer: B
Explanation:
The reason why the CEO did not receive an important message expected from a trusted sender after adding them to a safelist is because end-user safelists apply to antispam engines only. End-user safelists are lists of sender addresses or domains that end users can create and manage through their quarantine accounts or email clients. End-user safelists allow end users to accept or exempt messages from certain senders or domains from being identified as spam by the antispam engines. However, end-user safelists do not affect other filtering engines such as antivirus, outbreak filters, or content filters. Reference = User Guide for AsyncOS 12.0 for Cisco Email Security Appliances - GD (General Deployment) - Safelists and Blocklists [Cisco Secure Email Gateway] - Cisco
NEW QUESTION # 88
A trusted partner of an organization recently experienced a new campaign that was leveraging JavaScript attachments to trick users into executing malware. As a result, they created a local policy to deny messages with JavaScript attachments. Which action should the administrator of the organization take to ensure encrypted communications are delivered to the intended partner recipient?
- A. Select JavaScript-free' option within the Cisco Secure Email Encryption Service Add-in
- B. Create a new encryption profile and deselect the 'Use-Script' envelope settings option.
- C. Insert the X-PostX-Use-Script' header with a value of false to the encrypted messages
- D. Create an outgoing content filter and add the Encrypt and Deliver Nov/ action with Use-Script option deselected
Answer: B
Explanation:
According to the User Guide for Cisco Secure Email Encryption Service Add-In 1, the 'Use-Script' option allows you to use JavaScript in the encrypted message envelope. This option is enabled by default, but you can disable it if you want to send encrypted messages to recipients who have security policies that block JavaScript attachments[2, p. 14].
The other options are not valid because:
A) Inserting the X-PostX-Use-Script header with a value of false to the encrypted messages is not a supported feature of the Cisco Secure Email Encryption Service Add-in1.
B) Selecting JavaScript-free option within the Cisco Secure Email Encryption Service Add-in is not a valid option. The add-in does not have such an option1.
C) Creating an outgoing content filter and adding the Encrypt and Deliver Nov/ action with Use-Script option deselected is not possible. The Encrypt and Deliver Nov/ action does not have a Use-Script option[2, p. 13].
NEW QUESTION # 89
An organization wants to prevent proprietary patent documents from being shared externally via email. The network administrator reviewed the DLP policies on the Cisco Secure Email Gateway and could not find an existing policy with the appropriate matching patterns. Which type of DLP policy template must be used to create a policy that meets this requirement?
- A. regulatory compliance
- B. custom policy
- C. privacy protection
- D. acceptable use
Answer: B
Explanation:
Custom policy is a type of DLP policy template that must be used to create a policy that meets this requirement. Custom policy allows the administrator to define their own criteria for detecting sensitive or confidential data in messages, such as keywords, regular expressions, file types, etc.
To create a custom DLP policy on Cisco ESA, the administrator can follow these steps:
Select Mail Policies > DLP Policy Manager and click Add Policy.
Enter a name and description for the DLP policy, such as Patent Protection.
Under Policy Template, select Custom Policy.
Click Submit.
Under Content Matching Criteria, click Add Criteria.
Choose a matching type, such as Keyword or Regular Expression, and enter a value that matches the proprietary patent documents, such as "patent number" or "\d{4}/\d{6}".
Click Submit.
The other options are not valid types of DLP policy templates to create a policy that meets this requirement, because they are predefined templates that do not match the proprietary patent documents.
NEW QUESTION # 90
Refer to the exhibit.
Which SPF record is valid for mycompany.com?
- A. v=spf1 a mx ip4:172.16.18.230 -all
- B. v=spf1 a mx ip4:199.209.31.21 -all
- C. v=spf1 a mx ip4:10.1.10.23 -all
- D. v=spf1 a mx ip4:199.209.31.2 -all
Answer: A
NEW QUESTION # 91
What is the maximum message size that can be configured for encryption on the Cisco ESA?
- A. 25 MB
- B. 30 MB
- C. 15 MB
- D. 20 MB
Answer: A
Explanation:
https://www.cisco.com/c/en/us/td/docs/security/esa/esa13-
0/user_guide/b_ESA_Admin_Guide_13-0.pdf P.580
NEW QUESTION # 92
A network administrator notices that there are a high number of queries to the LDAP server. The mail logs show an entry "550 Too many invalid recipients | Connection closed by foreign host." Which feature must be used to address this?
- A. LDAP
- B. DHAP
- C. SMTP
- D. SBRS
Answer: C
NEW QUESTION # 93
A network administrator notices that there are a high number of queries to the LDAP server. The mail logs show an entry "550 Too many invalid recipients | Connection closed by foreign host." Which feature must be used to address this?
- A. LDAP
- B. SBRS
- C. DHAP
- D. SMTP
Answer: C
Explanation:
Reference:
https://www.cisco.com/c/en/us/td/docs/security/esa/esa12-0/user_guide/b_ESA_Admin_Guide_12_0/b_ESA_Admin_Guide_12_0_chapter_011010.html DHAP (Directory Harvest Attack Prevention) is a feature that must be used to address this issue. DHAP is a mechanism that allows Cisco ESA to prevent directory harvest attacks, which are attempts by spammers or hackers to obtain valid email addresses from an LDAP server by sending messages with random or guessed recipients and checking for bounce messages.
To enable DHAP on Cisco ESA, the network administrator can follow these steps:
Select Network > Listeners and click Edit Settings for the listener that receives incoming messages.
Under SMTP Authentication Settings, select Enable Directory Harvest Attack Prevention.
Enter a value for Maximum Invalid Recipients per Hour, which is the number of invalid recipients that triggers DHAP.
Enter a value for Block Sender for (hours), which is the duration that Cisco ESA blocks messages from senders who exceed the maximum invalid recipients per hour.
Click Submit.
NEW QUESTION # 94
What is the default behavior of any listener for TLS communication?
- A. required
- B. preferred
- C. preferred-verify
- D. off
Answer: D
Explanation:
Reference:
https://www.cisco.com/c/en/us/support/docs/security/email-security-appliance/118954-config-esa- 00.html
NEW QUESTION # 95
What is a benefit of implementing URL filtering on the Cisco ESA?
- A. provides URL reputation protection
- B. removes threats from malicious URLs
- C. enhances reputation against malicious URLs
- D. blacklists spam
Answer: A
Explanation:
A benefit of implementing URL filtering on the ESA is that it provides URL reputation protection. URL filtering uses SenderBase, a web-based service that collects information about URLs and domains from various sources, to assign a reputation score and a category to each URL. Based on these attributes, you can configure content or message filters to take actions on messages containing malicious or undesirable URLs.
NEW QUESTION # 96
What must be configured to allow the Cisco ESA to encrypt an email using the Cisco Registered Envelope Service?
- A. message encryption from a content filter that select "Message Encryption" over TLS
- B. provisioned email encryption profile
- C. content filter to forward the email to the Cisco Registered Envelope server
- D. message encryption from the mail flow policies with "CRES" selected
Answer: A
NEW QUESTION # 97
Which setting affects the aggressiveness of spam detection?
- A. protection level
- B. maximum depth of recursion scan
- C. spam threshold
- D. spam timeout
Answer: C
Explanation:
Spam threshold is a setting that determines the minimum score that a message must have to be classified as spam by Cisco ESA. The lower the threshold, the more aggressive the spam detection is.
NEW QUESTION # 98
Which two certificate authority lists are available in Cisco ESA? (Choose two.)
- A. demo
- B. custom
- C. default
- D. user
- E. system
Answer: B,E
Explanation:
Reference:
https://www.cisco.com/c/en/us/td/docs/security/esa/esa11-1/user_guide/ b_ESA_Admin_Guide_11_1/b_ESA_Admin_Guide_11_1_chapter_011000.html#task_1194859
NEW QUESTION # 99
An Encryption Profile has been set up on the Cisco ESA.
Drag and drop the steps from the left for creating an outgoing content filter to encrypt emails that contains the subject "Secure:" into the correct order on the right.
Answer:
Explanation:

NEW QUESTION # 100
Which SMTP extension does Cisco ESA support for email security?
- A. ETRN
- B. UTF8SMTP
- C. STARTTLS
- D. PIPELINING
Answer: C
Explanation:
Explanation/Reference: https://www.cisco.com/c/en/us/td/docs/security/esa/esa12-0/user_guide/ b_ESA_Admin_Guide_12_0/b_ESA_Admin_Guide_12_0_chapter_011000.html
NEW QUESTION # 101
Which action do Outbreak Filters take to stop small-scale and nonviral attacks, such as phishing scams and malware distribution sites?
- A. Quarantine messages that contain links to potentially harmful websites until the site is taken offline
- B. Strip all attachments from email domains associated with potentially harmful websites.
- C. Rewrite URLs to redirect traffic to potentially harmful websites through a web security proxy
- D. Block all emails from email domains associated with potentially harmful websites.
Answer: C
Explanation:
Outbreak Filters can take the action of rewriting URLs to redirect traffic to potentially harmful websites through a web security proxy. This allows the Cisco Secure Email Gateway to scan the content of the websites and block or warn the user if they are malicious or undesirable. This action can stop small-scale and nonviral attacks, such as phishing scams and malware distribution sites, that may not be detected by other filters. Reference: [Cisco Secure Email Gateway Administrator Guide - Configuring Outbreak Filters]
NEW QUESTION # 102
Which two Cisco ESA features are used to control email delivery based on the sender? (Choose two.)
- A. outbreak filter
- B. blocklists
- C. safelists
- D. spam quarantine
- E. incoming mail policies
Answer: B,C
Explanation:
Safelists and blocklists are features on Cisco ESA that allow you to control email delivery based on the sender. Safelists are lists of sender addresses or domains that you want to accept or exempt from certain filtering actions. Blocklists are lists of sender addresses or domains that you want to reject or drop3. Reference = Securing Email with Cisco Email Security Appliance (SESA) v3.1
NEW QUESTION # 103
What is the maximum message size that can be configured for encryption on the Cisco ESA?
- A. 30 MB
- B. 15 MB
- C. 20 MB
- D. 25 MB
Answer: C
NEW QUESTION # 104
Drag and drop the Cisco ESA reactions to a possible DLP from the left onto the correct action types on the right.
Answer:
Explanation:
Reference:
https://www.cisco.com/c/en/us/td/docs/security/esa/esa12-0/user_guide/b_ESA_Admin_Guide_12_0/ b_ESA_Admin_Guide_chapter_010001.html (message actions)
NEW QUESTION # 105
A Cisco ESA administrator has several mail policies configured. While testing policy match using a specific sender, the email was not matching the expected policy.
What is the reason of this?
- A. The To" header is checked against all policies in a top-down fashion.
- B. The message header with the highest priority is checked against the Default policy in a top-down fashion.
- C. The message header with the highest priority is checked against each policy in a top-down fashion.
- D. The Tram* header is checked against all policies in a top-down fashion.
Answer: B
NEW QUESTION # 106
......
Dumps of 300-720 Cover all the requirements of the Real Exam: https://braindumps2go.actualpdf.com/300-720-real-questions.html
