Securing Email with Cisco Email Security Appliance (300-720 SESA) Questions and Answers
When URL logging is configured on a Cisco ESA, which feature must be enabled first?
What is the default HTTPS port when configuring spam quarantine on Cisco ESA?
An organization wants to prevent proprietary patent documents from being shared externally via email. The network administrator reviewed the DLP policies on the Cisco Secure Email Gateway and could not find an existing policy with the appropriate matching patterns. Which type of DLP policy template must be used to create a policy that meets this requirement?
Which type of attack does Bounce Verification fight against?
Which two components must be configured to perform DLP scanning? (Choose two.)
When email authentication is configured on Cisco ESA, which two key types should be selected on the signing profile? (Choose two.)
Drag and drop the steps to configure Cisco ESA to use SPF/SIDF verification from the left into the correct order on the right.

An email containing a URL passes through the Cisco ESA that has content filtering disabled for all mail policies. The sender is sampleuser@test1.com, the recipients are testuser1@test2.com, testuser2@test2.com, testuser3@test2.com, and mailer1@te st2.com. The subject of the email is Test Document395898847. An administrator wants to add a policy to ensure that the Cisco ESA evaluates the web reputation score before permitting this email.
Which two criteria must be used by the administrator to achie ve this? (Choose two.)
What is the default method of remotely accessing a newly deployed Cisco Secure Email Virtual Gateway when a DHCP server is not available?
An engineer must add cisco.com to the listed domains in Cisco Secure Email Gateway that accept messages. All other domains must be blocked, and the message must be sent back to the sender is Domain Blocked. Which two actions must be taken to meet the requirement? (Choose two.)
Which two are configured in the DMARC verification profile? (Choose two.)
An engineer tries to implement phishing simulations to test end users, but they are being blocked by the Cisco Secure Email Gateway appliance. Which two components, when added to the allow list, allow these simulations to bypass antispam scanning? (Choose two.)
An engineer tries to implement phishing simulations to test end users, but they are being blocked by the Cisco Secure Email Gateway appliance. Which two components, when added to the allow list, allow these simulations to bypass antispam scanning? (Choose two.)
An organization wants to use DMARC to improve its brand reputation by leveraging DNS records.
Which two email authentica tion mechanisms are utilized during this process? (Choose two.)
Which SMTP extension does Cisco ESA support for email security?
An engineer deploys a Cisco Secure Email Gateway appliance with default settings in an organization that permits only standard H feature does not work. Which additional action resolves the issue?
A Cisco ESA administrator was notified that a user wa s not receiving emails from a specific domain. After reviewing the mail logs, the sender had a negative sender-based reputation score.
What should the administrator do to allow inbound email from that specific domain?
Which content filter condition checks to see if the " From: header " in the message is similar to any of the users in the content dictionary?
An organization is enforcing TLS with an external party. The external business employs its own internal CA so the Secure Email Gateway cannot verify the TLS connection. Which action must an engineer take for the Cisco Secure Email Gateway to trust the connection?
An analyst creates a new content dictionary to use with Forged Email Detection.
Which entry will be added into the dictionary?
Which action must be taken before a custom quarantine that is being used can be deleted?
A network administrator notices that there are a high number of queries to the LDAP server. The mail logs show an entry “550 Too many invalid recipients | Connection closed by foreign host.”
Which feature must be used to address this?
Refer to the exhibit.

What results from this filter configuration?
An engineer wants to ensure that emails received by company users that contain URLs do not make them susceptible to data loss from accessing malicious or undesired external content sources Which two features must be configured on Cisco Secure Email Gateway to meet this requirement1? (Choose two.)
Which two Cisco ESA features are used to control email delivery based on the sender? (Choose two.)
Which Cisco ESA security service is configured only through an outgoing mail policy?
An engineer must integrate Cisco Secure Email with the Cisco Secure Endpoint console. Which two settings must be configured to prevent zero-day threats? (Choose two.)
A Cisco ESA administrator has noticed that new messages being sent to the Centralized Policy Quarantine are being released after one hour. Previously, they were being held for a day before being released.
What was configured that caused this to occur?
A security engineer wants to ensure that legitimate emails from info@partners.com are not quarantined as spam in Cisco Secure Email. Which action must be taken to meet this requirement?
A content dictionary was created for use with Forged Email Detection. Proper data that pertains to the CEO Example CEO: < ceo@example com > must be entered. What must be added to the dictionary to accomplish this goal?
How does the graymail safe unsubscribe feature function?
Which of the following two statements are correct about the large file attachments (greater than 25MB) feature in Cisco Secure Email Encryption Service? (Choose two.)
Which two features of Cisco Email Security are added to a Sender Group to protect an organization against email threats? (Choose two.)
An email administrator must configure DLP policies on the Cisco Secure Email Gateway. The DLP policies must be added to the default outgoing mail policy. How is this task accomplished?
An engineer must configure the message source when integrating Cisco Secure Email Threat Defense with Microsoft 365. The integration must allow visibility but not remediation. Drag and drop the actions from the left into sequence on the right to meet the requirement.

An administrator notices that the Cisco Secure Email Gateway delivery queue on an appliance is consistently full. After further investigation, it is determined that the IP addresses currently in use by appliance are being rate-limited by some destinations. The administrator creates a new interface with an additional IP address using virtual gateway technology, but the issue is not solved Which configuration change resolves the issue?
A Cisco Secure Email Gateway administrator must provide outbound email authenticity and configures a DKIM signing profile to handle this task. What is the next step to allow this organization to use DKIM for their outbound email?
When virtual gateways are configured, which two distinct attributes are allocated to each virtual gateway address? (Choose two.)
Which two actions are configured on the Cisco ESA to query LDAP servers? (Choose two.)
A Cisco Secure Email Gateway administrator recently enabled the Outbreak Filters Global Service Setting to detect Viral as well as Non-Viral threat detection, with no detection of Non-viral threats after 24 hours of monitoring Outbreak Filters What is the reason that Non-Viral threat detection is not detecting any positive verdicts?
An engineer must configure a virtual gateway on a Cisco Secure Email Gateway to send email for a group named Grouplnt. Grouplnt is part of these domains:
•domain 1 -lab
•domain2.lab
Drag and drop the code snippets from the right onto the boxes to configure the virtual gateway. Not all options are used.

When DKIM signing is configured, which DNS record must be updated to load the DKIM public signing key?
Which action is a valid fallback when a client certificate is unavailable during SMTP authentication on Cisco ESA?
When an email is sent with bounce verification enabled, which address is rewritten by the Cisco Secure Email Gateway in the message?
What validates users via LDAP during login to end-user quarantine?


Refer to the exhibit. Which configuration on the scan behavior must be updated to allow the attachment to be scanned on the Cisco ESA?
To comply with a recent audit, an engineer must configure anti-virus message handling options on the incoming mail policies to attach warnings to the subject of an email.
What should be configured to meet this requirement for known viral emails?
Which type of query must be configured when setting up the Spam Quarantine while merging notifications?
Drag and drop authentication options for End-User Quarantine Access from the left onto the corresponding configuration steps on the right.

An admin istrator is managing multiple Cisco ESA devices and wants to view the quarantine emails from all devices in a central location.
How is this accomplished?
When outbreak filters are configured, which two actions are used to protect users from outbreaks? (Choose two.)
What is a benefit of graymail services?
An engineer must provide user access to the spam quarantine on a Cisco Secure Email Gateway. Users must be able to access the spam quarantine without additional authentication by using links. The users must be able to preview a spam message from within the Spam Quarantine section without restoring the message. Drag and drop the actions from the left into sequence on the right to meet the requirements.

Which two statements about configuring message filters within the Cisco ESA are true? (Choose two.)
An engineer must enable SIDF for a mail flow policy on an incoming listener in Cisco Secure Email Gateway. Drag and drop the actions from the left into the sequence on the right to meet the requirement.

Drag and drop the graymail descriptions from the left onto the verdict categories they belong to on the right.

What are two prerequisites for implementing undesirable URL protection in Cisco ESA? (Choose two.)
Spreadsheets containing credit card numbers are being allowed to bypass the Cisco ESA.
Which outgoing mail policy feature should be configured to catch this content before it leaves the network?






