Best Quality 300-720 Exam Questions Cisco Test To Gain Brilliante Result!
Preparations of 300-720 Exam 2024 CCNP Security Unlimited 149 Questions
NEW QUESTION # 20
Which benefit does enabling external spam quarantine on Cisco SMA provide?
- A. ability to consolidate spam quarantine data from multiple Cisco ESA to one central console
- B. ability to back up spam quarantine from multiple Cisco ESAs to one central console
- C. access to the spam quarantine interface on which a user can release, duplicate, or delete
- D. ability to scan messages by using two engines to increase a catch rate
Answer: A
Explanation:
Explanation/Reference: https://www.cisco.com/c/en/us/td/docs/security/security_management/sma/sma11-0/ user_guide/b_SMA_Admin_Guide/b_SMA_Admin_Guide_chapter_010101.html
NEW QUESTION # 21
Which action is a valid fallback when a client certificate is unavailable during SMTP authentication on Cisco ESA?
- A. SMTP TLS
- B. LDAP BIND
- C. LDAP Query
- D. SMTP AUTH
Answer: D
Explanation:
Reference:
https://www.cisco.com/c/en/us/td/docs/security/esa/esa12-0/user_guide/ b_ESA_Admin_Guide_12_0/b_ESA_Admin_Guide_12_0_chapter_011011.html
NEW QUESTION # 22
What is a benefit of implementing URL filtering on the Cisco ESA?
- A. enhances reputation against malicious URLs
- B. removes threats from malicious URLs
- C. provides URL reputation protection
- D. blacklists spam
Answer: C
NEW QUESTION # 23
Which two action types are performed by Cisco ESA message filters? (Choose two.)
- A. filter actions
- B. final actions
- C. discard actions
- D. quarantine actions
- E. non-final actions
Answer: B,E
Explanation:
Non-final actions are actions that do not terminate the message filter evaluation, such as adding headers, setting variables, logging, etc. Final actions are actions that end the message filter evaluation and determine the fate of the message, such as accept, drop, bounce, quarantine, etc.
NEW QUESTION # 24
Which SMTP extension does Cisco ESA support for email security?
- A. PIPELINING
- B. STARTTLS
- C. UTF8SMTP
- D. ETRN
Answer: B
Explanation:
Explanation/Reference: https://www.cisco.com/c/en/us/td/docs/security/esa/esa12-0/user_guide/ b_ESA_Admin_Guide_12_0/b_ESA_Admin_Guide_12_0_chapter_011000.html
NEW QUESTION # 25
When virtual gateways are configured, which two distinct attributes are allocated to each virtual gateway address? (Choose two.)
- A. domain
- B. DNS server address
- C. external spam quarantine
- D. DHCP server address
- E. IP address
Answer: A,E
Explanation:
Reference:
https://www.cisco.com/c/en/us/support/docs/security/email-security-appliance/118542-qa-esa- 00.html
NEW QUESTION # 26
A network administrator is modifying an outgoing mail policy to enable domain protection for the organization. A DNS entry is created that has the public key.
Which two headers will be used as matching criteria in the outgoing mail policy? (Choose two.)
- A. from
- B. URL reputation
- C. message-ID
- D. mail-from
- E. sender
Answer: A,E
Explanation:
To enable domain protection for the organization, the administrator must configure an outgoing mail policy that matches the sender and the from headers of the email. The sender header is the envelope sender address that is used by SMTP to route the email. The from header is the address that is displayed to the recipient as the source of the email. These headers are used to generate and verify a DomainKeys Identified Mail (DKIM) signature, which is a cryptographic method of validating the authenticity and integrity of an email message.
The other headers are not relevant for domain protection. The message-ID header is a unique identifier for each email message. The URL reputation header is a score that indicates the likelihood of a URL being malicious. The mail-from header is an alias for the sender header.
Reference:
Domain Protection
DKIM Signing
NEW QUESTION # 27
Refer to the exhibit.
Which SPF record is valid for mycompany.com?
- A. v=spf1 a mx ip4:10.1.10.23 -all
- B. v=spf1 a mx ip4:172.16.18.230 -all
- C. v=spf1 a mx ip4:199.209.31.21 -all
- D. v=spf1 a mx ip4:199.209.31.2 -all
Answer: B
NEW QUESTION # 28
Which action must be taken before a custom quarantine that is being used can be deleted?
- A. Remove the quarantine from the message action of a filter.
- B. Delete only the unused quarantine.
- C. Delete the quarantine that is not assigned to a filter.
- D. Delete the quarantine that is assigned to a filter.
Answer: A
Explanation:
Reference:
https://www.cisco.com/c/en/us/td/docs/security/esa/esa12-0/user_guide/ b_ESA_Admin_Guide_12_0/b_ESA_Admin_Guide_12_0_chapter_011111.html
NEW QUESTION # 29
Which of the following types of DNS records deals with mail delivery for a specific domain?
- A. A
- B. PTR
- C. MX
- D. TXT
Answer: C
NEW QUESTION # 30
An administrator must ensure that emails sent from [email protected] are routed through an alternate virtual gateway. Drag and drop the snippet from the bottom onto the blank in the graphic to finish the message filter syntax. Not all snippets are used.
Answer:
Explanation:
Explanation
Table Description automatically generated
NEW QUESTION # 31
An engineer is configuring a Cisco ESA for the first time and needs to ensure that any email traffic coming from the internal SMTP servers is relayed out through the Cisco ESA and is tied to the Outgoing Mail Policies.
Which Mail Flow Policy setting should be modified to accomplish this goal?
- A. Connection Behavior
- B. Bounce Detection Signing
- C. Exception List
- D. Reverse Connection Verification
Answer: A
Explanation:
Reference:
Connection Behavior setting allows you to specify how the Cisco Email Security Appliance (ESA) handles incoming connections from different sender groups. You can choose from four different settings:
Accept: The ESA accepts all connections from the sender group and applies the mail flow policy settings to the messages.
Throttle: The ESA limits the number of concurrent connections and messages per connection from the sender group. This can help reduce the impact of spam or malicious traffic on the ESA's performance.
Reject: The ESA rejects all connections from the sender group and returns a 5xx SMTP error code to the sender. This can help block unwanted or abusive senders from reaching your network.
Test: The ESA accepts connections from the sender group but does not deliver the messages to the recipients. Instead, it logs the messages and marks them as test messages. This can help you test the mail flow policy settings before applying them to real traffic.
To modify the Connection Behavior setting for a sender group, you need to do the following steps:
On the ESA, choose Mail Policies > HAT Overview.
Click Edit Settings for the sender group that you want to modify.
In the Mail Flow Policy Settings section, choose one of the options from the Connection Behavior drop-down list.
Click Submit and commit changes.
NEW QUESTION # 32
Which two components form the graymail management solution in Cisco ESA? (Choose two.)
- A. uniform unsubscription management interface for end users
- B. secure subscribe option for end users
- C. cloud-based unsubscribe service
- D. integrated graymail scanning engine
- E. improved mail efficacy
Answer: C,D
Explanation:
Reference:
https://www.cisco.com/c/en/us/td/docs/security/esa/esa12-0/user_guide/ b_ESA_Admin_Guide_12_0/b_ESA_Admin_Guide_chapter_01101.pdf (p.2)
NEW QUESTION # 33
Which process is skipped when an email is received from safedomain.com, which is on the safelist?
- A. outbreak filter
- B. antispam scanning
- C. antivirus scanning
- D. message filter
Answer: D
NEW QUESTION # 34
Which two steps are needed to disable local spam quarantine before external quarantine is enabled? (Choose two.)
- A. Select Monitor and click Spam Quarantine.
- B. Select Security Services and click Spam Quarantine.
- C. Uncheck the Enable Spam Quarantine check box.
- D. Check the External Safelist/Blocklist check box.
- E. Select External Spam Quarantine and click on Configure.
Answer: A,C
Explanation:
Reference:
https://www.cisco.com/c/en/us/support/docs/security/email-security-appliance/118555-qa-esa- 00.html (configuration summary)
NEW QUESTION # 35
Which two features of Cisco Email Security are added to a Sender Group to protect an organization against email threats? (Choose two.)
- A. NetFlow
- B. content disarm and reconstruction
- C. heuristic-based filtering
- D. geolocation-based filtering
- E. senderbase reputation filtering
Answer: D,E
Explanation:
Geolocation-based filtering and senderbase reputation filtering are two features of Cisco Email Security that can be added to a Sender Group to protect an organization against email threats. Geolocation-based filtering allows Cisco ESA to accept or reject connections from email servers based on their geographic location, such as country or continent. Senderbase reputation filtering allows Cisco ESA to reject or throttle connections from email servers based on their reputation score, which is calculated by Talos using sensor information from various sources.
NEW QUESTION # 36
Which two configurations are used on multiple LDAP servers to connect with Cisco ESA? (Choose two.)
- A. SLA monitor
- B. load balancing
- C. failover
- D. active-active
- E. active-standby
Answer: B,C
Explanation:
You can enter multiple host names to configure the LDAP servers for failover or load-balancing. Separate multiple entries with commas.
Reference:
https://www.cisco.com/c/en/us/td/docs/security/ces/user_guide/sma_user_guide/ b_SMA_Admin_Guide_ces_11/b_SMA_Admin_Guide_chapter_01010.html
NEW QUESTION # 37
What is the order of virus scanning when multilayer antivirus scanning is configured?
- A. The McAfee engine scans for viruses first and the default engine scans for viruses second.
- B. The Sophos engine scans for viruses first and the McAfee engine scans for viruses second.
- C. The McAfee engine scans for viruses first and the Sophos engine scans for viruses second.
- D. The default engine scans for viruses first and the McAfee engine scans for viruses second.
Answer: A
Explanation:
If you configure multi-layer anti-virus scanning, the Cisco appliance performs virus scanning with the McAfee engine first and the Sophos engine second. It scans messages using both engines, unless the McAfee engine detects a virus. If the McAfee engine detects a virus, the Cisco appliance performs the anti-virus actions (repairing, quarantining, etc.) defined for the mail policy.
Reference:
https://www.cisco.com/c/en/us/td/docs/security/esa/esa12-0/user_guide/ b_ESA_Admin_Guide_12_0/b_ESA_Admin_Guide_chapter_01011.html
NEW QUESTION # 38
Refer to the exhibit. An engineer is trying to connect to a Cisco ESA using SSH and has been unsuccessful. Upon further inspection, the engineer notices that there is a loss of connectivity to the neighboring switch.
Which connection method should be used to determine the configuration issue?
- A. serial
- B. Ethernet
- C. Telnet
- D. HTTPS
Answer: A
NEW QUESTION # 39
What are two prerequisites for implementing undesirable URL protection in Cisco ESA? (Choose two.)
- A. Enable antispam scanning.
- B. Enable port bouncing.
- C. Enable email relay.
- D. Enable antivirus scanning.
- E. Enable outbreak filters.
Answer: A,E
Explanation:
Undesirable URL protection is a feature that allows Cisco ESA to detect and block messages that contain URLs that lead to malicious or unwanted websites, such as phishing, malware, or adult content sites. To enable this feature, outbreak filters and antispam scanning must be enabled on Cisco ESA.
NEW QUESTION # 40
An organization wants to use its existing Cisco ESA to host a new domain and enforce a separate corporate policy for that domain.
What should be done on the Cisco ESA to achieve this?
- A. Use the deli very config command to configure mail delivery for the new domain.
- B. Use the dsestconf command to add a separate destination for the new domain.
- C. Use the altrchost command to add a separate gateway for the new domain.
- D. Use the smtproutes command to configure a SMTP route for the new domain.
Answer: D
NEW QUESTION # 41
Which feature must be activated on a Cisco Secure Email Gateway to combat backscatter?
- A. Bounce Verification
- B. Graymail Detection
- C. Forged Email Detection
- D. Bounce Profile
Answer: A
Explanation:
To combat backscatter, which is a type of spam that consists of bounce messages sent to forged sender addresses, the administrator must enable the Bounce Verification feature under Security Settings. This feature allows the appliance to verify whether a bounce message is legitimate or not by checking if the original message was sent from the appliance. If not, the bounce message is considered as backscatter and can be dropped or quarantined. Reference: [Cisco Secure Email Gateway Administrator Guide - Configuring Bounce Verification]
NEW QUESTION # 42
An administrator is trying to enable centralized PVO but receives the error, "Unable to proceed with Centralized Policy, Virus and Outbreak Quarantines configuration as esa1 in Cluster has content filters / DLP actions available at a level different from the cluster level." What is the cause of this error?
- A. DLP is not configured on host1.
- B. DLP is configured at the domain-level on esa1.
- C. DLP is configured at the cluster-level on esa2.
- D. Content filters are configured at the machine-level on esa1.
Answer: A
Explanation:
Explanation/Reference: https://www.cisco.com/c/en/us/support/docs/security/email-security-appliance/118026-technote- esa-00.html
NEW QUESTION # 43
......
Focus on 300-720 All-in-One Exam Guide For Quick Preparation: https://braindumps2go.actualpdf.com/300-720-real-questions.html
