Pass the Cisco CCNP Security 300-720 Questions and answers with CertsForce

Viewing page 1 out of 5 pages
Viewing questions 1-10 out of questions
Questions # 1:

Which feature must be configured before an administrator can use the outbreak filter for nonviral threats?

Options:

A.

quarantine threat level


B.

antispam


C.

data loss prevention


D.

antivirus


Expert Solution
Questions # 2:

Which component must be added to the content filter to trigger on failed SPF Verification or DKIM Authentication verdicts?

Options:

A.

status


B.

response


C.

parameter


D.

condition


Expert Solution
Questions # 3:

Which two are configured in the DMARC verification profile? (Choose two.)

Options:

A.

name of the verification profile


B.

minimum number of signatures to verify


C.

ESA listeners to use the verification profile


D.

message action into an incoming or outgoing content filter


E.

message action to take when the policy is reject/quarantine


Expert Solution
Questions # 4:

Which action on the Cisco ESA provides direct access to view the safelist/blocklist?

Options:

A.

Show the SLBL cache on the CLI.


B.

Monitor Incoming/Outgoing Listener.


C.

Export the SLBL to a .csv file.


D.

Debug the mail flow policy.


Expert Solution
Questions # 5:

A security administrator deployed a Cisco Secure Email Gateway appliance with a mail policy configured to store suspected spam for review. The appliance is the DMZ and only the standard HTTP/HTTPS ports are allowed by the firewall. An administrator wants to ensure that users can view any suspected spam that was blocked. Which action must be taken to meet this requirement?

Options:

A.

Enable the external Spam Quarantine and enter the IP address and port for the Secure Email and Web Manager


B.

Enable the Spam Quarantine and leave the default settings unchanged.


C.

Enable End-User Quarantine Access and point to an LDAP server for authentication.


D.

Enable the Spam Quarantine and specify port 80 for HTTP and port 443 for HTTPS


Expert Solution
Questions # 6:

What must be configured to allow the Cisco ESA to encrypt an email using the Cisco Registered Envelope Service?

Options:

A.

provisioned email encryption profile


B.

message encryption from a content filter that select "Message Encryption" over TLS


C.

message encryption from the mail flow policies with "CRES" selected


D.

content filter to forward the email to the Cisco Registered Envelope server


Expert Solution
Questions # 7:

How does the graymail safe unsubscribe feature function?

Options:

A.

It strips the malicious content of the URI before unsubscribing.


B.

It checks the URI reputation and category and allows the content filter to take an action on it.


C.

It redirects the end user who clicks the unsubscribe button to a sandbox environment to allow a safe unsubscribe.


D.

It checks the reputation of the URI and performs the unsubscribe process on behalf of the end user.


Expert Solution
Questions # 8:

Which setting affects the aggressiveness of spam detection?

Options:

A.

protection level


B.

spam threshold


C.

spam timeout


D.

maximum depth of recursion scan


Expert Solution
Questions # 9:

Which benefit does enabling external spam quarantine on Cisco SMA provide?

Options:

A.

ability to back up spam quarantine from multiple Cisco ESAs to one central console


B.

access to the spam quarantine interface on which a user can release, duplicate, or delete


C.

ability to scan messages by using two engines to increase a catch rate


D.

ability to consolidate spam quarantine data from multiple Cisco ESA to one central console


Expert Solution
Questions # 10:

Which method enables an engineer to deliver a flagged message to a specific virtual gateway address in the most flexible way?

Options:

A.

Set up the interface group with the flag.


B.

Issue the altsrchost command.


C.

Map the envelope sender address to the host.


D.

Apply a filter on the message.


Expert Solution
Viewing page 1 out of 5 pages
Viewing questions 1-10 out of questions