300-720 Revolutionary Guide To Exam Cisco Dumps 300-720 Free Study Guide! with New Update 149 Exam Questions Cisco 300-720 exam is designed to test the knowledge and skills of IT professionals in securing email with Cisco Email Security Appliance. Securing Email with Cisco Email Security Appliance certification is highly relevant for IT professionals who work in organizations that rely heavily on email [...]

300-720 Revolutionary Guide To Exam Cisco Dumps [Q15-Q39]

Share

300-720 Revolutionary Guide To Exam Cisco Dumps

300-720 Free Study Guide! with New Update 149 Exam Questions


Cisco 300-720 exam is designed to test the knowledge and skills of IT professionals in securing email with Cisco Email Security Appliance. Securing Email with Cisco Email Security Appliance certification is highly relevant for IT professionals who work in organizations that rely heavily on email communication. With the increasing number of email threats such as spam, phishing, and malware, it is essential for IT professionals to have the necessary skills to secure email and protect their organization's sensitive data.


Cisco 300-720 certification exam is a part of the Cisco Certified Specialist - Email Content Security certification program. Securing Email with Cisco Email Security Appliance certification program is designed to provide IT professionals with the necessary skills and knowledge to secure their organization's email content from various threats, including spam, malware, phishing, and other types of cyber-attacks. Securing Email with Cisco Email Security Appliance certification program covers a broad range of topics and technologies, including email security protocols, encryption, virtualization, and network security.

 

NEW QUESTION # 15
Drag and Drop Question
Drag and drop the steps to configure Cisco ESA to use SPF/SIDF verification from the left into the correct order on the right.

Answer:

Explanation:


NEW QUESTION # 16
Refer to the exhibit. How should this configuration be modified to stop delivering Zero Day malware attacks?

  • A. Change Unscannable Action from Deliver As Is to Quarantine.
  • B. Configure mailbox auto-remediation.
  • C. Apply Prepend on Modify Message Subject under Malware Attachments.
  • D. Change File Analysis Pending action from Deliver As Is to Quarantine.

Answer: B


NEW QUESTION # 17
What are the two different phases in the process of Cisco Secure Email Gateway performing S/MIME encryption? (Choose two.)

  • A. Attach the encrypted public key to the message
  • B. Attach the encrypted symmetric key to the message
  • C. Send the encrypted message to the sender
  • D. Create a pseudo-random session key.
  • E. Encrypt the message body using the session key

Answer: B,D


NEW QUESTION # 18
Drag and drop the graymail descriptions from the left onto the verdict categories they belong to on the right.

Answer:

Explanation:


NEW QUESTION # 19
Refer to the exhibit. Which SPF record is valid for mycompany.com?

  • A. v=spf1 a mx ip4:199.209.31.2 -all
  • B. v=spf1 a mx ip4:172.16.18.230 -all
  • C. v=spf1 a mx ip4:199.209.31.21 -all
  • D. v=spf1 a mx ip4:10.1.10.23 -all

Answer: C


NEW QUESTION # 20
Which two statements about configuring message filters within the Cisco ESA are true? (Choose two.)

  • A. Message filters can be configured only from the CLI.
  • B. The filters command executed from the CLI is used to configure the message filters.
  • C. Message filters configuration within the web user interface is located within Incoming Content Filters.
  • D. The filterconfig command executed from the CLI is used to configure message filters.
  • E. Message filters can be configured only from the web user interface.

Answer: A,B

Explanation:
Reference:
https://www.cisco.com/c/en/us/support/docs/security/email-security-appliance/213940-esa-using-a- message-filter-to-take-act.html


NEW QUESTION # 21
Which global setting is configured under Cisco ESA Scan Behavior?

  • A. minimum attachment size to scan
  • B. attachment scanning timeout
  • C. minimum depth of attachment recursion to scan
  • D. actions for unscannable messages due to attachment type

Answer: B

Explanation:
Reference:
https://community.cisco.com/t5/email-security/cisco-ironport-esa-security-services-scan-behavior- impact-on-av/td-p/3923243


NEW QUESTION # 22
An administrator is trying to enable centralized PVO but receives the error, "Unable to proceed with Centralized Policy, Virus and Outbreak Quarantines configuration as esa1 in Cluster has content filters / DLP actions available at a level different from the cluster level." What is the cause of this error?

  • A. DLP is not configured on host1.
  • B. Content filters are configured at the machine-level on esa1.
  • C. DLP is configured at the cluster-level on esa2.
  • D. DLP is configured at the domain-level on esa1.

Answer: A


NEW QUESTION # 23
When email authentication is configured on Cisco ESA, which two key types should be selected on the signing profile? (Choose two.)

  • A. Symmetric Keys
  • B. DKIM
  • C. Private Keys
  • D. Domain Keys
  • E. Public Keys

Answer: B,D

Explanation:
Reference:
https://www.cisco.com/c/en/us/support/docs/security/email-security-appliance/213939-esa- configure-dkim-signing.html


NEW QUESTION # 24
Drag and Drop Question
An administrator must ensure that emails sent from [email protected] are routed through an alternate virtual gateway. Drag and drop the snippet from the bottom onto the blank in the graphic to finish the message filter syntax. Not all snippets are used.

Answer:

Explanation:


NEW QUESTION # 25
Which action on the Cisco ESA provides direct access to view the safelist/blocklist?

  • A. Show the SLBL cache on the CLI.
  • B. Debug the mail flow policy.
  • C. Monitor Incoming/Outgoing Listener.
  • D. Export the SLBL to a .csv file.

Answer: D

Explanation:
Explanation/Reference: https://www.cisco.com/c/en/us/support/docs/security/email-security-appliance/117922-technote- esa-00.html


NEW QUESTION # 26
Which Cisco Secure Email Threat Defense visibility and remediation mode is only available when using Cisco Secure Email Gateway as the message source?

  • A. Cisco Security Cloud Sign On
  • B. Microsoft 365 Authentication
  • C. No Authentication
  • D. Basic Authentication

Answer: C

Explanation:
According to the Cisco Secure Email Threat Defense User Guide, the No Authentication option is only available if you are using a Cisco Secure Email Gateway (SEG) as your message source. This option allows visibility only, no remediation1.
The other options are not valid because:
A) Basic Authentication is not a visibility and remediation mode for Cisco Secure Email Threat Defense. It is a method of authenticating users with a username and password2.
C) Microsoft 365 Authentication is a visibility and remediation mode that allows you to use Microsoft 365 credentials to access Cisco Secure Email Threat Defense. It has two sub-options: Read/Write and Read. This mode is available for both Microsoft 365 and Gateway message sources1.
D) Cisco Security Cloud Sign On is not a visibility and remediation mode for Cisco Secure Email Threat Defense. It is a service that manages user authentication for Cisco security products, including Cisco Secure Email Threat Defense3.


NEW QUESTION # 27
What is a benefit of implementing URL filtering on the Cisco ESA?

  • A. provides URL reputation protection
  • B. blacklists spam
  • C. removes threats from malicious URLs
  • D. enhances reputation against malicious URLs

Answer: A


NEW QUESTION # 28
A network engineer must tighten up the SPAM control policy of an organization due to a recent SPAM attack. In which scenario does enabling regional scanning improve security for this organization?

  • A. when most of the received spam originates outside of the U.S.
  • B. when most of the received email originates from a specific region
  • C. when most of the received spam comes from a specific country
  • D. when most of the received email originates outside of the U.S.

Answer: B

Explanation:
Enabling regional scanning improves security for this organization when most of the received email originates from a specific region. Regional scanning is a feature that allows Cisco ESA to apply different spam thresholds and actions based on the geographic region of the sender's IP address, using a database of IP addresses and regions.
To enable regional scanning on Cisco ESA, the administrator can follow these steps:
Select Security Services > IronPort Anti-Spam and click Edit Settings.
Under Regional Scanning, select Enable Regional Scanning.
Click Submit.
Select Security Services > IronPort Anti-Spam > Regional Settings and click Add Region.
Choose a region from the drop-down menu, such as Asia Pacific.
Enter a spam threshold and an action for that region, such as 80 and Drop.
Click Submit.


NEW QUESTION # 29

Refer to the exhibit. An engineer is trying to connect to a Cisco ESA using SSH and has been unsuccessful.
Upon further inspection, the engineer notices that there is a loss of connectivity to the neighboring switch.
Which connection method should be used to determine the configuration issue?

  • A. HTTPS
  • B. Ethernet
  • C. Telnet
  • D. serial

Answer: D


NEW QUESTION # 30
What is the default port to deliver emails from the Cisco ESA to the Cisco SMA using the centralized Spam Quarantine?

  • A. 0
  • B. 1
  • C. 2
  • D. 3

Answer: B

Explanation:
Explanation/Reference: https://www.cisco.com/c/en/us/support/docs/security/email-security-appliance/118692- configure-esa-00.html


NEW QUESTION # 31
Which attack is mitigated by using Bounce Verification?

  • A. spoof
  • B. denial of service
  • C. eavesdropping
  • D. smurf

Answer: B

Explanation:
Explanation/Reference: https://www.networkworld.com/article/2305394/ironport-adds-bounce-back-verification-for-e- mail.html


NEW QUESTION # 32
Which type of attack is prevented by configuring file reputation filtering and file analysis features?

  • A. denial of service
  • B. backscatter
  • C. zero-day
  • D. phishing

Answer: C

Explanation:
The type of attack that is prevented by configuring file reputation filtering and file analysis features is zero-day. Zero-day attacks are those that exploit unknown vulnerabilities in software or systems before they are patched or fixed. File reputation filtering and file analysis features help to protect against zero-day attacks by checking the reputation of files attached to email messages and sending them to a cloud-based service for dynamic analysis.


NEW QUESTION # 33
Which type of query must be configured when setting up the Spam Quarantine while merging notifications?

  • A. Spam Quarantine Alias Authentication Query
  • B. Spam Quarantine Alias Routing Query
  • C. Spam Quarantine Alias Masquerading Query
  • D. Spam Quarantine Alias Consolidation Query

Answer: D

Explanation:
Spam Quarantine Alias Consolidation Query is a type of query that must be configured when setting up the Spam Quarantine while merging notifications on Cisco ESA. This query allows Cisco ESA to consolidate multiple email addresses that belong to the same end user into one entry in the Spam Quarantine, and send only one notification email to that end user with all the quarantined messages for all their email addresses.


NEW QUESTION # 34
Which two features of Cisco Email Security are added to a Sender Group to protect an organization against email threats? (Choose two.)

  • A. heuristic-based filtering
  • B. geolocation-based filtering
  • C. senderbase reputation filtering
  • D. NetFlow
  • E. content disarm and reconstruction

Answer: A,C


NEW QUESTION # 35
Which two components must be configured to perform DLP scanning? (Choose two.)

  • A. Add a DLP policy to the Outgoing Content Filter.
  • B. Enable a DLP policy on the DLP Policy Customizations.
  • C. Enable a DLP policy on the Outgoing Mail Policy.
  • D. Add a DLP policy to the DLP Policy Manager.
  • E. Add a DLP policy on the Incoming Mail Policy.

Answer: C,D

Explanation:
To perform DLP scanning on Cisco ESA, two components must be configured:
Add a DLP policy to the DLP Policy Manager, which is a repository of predefined or custom DLP policies that specify what types of data to scan for and what actions to take if a match is found.
Enable a DLP policy on the Outgoing Mail Policy, which is a set of rules that determine how outgoing messages are processed by Cisco ESA, including whether to apply DLP scanning or not.


NEW QUESTION # 36
Which two options describe the expected results when centralized policy, virus, and outbreak quarantines are disabled on the Cisco Email Security Appliance? (Choose two.)

  • A. The quarantine process must be restarted.
  • B. The Cisco ESA must be rebooted.
  • C. Local quarantines are enabled automatically.
  • D. The Cisco ESA stops accepting new messages.
  • E. New messages sent to the quarantine are immediately sent to local quarantines

Answer: C,E


NEW QUESTION # 37
Which two features are applied to either incoming or outgoing mail policies? (Choose two.)

  • A. outbreak filters
  • B. antivirus
  • C. Indication of Compromise
  • D. application filtering
  • E. sender reputation filtering

Answer: A,B

Explanation:
Reference:
https://www.cisco.com/c/en/us/td/docs/security/esa/esa11-1/user_guide/ b_ESA_Admin_Guide_11_1/b_ESA_Admin_Guide_chapter_01001.html


NEW QUESTION # 38
An engineer tries to implement phishing simul-ations to test end users, but they are being blocked by the Cisco Secure Email Gateway appliance. Which two components, when added to the allow list, allow these simul-ations to bypass antispam scanning? (Choose two.)

  • A. receivers
  • B. domains
  • C. senders
  • D. reputation score
  • E. spf check

Answer: B,C

Explanation:
To allow phishing simul-ations to bypass antispam scanning, the administrator must add two components to the allow list: domains and senders. Domains are the email domains that are used in the phishing simulations, such as example.com or test.com. Senders are the email addresses that are used to send the phishing simulations, such as [email protected] or [email protected]. By adding these components to the allow list, the administrator can prevent them from being blocked by antispam scanning and allow them to reach the end users for testing purposes. Reference: [Cisco Secure Email Gateway Administrator Guide - Creating Allow Lists]


NEW QUESTION # 39
......

Get up-to-date Real Exam Questions for 300-720: https://pass4sure.guidetorrent.com/300-720-dumps-questions.html