Pre-Summer Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Cisco CCNP Security 300-720 Questions and answers with CertsForce

Viewing page 3 out of 6 pages
Viewing questions 21-30 out of questions
Questions # 21:

An administrator needs to configure Cisco ESA to ensure that emails are sent and authorized by th e owner of the domain. Which two steps must be performed to accomplish this task? (Choose two.)

Options:

A.

Generate keys.


B.

Create signing profile.


C.

Create Mx record.


D.

Enable SPF verification.


E.

Create DMARC profile.


Expert Solution
Questions # 22:

The company security policy requires that the finance department have an easy way to apply encryption to their outbound messages that contain sensitive data Users must be able to flag the messages that require encryption versus a Cisco Secure Email Gateway appliance scanning all messages and automatically encrypting via detection Which action enables this capability?

Options:

A.

Create an encryption profile with [SECURE] in the Subject setting and enable encryption on the mail flow policy


B.

Create an outgoing content filter with no conditions and with the Encrypt and Deliver Now action configured with [SECURE] in the Subject setting


C.

Create an encryption profile and an outgoing content filter that includes \[SECURE\] within the Subject Header: Contains condition along with the Encrypt and Deliver Now action


D.

Create a DLP policy manager message action with encryption enabled and apply it to active DLP policies for outgoing mail.


Expert Solution
Questions # 23:

Drag and drop the graymail descriptions from the left onto the verdict categories they belong to on the right.

Question # 23


Expert Solution
Questions # 24:

Refer to the exhibit.

Question # 24

An administrator has configured File Reputation and File Analysis on the Cisco Secure Email Gateway appliance however it does not function as expected What must be configured on the appliance for this to function?

Options:

A.

Upload the Root CA certificate for the File Reputation cloud to the Cisco Secure Email Gateway.


B.

Open port 443 on the firewall for the Cisco Secure Email Gateway to connect to the File Reputation cloud.


C.

Configure the Cisco Secure Email Gateway to use SSL for the connection to the File Reputation server


D.

Restart the File Reputation service to force the scanning engine to connect to the File Reputation cloud.


Expert Solution
Questions # 25:

To comply with a recent audit, an engineer must configure anti-virus message handling options on the incoming mail policies to attach warnings to the subject of an email.

What should be configured to meet this requirement for known viral emails?

Options:

A.

Virus Infected Messages

B Unscannable Messages


B.

Encrypted Messages


C.

Positively Identified Messages


Expert Solution
Questions # 26:

Drag and drop the actions from the left into sequence on the right to validate the authenticity of email on a Cisco Secure Email Gateway by using DNS records.

Question # 26


Expert Solution
Questions # 27:

Which method enables an engineer to deliver a flagged messag e to a specific virtual gateway address in the most flexible way?

Options:

A.

Set up the interface group with the flag.


B.

Issue the altsrchost command.


C.

Map the envelope sender address to the host.


D.

Apply a filter on the message.


Expert Solution
Questions # 28:

Which type of attack does Bounce Verification fight against?

Options:

A.

identity


B.

backscatter


C.

phishing


D.

spear phishing


Expert Solution
Questions # 29:

What must be configured to allow the Cisco ESA to encrypt an email using the Cisco Registered Envelope Service?

Options:

A.

provisioned email encryption profile


B.

message encryption from a content filter that select " Message Encryption " over TLS


C.

message encryption from the mail flow policies with " CRES " selected


D.

content filter to forward the email to the Cisco Registered Envelope server


Expert Solution
Questions # 30:

Which action is a valid fallback when a client certificate is unavailable during SMTP authentication on Cisco ESA?

Options:

A.

LDAP Query


B.

SMTP AUTH


C.

SMTP TLS


D.

LDAP BIND


Expert Solution
Viewing page 3 out of 6 pages
Viewing questions 21-30 out of questions