Pass the Cisco CCNP Security 300-720 Questions and answers with CertsForce

Viewing page 4 out of 5 pages
Viewing questions 31-40 out of questions
Questions # 31:

Which two certificate authority lists are available in Cisco ESA? (Choose two.)

Options:

A.

default


B.

system


C.

user


D.

custom


E.

demo


Expert Solution
Questions # 32:

What is the maximum message size that can be configured for encryption on the Cisco ESA?

Options:

A.

20 MB


B.

25 MB


C.

15 MB


D.

30 MB


Expert Solution
Questions # 33:

A list of company executives is routinely being spoofed, which puts the company at risk of malicious email attacks An administrator must ensure that executive messages are originating from legitimate sending addresses Which two steps must be taken to accomplish this task? (Choose two.)

Options:

A.

Create an incoming content filter with SPF detection.


B.

Enable the Forged Email Detection feature under Security Settings.


C.

Enable DMARC feature under Mail Policies.


D.

Create an incoming content filter with the Forged Email Detection condition


E.

Create a content dictionary including a list of the names that are being spoofed.


Expert Solution
Questions # 34:

Which SMTP extension does Cisco ESA support for email security?

Options:

A.

ETRN


B.

UTF8SMTP


C.

PIPELINING


D.

STARTTLS


Expert Solution
Questions # 35:

Refer to the exhibit.

Question # 35

Which additional configuration action must be taken to protect against Directory Harvest Attacks?

Options:

A.

When LDAP Queries are configured, Directory Harvest Attack Prevention is enabled by default.


B.

In the LDAP Server profile, configure Directory Harvest Attack Prevention


C.

In the mail flow policy, configure Directory Harvest Attack Prevention.


D.

In the Listener Settings, modify the LDAP Queries configuration to use the Work Queue


Expert Solution
Questions # 36:

An engineer wants to utilize a digital signature in outgoing emails to validate to others that the email they are receiving was indeed sent and authorized by the owner of that domain Which two components should be configured on the Cisco Secure Email Gateway appliance to achieve this? (Choose two.)

Options:

A.

DMARC verification profile


B.

SPF record


C.

Public/Private keypair


D.

Domain signing profile


E.

PKI certificate


Expert Solution
Questions # 37:

Drag and drop the graymail descriptions from the left onto the verdict categories they belong to on the right.

Question # 37


Expert Solution
Questions # 38:

What is the purpose of Cisco Email Encryption on Cisco ESA?

Options:

A.

to ensure anonymity between a recipient and MTA


B.

to ensure integrity between a sender and MTA


C.

to authenticate direct communication between a sender and Cisco ESA


D.

to ensure privacy between Cisco ESA and MTA


Expert Solution
Questions # 39:

An engineer is configuring a Cisco ESA for the first time and needs to ensure that any email traffic coming from the internal SMTP servers is relayed out through the Cisco ESA and is tied to the Outgoing Mail Policies.

Which Mail Flow Policy setting should be modified to accomplish this goal?

Options:

A.

Exception List


B.

Connection Behavior


C.

Bounce Detection Signing


D.

Reverse Connection Verification


Expert Solution
Questions # 40:

Which two query types are available when an LDAP profile is configured? (Choose two.)

Options:

A.

proxy consolidation


B.

user


C.

recursive


D.

group


E.

routing


Expert Solution
Viewing page 4 out of 5 pages
Viewing questions 31-40 out of questions