Pre-Summer Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: best70

300-720 Securing Email with Cisco Email Security Appliance (300-720 SESA) Questions and Answers

Questions 4

What are two phases of the Cisco ESA email pipeline? (Choose two.)

Options:

A.

reject

B.

workqueue

C.

action

D.

delivery

E.

quarantine

Buy Now
Questions 5

What is the default HTTPS port when configuring spam quarantine on Cisco ESA?

Options:

A.

83

B.

82

C.

443

D.

80

Buy Now
Questions 6

Which method enables an engineer to deliver a flagged messag e to a specific virtual gateway address in the most flexible way?

Options:

A.

Set up the interface group with the flag.

B.

Issue the altsrchost command.

C.

Map the envelope sender address to the host.

D.

Apply a filter on the message.

Buy Now
Questions 7

An engineer must configure Cisco Secure Email Gateway to scan all email from the HR department for viruses. The Sophos scanning engine must be used, and messages that potentially

still contain viruses after repair must be quarantined. These configurations were performed already:

•Enable antivirus scanning on the email gateway.

•Create a mail policy for the HR department.

Which two actions must be taken to complete the configuration? (Choose two.)

Options:

A.

From the Message Scanning settings, enable Scan and Repair Viruses.

B.

Configure Virus Infected Message Handling to quarantine the messages.

C.

From the Message Scanning settings, enable the dropping of attachments.

D.

From the Message Scanning settings, enable Scan for Viruses only.

E.

Configure Unscannable Message Handling to quarantine the messages.

Buy Now
Questions 8

A Cisco Secure Email Gateway administrator must provide outbound email authenticity and configures a DKIM signing profile to handle this task. What is the next step to allow this organization to use DKIM for their outbound email?

Options:

A.

Enable the DKIM service checker

B.

Export the DNS TXT record to provide to the DNS registrar

C.

Import the DNS record of the service provider into the Cisco Secure Email Gateway.

D.

Configure the Trusted Sender Group message authenticity policy.

Buy Now
Questions 9

An email containing a URL passes through the Cisco ESA that has content filtering disabled for all mail policies. The sender is sampleuser@test1.com, the recipients are testuser1@test2.com, testuser2@test2.com, testuser3@test2.com, and mailer1@te st2.com. The subject of the email is Test Document395898847. An administrator wants to add a policy to ensure that the Cisco ESA evaluates the web reputation score before permitting this email.

Which two criteria must be used by the administrator to achie ve this? (Choose two.)

Options:

A.

Subject contains Test Document "

B.

Sender matches test1.com

C.

Email body contains a URL

D.

Date and time of email

E.

Email does not match mailer1@test2.com

Buy Now
Questions 10

What validates users via LDAP during login to end-user quarantine?

Options:

A.

end-user authentication query

B.

alias consolidation query

C.

LDAP authentication query

D.

external authentication query

Buy Now
Questions 11

An administrator notices that incoming emails with certain attachments do not get delivered to all recipients when the emails have multiple recipients in different domains like cisco.com and test.com. The same emails when sent only to recipients in cisco.com are delivered properly. How must the Cisco Secure Email Gateway be configured to avoid this behavior?

Options:

A.

Modify mail policies for cisco.com to ensure that emails are not dropped.

B.

Modify mail policies so email recipients do not match multiple policies.

C.

Modify DLP configuration to ensure that all attachments are permitted for test.com.

D.

Modify DLP configuration to exempt DLP scanning for messages sent to test.com domain

Buy Now
Questions 12

An engineer must add the user1@cisco.co m with an IP address of 10.1.1.13 to a safelist in Cisco Secure Email Gateway. Which two safelist syntaxes must be configured to meet the requirement? (Choose two.)

Options:

A.

[10.1.1.16/30]

B.

user1@ [10.1.1.13]

C.

[10.1.1.0/24]

D.

[10.1.1.13/30]

Buy Now
Questions 13

Which suboption must be selected when LDAP is configured for Spam Quarantine End-User Authentication?

Options:

A.

Designate as the active query

B.

Update Frequency

C.

Server Priority

D.

Entity ID

Buy Now
Questions 14

Which two action types are performed by Cisco ESA message filters? (Choose two.)

Options:

A.

non-final actions

B.

filter actions

C.

discard actions

D.

final actions

E.

quarantine actions

Buy Now
Questions 15

Which type of query must be configured when setting up the Spam Quarantine while merging notifications?

Options:

A.

Spam Quarantine Alias Routing Query

B.

Spam Quarantine Alias Consolidation Query

C.

Spam Quarantine Alias Authentication Query

D.

Spam Quarantine Alias Masquerading Query

Buy Now
Questions 16

Which scenario prevents a message from being sent to the quarantine as an action in the scan behavior on Cisco ESA?

Options:

A.

A policy quarantine is missing.

B.

More than one email pipeline is defined.

C.

The " modify the message subject " is already set.

D.

The " add custom header " action is performed first.

Buy Now
Questions 17

What is needed to sign outbound emails using Domain Keys Identified Mail after a signing profile is created in the Cisco Secure Email Gateway?

Options:

A.

Configure in destination controls.

B.

Enable DKIM in an outbound content filter.

C.

Enable DKIM in the mail flow policy.

D.

A signing profile referencing the sender domain is sufficient.

Buy Now
Questions 18

Which type of DNS record would contain the following line, which references the DKIM public key per RFC 6376?

v=DKIM1; p=76E629F05F709EF665853333EEC3F5ADE69A2362BECE406582670456943283BE

Options:

A.

CNAME

B.

AAAA

C.

TXT

D.

PTR

Buy Now
Questions 19

What is the default method of remotely accessing a newly deployed Cisco Secure Email Virtual Gateway when a DHCP server is not available?

Options:

A.

Manual configuration of an IP address is required through the serial port before remote access

B.

DHCP is required for the initial IP address assignment

C.

Use the IP address of 192.168 42 42 via the Management port

D.

Manual configuration of an IP address is required through the hypervisor console before remote access

Buy Now
Questions 20

What occurs when configuring separate incoming mail policies?

Options:

A.

message splintering

B.

message exceptions

C.

message detachment

D.

message aggregation

Buy Now
Questions 21

An analyst creates a new content dictionary to use with Forged Email Detection.

Which entry will be added into the dictionary?

Options:

A.

mycompany.com

B.

Alpha Beta

C.

^Alpha\ Beta$

D.

Alpha.Beta@mycompany.com

Buy Now
Questions 22

A network administrator is modifying an outgoing mail policy to enable domain protection for the organization. A DNS entry is created that has the public key.

Which two headers will be used as matching criteria in the outgoing mail policy? (Choose two.)

Options:

A.

message-ID

B.

sender

C.

URL reputation

D.

from

E.

mail-from

Buy Now
Questions 23

When DKIM signing is configured, which DNS record must be updated to load the DKIM public signing key?

Options:

A.

AAAA record

B.

PTR record

C.

TXT record

D.

MX record

Buy Now
Questions 24

An engineer must ensure that email sent from is not sent to the spam quarantine on a Cisco Secure Email Gateway. What must be configured on the Secure Email Gateway?

Options:

A.

URL filtering

B.

content filter

C.

safelist

D.

S/MIME

Buy Now
Questions 25

When the spam quarantine is configured on the Cisco Secure Email Gateway, which type of query is used to validate non administrative user access to the end-user quarantine via LDAP?

Options:

A.

spam quarantine end-user authentication

B.

spam quarantine alias consolidation

C.

spam quarantine external authorization

D.

local mailbox (IMAP/POP) authentication

Buy Now
Questions 26

A content dictionary was created for use with Forged Email Detection. Proper data that pertains to the CEO Example CEO: < ceo@example com > must be entered. What must be added to the dictionary to accomplish this goal?

Options:

A.

example.com

B.

Example CEO

C.

ceo

D.

ceo@example com

Buy Now
Questions 27

An engineer must configure the message source when integrating Cisco Secure Email Threat Defense with Microsoft 365. The integration must allow visibility but not remediation. Drag and drop the actions from the left into sequence on the right to meet the requirement.

300-720 Question 27

Options:

Buy Now
Questions 28

An engineer is tasked with reviewing mail logs to confirm that messages sent from domain abc.com are passing SPF verification and being accepted by the Cisco ESA. The engineer notices that SPF veri fication is not being performed and that SPF is not being referenced in the logs for messages sent from domain abc.com.

Why is the verification not working properly?

Options:

A.

SPF verification is disabled in the Recipient Access Table.

B.

SPF verification i s disabled on the Mail Flow Policy.

C.

The SPF conformance level is set to SIDF compatible on the Mail Flow Policy.

D.

An SPF verification Content Filter has not been created.

Buy Now
Questions 29

How does the graymail safe unsubscribe feature function?

Options:

A.

It strips the malicious content of the URI before unsubscribing.

B.

It checks the URI reputation and category and allows the content filter to take an action on it.

C.

It redirects the end user who clicks the unsubscribe button to a sandbox environment to allow a safe unsubscribe.

D.

It checks the reputation of the URI and performs the unsubscribe process on behalf of the end user.

Buy Now
Questions 30

Which global setting is configured under Cisco ESA Scan Behavior?

Options:

A.

minimum attachment size to scan

B.

attachment scanning timeout

C.

actions for unscannable messages due to attachment type

D.

minimum depth of attachment recursion to scan

Buy Now
Questions 31

An organization wants to use DMARC to improve its brand reputation by leveraging DNS records.

Which two email authentica tion mechanisms are utilized during this process? (Choose two.)

Options:

A.

SPF

B.

DSTP

C.

DKIM

D.

TLS

E.

PKI

Buy Now
Questions 32

An engineer must configure a policy quarantine in Cisco Secure Email Gateway. The retention time must be 7 days and user@cisco.com must have access to the quarantine. Drag and drop the actions from the left into the sequence on the right to meet the requirements.

300-720 Question 32

Options:

Buy Now
Questions 33

A Cisco ESA administrator has several mail policies configured. While testing policy match using a specific sender, the email was not matching the expected policy.

What is the reason of this?

Options:

A.

The Tram* header is checked against all policies in a top-down fashion.

B.

The message header with the highest priority is checked ag ainst each policy in a top-down fashion.

C.

The To " header is checked against all policies in a top-down fashion.

D.

The message header with the highest priority is checked against the Default policy in a top-down fashion.

Buy Now
Questions 34

Drag and drop the AsyncOS methods for performing DMARC verification from the left into the correct order on the right.

300-720 Question 34

Options:

Buy Now
Questions 35

Spammers routinely try to send emails with the recipient field filled with a list of all possible combinations of letters and numbers. These combinations, appended with a company domain name are malicious attempts at learning all possible valid email addresses. Which action must be taken on a Cisco Secure Email Gateway to prevent this from occurring?

Options:

A.

Select the SMTP Authentication Query checkbox

B.

Perform LDAP acceptance validation.

C.

Quarantine external authentication queries.

D.

Enable end user safelist features

Buy Now
Questions 36

A Cisco ESA administrator was notified that a user wa s not receiving emails from a specific domain. After reviewing the mail logs, the sender had a negative sender-based reputation score.

What should the administrator do to allow inbound email from that specific domain?

Options:

A.

Create a new inbound mail polic y with a message filter that overrides Talos.

B.

Ask the user to add the sender to the email application ' s allow list.

C.

Modify the firewall to allow emails from the domain.

D.

Add the domain into the allow list.

Buy Now
Questions 37

Which functionality is impacted if the assigned certificate under one of the IP interfaces is modified?

Options:

A.

traffic between the Cisco Secure Email Gateway and the LDAP server

B.

emails being delivered from the Cisco Secure Email Gateway

C.

HTTPS traffic when connecting to the web user interface of the Cisco Secure Email Gateway

D.

emails being received by the Cisco Secure Email Gateway

Buy Now
Questions 38

An engineer must provide user access to the spam quarantine on a Cisco Secure Email Gateway. Users must be able to access the spam quarantine without additional authentication by using links. The users must be able to preview a spam message from within the Spam Quarantine section without restoring the message. Drag and drop the actions from the left into sequence on the right to meet the requirements.

300-720 Question 38

Options:

Buy Now
Questions 39

An organization has a strict policy on URLs embedded in emails. The policy allows visibility into what the URL is but does not allow the user to click it. Which action must be taken to meet the requirements of the security policy?

Options:

A.

Enable the URL quarantine policy

B.

Defang the URL.

C.

Replace the URL with text

D.

Redirect the URL to the Cisco security proxy

Buy Now
Questions 40

Which two statements about configuring message filters within the Cisco ESA are true? (Choose two.)

Options:

A.

The filters command executed from the CLI is used to configure the message filters.

B.

Message filters configuration within the web user interface is located within Incoming Content Filters.

C.

The filterconfig command executed from the CLI is used to configure message filters.

D.

Message filters can be configured only from the CLI.

E.

Message filters can be configured only from the web user interface.

Buy Now
Questions 41

A network engineer is integrating Cisco Secure Email Gateway with Cisco SecureX. Which two actions must be taken before registering Cisco Secure Email Gateway with Cisco SecureX? (Choose two.)

Options:

A.

Run the threatresponseconflg command in SecureX

B.

Open TCP port 22 on the firewall

C.

Open TCP port 443 on the firewall.

D.

Run the cloudserviceconflg command in SecureX

E.

Create an admin account in SecureX

Buy Now
Questions 42

An administrator has cr eated a content filter to quarantine all messages that result in an SPF hardfail to review the messages and determine whether a trusted partner has accidentally misconfigured the DNS settings. The administrator sets the policy quarantine to release the mes sages after 24 hours, allowing time to review while not interrupting business.

Which additional option should be used to help the end users be aware of the elevated risk of interacting with these messages?

Options:

A.

Notify Recipient

B.

Strip Attachments

C.

Notify Sender

D.

Modify Subject

Buy Now
Questions 43

Which action on the Cisco ESA provides direct access to view the safelist/blocklist?

Options:

A.

Show the SLBL cache on the CLI.

B.

Monitor Incoming/Outgoing Listener.

C.

Export the SLBL to a .csv file.

D.

Debug the mail flow policy.

Buy Now
Questions 44

Spreadsheets containing credit card numbers are being allowed to bypass the Cisco ESA.

Which outgoing mail policy feature should be configured to catch this content before it leaves the network?

Options:

A.

file reputation filtering

B.

outbreak filtering

C.

data loss prevention

D.

file analysis

Buy Now
Questions 45

Which content filter condition checks to see if the " From: header " in the message is similar to any of the users in the content dictionary?

Options:

A.

Forged Email Detection

B.

SPF Verification

C.

Subject Header

D.

Duplicate Boundaries Verification

Buy Now
Questions 46

Which components are required when encrypting SMTP with TLS on a Cisco Secure Email Gateway appliance when the sender requires TLS verification?

Options:

A.

DER certificate and matching public key from a CA

B.

self-signed certificate in PKCS#7 format

C.

X. 509 certificate and matching private key from a CA

D.

self-signed certificate in PKCS#12 format

Buy Now
Questions 47

An administrator needs to configure Cisco ESA to ensure that emails are sent and authorized by th e owner of the domain. Which two steps must be performed to accomplish this task? (Choose two.)

Options:

A.

Generate keys.

B.

Create signing profile.

C.

Create Mx record.

D.

Enable SPF verification.

E.

Create DMARC profile.

Buy Now
Questions 48

A list of company executives is routinely being spoofed, which puts the company at risk of malicious email attacks An administrator must ensure that executive messages are originating from legitimate sending addresses Which two steps must be taken to accomplish this task? (Choose two.)

Options:

A.

Create an incoming content filter with SPF detection.

B.

Enable the Forged Email Detection feature under Security Settings.

C.

Enable DMARC feature under Mail Policies.

D.

Create an incoming content filter with the Forged Email Detection condition

E.

Create a content dictionary including a list of the names that are being spoofed.

Buy Now
Questions 49

What is the purpose of Cisco Email Encryption on Cisco ESA?

Options:

A.

to ensure anonymity between a recipient and MTA

B.

to ensure integrity between a sender and MTA

C.

to aut henticate direct communication between a sender and Cisco ESA

D.

to ensure privacy between Cisco ESA and MTA

Buy Now
Questions 50

What are the two different phases in the process of Cisco Secure Email Gateway performing S/MIME encryption? (Choose two.)

Options:

A.

Attach the encrypted public key to the message

B.

Encrypt the message body using the session key

C.

Send the encrypted message to the sender

D.

Attach the encrypted symmetric key to the message

E.

Create a pseudo-random session key.

Buy Now
Questions 51

When an email is sent with bounce verification enabled, which address is rewritten by the Cisco Secure Email Gateway in the message?

Options:

A.

sender

B.

envelope recipient

C.

recipient

D.

envelope sender

Buy Now
Questions 52

An engineer must integrate Cisco Secure Email with the Cisco Secure Endpoint console. Which two settings must be configured to prevent zero-day threats? (Choose two.)

Options:

A.

File Reputation Filtering

B.

Message Filters

C.

Content Filter Settings

D.

Undesirable URL Settings

E.

File Analysis

Buy Now
Questions 53

Which two factors must be considered when message filter processing is configured? (Choose two.)

Options:

A.

message-filter order

B.

lateral processing

C.

structure of the combined packet

D.

mail policies

E.

MIME structure of the message

Buy Now
Questions 54

Which action is allowed while managing list of certificate authorities on Cisco Secure Email Gateway?

Options:

A.

Export the list to the xml file.

B.

Remove the preinstalled list.

C.

Accept the selected certificate list.

D.

Enable the system list.

Buy Now
Questions 55

When a network engineer is troubleshooting a mail flow issue, they discover that some emails are rejected with an SMTP code of 451 and the error message " #4.7.1 Unable to perform DMARC verification " . In the DMARC verification profile on the Cisco Secure Email Gateway appliance, which action must be set for messages that result in temporary failure to prevent these emails from being rejected?

Options:

A.

Accept

B.

Ignore

C.

Quarantine

D.

No Action

Buy Now
Questions 56

An engineer must configure a virtual gateway on a Cisco Secure Email Gateway to send email for a group named Grouplnt. Grouplnt is part of these domains:

•domain 1 -lab

•domain2.lab

Drag and drop the code snippets from the right onto the boxes to configure the virtual gateway. Not all options are used.

300-720 Question 56

Options:

Buy Now
Questions 57

Refer to the exhibit.

300-720 Question 57

An administrator has configured File Reputation and File Analysis on the Cisco Secure Email Gateway appliance however it does not function as expected What must be configured on the appliance for this to function?

Options:

A.

Upload the Root CA certificate for the File Reputation cloud to the Cisco Secure Email Gateway.

B.

Open port 443 on the firewall for the Cisco Secure Email Gateway to connect to the File Reputation cloud.

C.

Configure the Cisco Secure Email Gateway to use SSL for the connection to the File Reputation server

D.

Restart the File Reputation service to force the scanning engine to connect to the File Reputation cloud.

Buy Now
Exam Code: 300-720
Exam Name: Securing Email with Cisco Email Security Appliance (300-720 SESA)
Last Update: May 25, 2026
Questions: 190

PDF + Testing Engine

$144.99

Testing Engine

$109.99

PDF (Q&A)

$94.99