[Apr 05, 2024] Pass 300-720 Review Guide, Reliable 300-720 Test Engine [Q84-Q100]

Share

[Apr 05, 2024] Pass 300-720 Review Guide, Reliable 300-720 Test Engine

300-720 Test Engine Practice Test Questions, Exam Dumps


Cisco 300-720 exam is designed to test the knowledge and skills of candidates in securing email with the Cisco Email Security Appliance. 300-720 exam is intended for professionals who are responsible for designing, implementing, and managing email security solutions for their organizations. 300-720 exam covers topics such as email security architecture, policy management, message filtering, threat detection, and encryption.

 

NEW QUESTION # 84
When DKIM signing is configured, which DNS record must be updated to load the DKIM public signing key?

  • A. PTR record
  • B. TXT record
  • C. AAAA record
  • D. MX record

Answer: B

Explanation:
Explanation/Reference: https://www.cisco.com/c/en/us/support/docs/security/email-security-appliance/213939-esa- configure-dkim-signing.html


NEW QUESTION # 85
Which type of attack is prevented by configuring file reputation filtering and file analysis features?

  • A. denial of service
  • B. backscatter
  • C. phishing
  • D. zero-day

Answer: D

Explanation:
The type of attack that is prevented by configuring file reputation filtering and file analysis features is zero-day. Zero-day attacks are those that exploit unknown vulnerabilities in software or systems before they are patched or fixed. File reputation filtering and file analysis features help to protect against zero-day attacks by checking the reputation of files attached to email messages and sending them to a cloud-based service for dynamic analysis.


NEW QUESTION # 86
Which components are required when encrypting SMTP with TLS on a Cisco Secure Email Gateway appliance when the sender requires TLS verification?

  • A. X. 509 certificate and matching private key from a CA
  • B. DER certificate and matching public key from a CA
  • C. self-signed certificate in PKCS#7 format
  • D. self-signed certificate in PKCS#12 format

Answer: A

Explanation:
To encrypt SMTP with TLS on a Cisco Secure Email Gateway appliance when the sender requires TLS verification, the components that are required are an X.509 certificate and matching private key from a CA. The certificate must be signed by a trusted CA and contain the domain name or IP address of the listener in the Subject or Subject Alternative Name fields. The private key must be unencrypted and match the certificate. Reference: [Cisco Secure Email Gateway Administrator Guide - Configuring TLS]


NEW QUESTION # 87
What is a valid content filter action?

  • A. skip antispam
  • B. decrypt on delivery
  • C. archive
  • D. quarantine

Answer: D


NEW QUESTION # 88
Which two components form the graymail management solution in Cisco ESA? (Choose two.)

  • A. improved mail efficacy
  • B. cloud-based unsubscribe service
  • C. uniform unsubscription management interface for end users
  • D. secure subscribe option for end users
  • E. integrated graymail scanning engine

Answer: B,E

Explanation:
The graymail management solution in the appliance comprises of two components: an integrated graymail scanning engine and a cloud-based Unsubscribe Service. The integrated graymail scanning engine identifies graymail messages using various criteria and assigns them to different categories. The cloud-based Unsubscribe Service provides an easy mechanism for end users to unsubscribe from unwanted messages by checking the reputation of the unsubscribe links and performing the unsubscribe process on behalf of the end user.


NEW QUESTION # 89
Refer to the exhibit. What is the correct order of commands to set filter 2 to active?

  • A. filters-> modify-> All-> Active
  • B. filters-> detail-> 2-> 1
  • C. filters-> set-> 2-> 1
  • D. filters-> edit-> 2-> Active

Answer: C

Explanation:
The correct order of commands to set filter 2 to active on the CLI of Cisco ESA is:
filters, which enters the message filter mode.
set, which sets the status of one or more message filters.
2, which specifies the message filter number.
1, which sets the status of message filter 2 to active.
The other options are not valid orders of commands to set filter 2 to active on the CLI of Cisco ESA, because they use incorrect commands or parameters.


NEW QUESTION # 90
Refer to the exhibit. Which configuration on the scan behavior must be updated to allow the attachment to be scanned on the Cisco ESA?

  • A. Add an additional mapping for attachment type for zip files.
  • B. Enable assume match pattern if the email was not scanned for any reason.
  • C. Increase the maximum recursion depth from 5 to a larger value.
  • D. Increase the maximum attachment size to scan to a larger value.

Answer: D

Explanation:
The maximum attachment size to scan is a configuration on the scan behavior that determines the maximum size of an attachment that Cisco ESA will scan for viruses and malware. If an attachment exceeds this size, Cisco ESA will apply the configured action for unscannable messages, such as deliver, drop, or quarantine.
To allow the attachment to be scanned on the Cisco ESA, this configuration must be updated to a larger value than the attachment size, which is 10 MB according to the message header.
The other options are not valid configurations to allow the attachment to be scanned on the Cisco ESA, because they do not affect the maximum attachment size to scan.


NEW QUESTION # 91
A Cisco ESA administrator has noticed that new messages being sent to the Centralized Policy Quarantine are being released after one hour. Previously, they were being held for a day before being released.
What was configured that caused this to occur?

  • A. The retention period was set to default.
  • B. The threshold settings were set to default.
  • C. The retention period was changed to one hour.
  • D. The threshold settings were set to override the clock settings.

Answer: A

Explanation:
You can configure Policy, Virus, and Outbreak Quarantines in any one of the following ways:
Choose Quarantine > Other Quarantine > View > +.
Choose Monitor > Policy, Virus, and Outbreak Quarantines and do one of the following.
Click Add Policy Quarantine.
Keep the following in mind, changing the retention time of the File Analysis quarantine from the default of one hour is not recommended.
https://www.cisco.com/c/en/us/td/docs/security/esa/esa14-0/user_guide/b_ESA_Admin_Guide_14-0/b_ESA_Admin_Guide_12_1_chapter_011111.html?bookSearch=true


NEW QUESTION # 92
Which two components must be configured to perform DLP scanning? (Choose two.)

  • A. Add a DLP policy to the DLP Policy Manager.
  • B. Enable a DLP policy on the DLP Policy Customizations.
  • C. Enable a DLP policy on the Outgoing Mail Policy.
  • D. Add a DLP policy on the Incoming Mail Policy.
  • E. Add a DLP policy to the Outgoing Content Filter.

Answer: A,C

Explanation:
To perform DLP scanning on Cisco ESA, two components must be configured:
Add a DLP policy to the DLP Policy Manager, which is a repository of predefined or custom DLP policies that specify what types of data to scan for and what actions to take if a match is found.
Enable a DLP policy on the Outgoing Mail Policy, which is a set of rules that determine how outgoing messages are processed by Cisco ESA, including whether to apply DLP scanning or not.


NEW QUESTION # 93
A list of company executives is routinely being spoofed, which puts the company at risk of malicious email attacks An administrator must ensure that executive messages are originating from legitimate sending addresses Which two steps must be taken to accomplish this task? (Choose two.)

  • A. Create an incoming content filter with the Forged Email Detection condition
  • B. Enable DMARC feature under Mail Policies.
  • C. Create a content dictionary including a list of the names that are being spoofed.
  • D. Create an incoming content filter with SPF detection.
  • E. Enable the Forged Email Detection feature under Security Settings.

Answer: A,C

Explanation:
To ensure that executive messages are originating from legitimate sending addresses, the administrator must take two steps:
Create an incoming content filter with the Forged Email Detection condition. This will allow the administrator to detect and block messages that have a forged "From: header" that matches or is similar to any of the names in a content dictionary.
Create a content dictionary including a list of the names that are being spoofed. This will allow the administrator to specify the names of the executives that are being targeted by spoofing attacks and use them in the Forged Email Detection condition. The other options are not relevant or sufficient for this task. Reference: [Cisco Secure Email Gateway Administrator Guide - Forged Email Detection] and [Cisco Secure Email Gateway Administrator Guide - Creating Content Dictionaries]


NEW QUESTION # 94
Drag and drop the steps to configure Cisco ESA to use SPF/SIDF verification from the left into the correct order on the right.

Answer:

Explanation:


NEW QUESTION # 95
Which antispam feature is utilized to give end users control to allow emails that are spam to be delivered to their inbox, overriding any spam verdict and action on the Cisco ESA?

  • A. end user spam quarantine access
  • B. end user passthrough list
  • C. end user safelist
  • D. end user allow list

Answer: C

Explanation:
End user safelist is a feature that allows end users to specify email addresses or domains that they want to receive messages from, regardless of the spam verdict or action assigned by Cisco ESA. Messages from senders on the end user safelist are delivered to the end user's inbox without any spam filtering.


NEW QUESTION # 96
An engineer is testing mail flow on a new Cisco ESA and notices that messages for domain abc.com are stuck in the delivery queue. Upon further investigation, the engineer notices that the messages pending delivery are destined for 192.168.1.11, when they should instead be routed to 192.168.1.10.
What configuration change needed to address this issue?

  • A. Modify the Routing Tables and add a route for IP address to 192.168.1.10.
  • B. Modify the SMTP route for the domain and change the IP address to 192.168.1.10.
  • C. Add an address list for domain abc.com.
  • D. Modify Destination Controls entry for the domain abc.com.

Answer: B


NEW QUESTION # 97
Which two steps are needed to disable local spam quarantine before external quarantine is enabled? (Choose two.)

  • A. Check the External Safelist/Blocklist check box.
  • B. Select Security Services and click Spam Quarantine.
  • C. Uncheck the Enable Spam Quarantine check box.
  • D. Select Monitor and click Spam Quarantine.
  • E. Select External Spam Quarantine and click on Configure.

Answer: C,D

Explanation:
Reference:
https://www.cisco.com/c/en/us/support/docs/security/email-security-appliance/118555-qa-esa- 00.html (configuration summary)


NEW QUESTION # 98
Which two features are applied to either incoming or outgoing mail policies? (Choose two.)

  • A. application filtering
  • B. antivirus
  • C. sender reputation filtering
  • D. outbreak filters
  • E. Indication of Compromise

Answer: B,D

Explanation:
Explanation/Reference: https://www.cisco.com/c/en/us/td/docs/security/esa/esa11-1/user_guide/ b_ESA_Admin_Guide_11_1/b_ESA_Admin_Guide_chapter_01001.html


NEW QUESTION # 99
What is the default port to deliver emails from the Cisco ESA to the Cisco SMA using the centralized Spam Quarantine?

  • A. 0
  • B. 1
  • C. 2
  • D. 3

Answer: B

Explanation:
Reference:
https://www.cisco.com/c/en/us/support/docs/security/email-security-appliance/118692-configure- esa-00.html


NEW QUESTION # 100
......


Cisco 300-720 exam is a valuable certification for IT professionals who want to specialize in email security. Passing 300-720 exam demonstrates that the candidate has the skills and knowledge to secure an organization's email infrastructure using the Cisco Email Security Appliance.


The Securing Email with Cisco Email Security Appliance certification exam covers various topics such as email security, Cisco Email Security Appliance architecture, message filtering, and message tracking. It also covers the configuration and management of email encryption, antispam, and antivirus features.

 

100% Free 300-720 Daily Practice Exam With 149 Questions: https://www.realexamfree.com/300-720-real-exam-dumps.html

300-720 exam torrent Cisco study guide: https://drive.google.com/open?id=1e2pLHkUQJWKdP3s4YWpVny1hkUw8973N