300-720 Exam Dumps Pass with Updated 2024 Certified Exam Questions [Q12-Q27]

Share

300-720 Exam Dumps Pass with Updated 2024 Certified Exam Questions

300-720 Exam Questions - Real & Updated Questions PDF


Cisco 300-720 (Securing Email with Cisco Email Security Appliance) Certification Exam is designed for professionals who are interested in enhancing their knowledge and skills in securing email communications. 300-720 exam covers a wide range of topics related to email security, including anti-spam and anti-virus protection, encryption and decryption of emails, and email content filtering. By passing 300-720 exam, candidates will demonstrate their ability to implement and manage email security solutions using Cisco Email Security Appliance.

 

NEW QUESTION # 12
When DKIM signing is configured, which DNS record must be updated to load the DKIM public signing key?

  • A. PTR record
  • B. AAAA record
  • C. TXT record
  • D. MX record

Answer: C

Explanation:
Reference:
https://www.cisco.com/c/en/us/support/docs/security/email-security-appliance/213939-esa- configure-dkim-signing.html


NEW QUESTION # 13
When URL logging is configured on a Cisco ESA, which feature must be enabled first?

  • A. senderbase reputation filter
  • B. virus outbreak filter
  • C. antispam
  • D. antivirus

Answer: B


NEW QUESTION # 14
Refer to the exhibit.


Which configuration allows the Cisco Secure Email Gateway to scan for executables inside the archive file and apply the action as per the content filter?

  • A. Modify the content filter to look for attachment filetype of compressed.
  • B. Configure the recursion depth to a higher value.
  • C. Configure the maximum attachment size to a higher value.
  • D. Modify the content filter to look for exe filename instead of executable filetype.

Answer: B

Explanation:
The recursion depth is the number of levels that the Cisco Secure Email Gateway will scan inside an archive file for executables and other file types. If the recursion depth is too low, some executables may not be detected and scanned by the content filter. To allow the appliance to scan for executables inside the archive file and apply the action as per the content filter, you need to configure the recursion depth to a higher value1. Reference = User Guide for AsyncOS 12.0 for Cisco Email Security Appliances - GD (General Deployment) - Configuring File Reputation Filtering and File Analysis [Cisco Secure Email Gateway] - Cisco


NEW QUESTION # 15
What is the default port to deliver emails from the Cisco ESA to the Cisco SMA using the centralized Spam Quarantine?

  • A. 0
  • B. 1
  • C. 2
  • D. 3

Answer: A


NEW QUESTION # 16
A Cisco ESA administrator was notified that a user was not receiving emails from a specific domain. After reviewing the mail logs, the sender had a negative sender-based reputation score.
What should the administrator do to allow inbound email from that specific domain?

  • A. Create a new inbound mail policy with a message filter that overrides Talos.
  • B. Add the domain into the allow list.
  • C. Modify the firewall to allow emails from the domain.
  • D. Ask the user to add the sender to the email application's allow list.

Answer: B


NEW QUESTION # 17
Which process is skipped when an email is received from safedomain.com, which is on the safelist?

  • A. outbreak filter
  • B. antispam scanning
  • C. message filter
  • D. antivirus scanning

Answer: C


NEW QUESTION # 18
An Encryption Profile has been set up on the Cisco ESA.
Drag and drop the steps from the left for creating an outgoing content filter to encrypt emails that contains the subject "Secure:" into the correct order on the right.

Answer:

Explanation:

Reference:
https://community.cisco.com/t5/email-security/keyword-in-subject-line-to-encrypt-message/td-p/2441383


NEW QUESTION # 19
What are two prerequisites for implementing undesirable URL protection in Cisco ESA? (Choose two.)

  • A. Enable outbreak filters.
  • B. Enable antivirus scanning.
  • C. Enable antispam scanning.
  • D. Enable email relay.
  • E. Enable port bouncing.

Answer: A,C


NEW QUESTION # 20
What is the purpose of checking the CRL during SMTP authentication on a Cisco Secure Email Gateway?

  • A. Validate the date to check if the certificate is still valid
  • B. Confirm that corresponding CA is present
  • C. Verify the common name matches user ID
  • D. Check if the certificate is not revoked.

Answer: D

Explanation:
The purpose of checking the Certificate Revocation List (CRL) during SMTP authentication on a Cisco Secure Email Gateway is to check if the certificate is not revoked by the issuing Certificate Authority (CA). A revoked certificate means that it is no longer valid and should not be trusted. Reference = [User Guide for AsyncOS 12.0 for Cisco Email Security Appliances - GD (General Deployment) - Configuring SMTP Authentication [Cisco Secure Email Gateway] - Cisco]


NEW QUESTION # 21
An administrator is trying to enable centralized PVO but receives the error, "Unable to proceed with Centralized Policy, Virus and Outbreak Quarantines configuration as esa1 in Cluster has content filters / DLP actions available at a level different from the cluster level." What is the cause of this error?

  • A. DLP is configured at the domain-level on esa1.
  • B. Content filters are configured at the machine-level on esa1.
  • C. DLP is configured at the cluster-level on esa2.
  • D. DLP is not configured on host1.

Answer: D


NEW QUESTION # 22
Which two statements about configuring message filters within the Cisco ESA are true? (Choose two.)

  • A. Message filters can be configured only from the web user interface.
  • B. Message filters can be configured only from the CLI.
  • C. The filters command executed from the CLI is used to configure the message filters.
  • D. Message filters configuration within the web user interface is located within Incoming Content Filters.
  • E. The filterconfig command executed from the CLI is used to configure message filters.

Answer: B,C


NEW QUESTION # 23
An administrator is managing multiple Cisco ESA devices and wants to view the quarantine emails from all devices in a central location.
How is this accomplished?

  • A. Configure a mail policy to determine whether the message is sent to the local or external quarantine.
  • B. Configure a user policy to determine whether the message is sent to the local or external quarantine.
  • C. Disable the VOF feature before sending SPAM to the external quarantine.
  • D. Disable the local quarantine before sending SPAM to the external quarantine.

Answer: A


NEW QUESTION # 24
Which SMTP extension does Cisco ESA support for email security?

  • A. STARTTLS
  • B. ETRN
  • C. UTF8SMTP
  • D. PIPELINING

Answer: A

Explanation:
Explanation/Reference: https://www.cisco.com/c/en/us/td/docs/security/esa/esa12-0/user_guide/ b_ESA_Admin_Guide_12_0/b_ESA_Admin_Guide_12_0_chapter_011000.html


NEW QUESTION # 25
What is the order of virus scanning when multilayer antivirus scanning is configured?

  • A. The McAfee engine scans for viruses first and the default engine scans for viruses second.
  • B. The Sophos engine scans for viruses first and the McAfee engine scans for viruses second.
  • C. The default engine scans for viruses first and the McAfee engine scans for viruses second.
  • D. The McAfee engine scans for viruses first and the Sophos engine scans for viruses second.

Answer: D

Explanation:

https://www.cisco.com/c/en/us/td/docs/security/esa/esa13-
0/user_guide/b_ESA_Admin_Guide_13-0.pdf P.402


NEW QUESTION # 26
Which two features are applied to either incoming or outgoing mail policies? (Choose two.)

  • A. Indication of Compromise
  • B. antivirus
  • C. application filtering
  • D. sender reputation filtering
  • E. outbreak filters

Answer: B,E

Explanation:
Outbreak filters and antivirus are two features that can be applied to either incoming or outgoing mail policies on Cisco ESA. Outbreak filters allow Cisco ESA to detect and block messages that contain new or emerging email threats, such as viruses, worms, phishing, or spam, by using real-time updates from Talos intelligence. Antivirus allows Cisco ESA to scan messages for known viruses and malware using one or two antivirus engines (Sophos and McAfee).


NEW QUESTION # 27
......


Cisco 300-720 certification exam is part of the Cisco Certified Specialist - Email Content Security certification. Securing Email with Cisco Email Security Appliance certification is an excellent way to showcase your expertise in email security technologies and solutions. The Cisco Email Security Appliance is a widely used email security solution that is used by many organizations worldwide. By passing this certification exam, you will be able to demonstrate your proficiency in email security technologies and solutions and enhance your career prospects in the cybersecurity field.

 

Pass Guaranteed Quiz 2024 Realistic Verified Free Cisco: https://www.itcertmagic.com/Cisco/real-300-720-exam-prep-dumps.html

Free CCNP Security 300-720 Ultimate Study Guide: https://drive.google.com/open?id=1jY35ZEfgWrVtHw-ZTGvAJPKcx7z4t8lR