Pass the Cisco CCNP Security 300-720 Questions and answers with CertsForce

Viewing page 3 out of 5 pages
Viewing questions 21-30 out of questions
Questions # 21:

What are the two different phases in the process of Cisco Secure Email Gateway performing S/MIME encryption? (Choose two.)

Options:

A.

Attach the encrypted public key to the message


B.

Encrypt the message body using the session key


C.

Send the encrypted message to the sender


D.

Attach the encrypted symmetric key to the message


E.

Create a pseudo-random session key.


Expert Solution
Questions # 22:

The CEO added a sender to a safelist but does not receive an important message expected from the trusted sender. An engineer evaluates message tracking on the Cisco Secure Email Gateway appliance and determines that the message was dropped by the antivirus engine. What is the reason for this behavior?

Options:

A.

The sender is included in an ISP blocklist


B.

Administrative access is required to create a safelist.


C.

The sender didn't mark the message as urgent


D.

End-user safelists apply to antispam engines only.


Expert Solution
Questions # 23:

Which suboption must be selected when LDAP is configured for Spam Quarantine End-User Authentication?

Options:

A.

Designate as the active query


B.

Update Frequency


C.

Server Priority


D.

Entity ID


Expert Solution
Questions # 24:

A Cisco Secure Email Gateway appliance is processing many messages that are sent to invalid recipients verification. Which two steps are required to accomplish this task? (Choose two.)

Options:

A.

Enable external LDAP authentication


B.

Configure the LDAP query on a listener


C.

Configure LDAP server profiles


D.

Enable LDAP authentication on a listener


E.

Configure incoming mail policy to query LDAP server


Expert Solution
Questions # 25:

Which scenario prevents a message from being sent to the quarantine as an action in the scan behavior on Cisco ESA?

Options:

A.

A policy quarantine is missing.


B.

More than one email pipeline is defined.


C.

The "modify the message subject" is already set.


D.

The "add custom header" action is performed first.


Expert Solution
Questions # 26:

Refer to the exhibit.

Question # 26

An administrator has configured File Reputation and File Analysis on the Cisco Secure Email Gateway appliance however it does not function as expected What must be configured on the appliance for this to function?

Options:

A.

Upload the Root CA certificate for the File Reputation cloud to the Cisco Secure Email Gateway.


B.

Open port 443 on the firewall for the Cisco Secure Email Gateway to connect to the File Reputation cloud.


C.

Configure the Cisco Secure Email Gateway to use SSL for the connection to the File Reputation server


D.

Restart the File Reputation service to force the scanning engine to connect to the File Reputation cloud.


Expert Solution
Questions # 27:

A company has deployed a new mandate that requires all emails sent externally from the Sales Department to be scanned by DLP for PCI-DSS compliance. A new DLP policy has been created on the Cisco ESA and needs to be assigned to a mail policy named ‘Sales’ that has yet to be created.

Which mail policy should be created to accomplish this task?

Options:

A.

Outgoing Mail Policy


B.

Preliminary Mail Policy


C.

Incoming Mail Flow Policy


D.

Outgoing Mail Flow Policy


Expert Solution
Questions # 28:

An administrator needs to configure Cisco ESA to ensure that emails are sent and authorized by the owner of the domain. Which two steps must be performed to accomplish this task? (Choose two.)

Options:

A.

Generate keys.


B.

Create signing profile.


C.

Create Mx record.


D.

Enable SPF verification.


E.

Create DMARC profile.


Expert Solution
Questions # 29:

What is the order of virus scanning when multilayer antivirus scanning is configured?

Options:

A.

The default engine scans for viruses first and the McAfee engine scans for viruses second.


B.

The Sophos engine scans for viruses first and the McAfee engine scans for viruses second.


C.

The McAfee engine scans for viruses first and the default engine scans for viruses second.


D.

The McAfee engine scans for viruses first and the Sophos engine scans for viruses second.


Expert Solution
Questions # 30:

Which restriction is in place for end users accessing the spam quarantine on Cisco Secure Email Gateway appliances?

Options:

A.

Access via a link in a notification is mandatory.


B.

The end user must be assigned to the Guest role


C.

Direct access via web browser requires authentication.


D.

Authentication is required when accessing via a link in a notification.


Expert Solution
Viewing page 3 out of 5 pages
Viewing questions 21-30 out of questions