300-720 Securing Email with Cisco Email Security Appliance (300-720 SESA) Questions and Answers
Which method enables an engineer to deliver a flagged messag e to a specific virtual gateway address in the most flexible way?
An engineer must configure Cisco Secure Email Gateway to scan all email from the HR department for viruses. The Sophos scanning engine must be used, and messages that potentially
still contain viruses after repair must be quarantined. These configurations were performed already:
•Enable antivirus scanning on the email gateway.
•Create a mail policy for the HR department.
Which two actions must be taken to complete the configuration? (Choose two.)
A Cisco Secure Email Gateway administrator must provide outbound email authenticity and configures a DKIM signing profile to handle this task. What is the next step to allow this organization to use DKIM for their outbound email?
An email containing a URL passes through the Cisco ESA that has content filtering disabled for all mail policies. The sender is sampleuser@test1.com, the recipients are testuser1@test2.com, testuser2@test2.com, testuser3@test2.com, and mailer1@te st2.com. The subject of the email is Test Document395898847. An administrator wants to add a policy to ensure that the Cisco ESA evaluates the web reputation score before permitting this email.
Which two criteria must be used by the administrator to achie ve this? (Choose two.)
An administrator notices that incoming emails with certain attachments do not get delivered to all recipients when the emails have multiple recipients in different domains like cisco.com and test.com. The same emails when sent only to recipients in cisco.com are delivered properly. How must the Cisco Secure Email Gateway be configured to avoid this behavior?
An engineer must add the user1@cisco.co m with an IP address of 10.1.1.13 to a safelist in Cisco Secure Email Gateway. Which two safelist syntaxes must be configured to meet the requirement? (Choose two.)
Which suboption must be selected when LDAP is configured for Spam Quarantine End-User Authentication?
Which two action types are performed by Cisco ESA message filters? (Choose two.)
Which type of query must be configured when setting up the Spam Quarantine while merging notifications?
Which scenario prevents a message from being sent to the quarantine as an action in the scan behavior on Cisco ESA?
What is needed to sign outbound emails using Domain Keys Identified Mail after a signing profile is created in the Cisco Secure Email Gateway?
Which type of DNS record would contain the following line, which references the DKIM public key per RFC 6376?
v=DKIM1; p=76E629F05F709EF665853333EEC3F5ADE69A2362BECE406582670456943283BE
What is the default method of remotely accessing a newly deployed Cisco Secure Email Virtual Gateway when a DHCP server is not available?
An analyst creates a new content dictionary to use with Forged Email Detection.
Which entry will be added into the dictionary?
A network administrator is modifying an outgoing mail policy to enable domain protection for the organization. A DNS entry is created that has the public key.
Which two headers will be used as matching criteria in the outgoing mail policy? (Choose two.)
When DKIM signing is configured, which DNS record must be updated to load the DKIM public signing key?
An engineer must ensure that email sent from is not sent to the spam quarantine on a Cisco Secure Email Gateway. What must be configured on the Secure Email Gateway?
When the spam quarantine is configured on the Cisco Secure Email Gateway, which type of query is used to validate non administrative user access to the end-user quarantine via LDAP?
A content dictionary was created for use with Forged Email Detection. Proper data that pertains to the CEO Example CEO: < ceo@example com > must be entered. What must be added to the dictionary to accomplish this goal?
An engineer must configure the message source when integrating Cisco Secure Email Threat Defense with Microsoft 365. The integration must allow visibility but not remediation. Drag and drop the actions from the left into sequence on the right to meet the requirement.

An engineer is tasked with reviewing mail logs to confirm that messages sent from domain abc.com are passing SPF verification and being accepted by the Cisco ESA. The engineer notices that SPF veri fication is not being performed and that SPF is not being referenced in the logs for messages sent from domain abc.com.
Why is the verification not working properly?
An organization wants to use DMARC to improve its brand reputation by leveraging DNS records.
Which two email authentica tion mechanisms are utilized during this process? (Choose two.)
An engineer must configure a policy quarantine in Cisco Secure Email Gateway. The retention time must be 7 days and user@cisco.com must have access to the quarantine. Drag and drop the actions from the left into the sequence on the right to meet the requirements.

A Cisco ESA administrator has several mail policies configured. While testing policy match using a specific sender, the email was not matching the expected policy.
What is the reason of this?
Drag and drop the AsyncOS methods for performing DMARC verification from the left into the correct order on the right.

Spammers routinely try to send emails with the recipient field filled with a list of all possible combinations of letters and numbers. These combinations, appended with a company domain name are malicious attempts at learning all possible valid email addresses. Which action must be taken on a Cisco Secure Email Gateway to prevent this from occurring?
A Cisco ESA administrator was notified that a user wa s not receiving emails from a specific domain. After reviewing the mail logs, the sender had a negative sender-based reputation score.
What should the administrator do to allow inbound email from that specific domain?
Which functionality is impacted if the assigned certificate under one of the IP interfaces is modified?
An engineer must provide user access to the spam quarantine on a Cisco Secure Email Gateway. Users must be able to access the spam quarantine without additional authentication by using links. The users must be able to preview a spam message from within the Spam Quarantine section without restoring the message. Drag and drop the actions from the left into sequence on the right to meet the requirements.

An organization has a strict policy on URLs embedded in emails. The policy allows visibility into what the URL is but does not allow the user to click it. Which action must be taken to meet the requirements of the security policy?
Which two statements about configuring message filters within the Cisco ESA are true? (Choose two.)
A network engineer is integrating Cisco Secure Email Gateway with Cisco SecureX. Which two actions must be taken before registering Cisco Secure Email Gateway with Cisco SecureX? (Choose two.)
An administrator has cr eated a content filter to quarantine all messages that result in an SPF hardfail to review the messages and determine whether a trusted partner has accidentally misconfigured the DNS settings. The administrator sets the policy quarantine to release the mes sages after 24 hours, allowing time to review while not interrupting business.
Which additional option should be used to help the end users be aware of the elevated risk of interacting with these messages?
Which action on the Cisco ESA provides direct access to view the safelist/blocklist?
Spreadsheets containing credit card numbers are being allowed to bypass the Cisco ESA.
Which outgoing mail policy feature should be configured to catch this content before it leaves the network?
Which content filter condition checks to see if the " From: header " in the message is similar to any of the users in the content dictionary?
Which components are required when encrypting SMTP with TLS on a Cisco Secure Email Gateway appliance when the sender requires TLS verification?
An administrator needs to configure Cisco ESA to ensure that emails are sent and authorized by th e owner of the domain. Which two steps must be performed to accomplish this task? (Choose two.)
A list of company executives is routinely being spoofed, which puts the company at risk of malicious email attacks An administrator must ensure that executive messages are originating from legitimate sending addresses Which two steps must be taken to accomplish this task? (Choose two.)
What are the two different phases in the process of Cisco Secure Email Gateway performing S/MIME encryption? (Choose two.)
When an email is sent with bounce verification enabled, which address is rewritten by the Cisco Secure Email Gateway in the message?
An engineer must integrate Cisco Secure Email with the Cisco Secure Endpoint console. Which two settings must be configured to prevent zero-day threats? (Choose two.)
Which two factors must be considered when message filter processing is configured? (Choose two.)
Which action is allowed while managing list of certificate authorities on Cisco Secure Email Gateway?
When a network engineer is troubleshooting a mail flow issue, they discover that some emails are rejected with an SMTP code of 451 and the error message " #4.7.1 Unable to perform DMARC verification " . In the DMARC verification profile on the Cisco Secure Email Gateway appliance, which action must be set for messages that result in temporary failure to prevent these emails from being rejected?
An engineer must configure a virtual gateway on a Cisco Secure Email Gateway to send email for a group named Grouplnt. Grouplnt is part of these domains:
•domain 1 -lab
•domain2.lab
Drag and drop the code snippets from the right onto the boxes to configure the virtual gateway. Not all options are used.

Refer to the exhibit.

An administrator has configured File Reputation and File Analysis on the Cisco Secure Email Gateway appliance however it does not function as expected What must be configured on the appliance for this to function?




