[Jan-2024] 300-720 PDF Dumps Are Helpful To produce Your Dreams Correct QA's
New 300-720 exam Free Sample Questions to Practice
Cisco 300-720 (Securing Email with Cisco Email Security Appliance) Certification Exam is a professional-level certification exam offered by Cisco. 300-720 exam is designed to validate the skills and knowledge required for securing email using Cisco Email Security Appliance technologies. 300-720 exam covers a wide range of topics related to email security, including email filtering, anti-spam, anti-virus, content filtering, and email encryption.
Cisco 300-720 exam is a challenging certification exam that tests the skills and knowledge of professionals in securing email with the Cisco Email Security Appliance. Professionals who pass 300-720 exam are recognized as experts in email security and Cisco Email Security Appliance and can expect to have better job opportunities and higher salaries.
Cisco 300-720 certification exam is an excellent opportunity for IT professionals to showcase their skills and knowledge in securing email with Cisco Email Security Appliance. It is a valuable certification that can help individuals advance their careers and become more valuable to their organizations. With the increasing importance of email security, obtaining this certification can make a significant difference in an IT professional's career.
NEW QUESTION # 62
When URL logging is configured on a Cisco ESA, which feature must be enabled first?
- A. antivirus
- B. senderbase reputation filter
- C. virus outbreak filter
- D. antispam
Answer: C
Explanation:
Enabling Logging of URLs and Message Tracking Details for URLs
Logging of URL-related logs, and display of this information in Message Tracking details, is disabled by default. This includes the logs for the following events:
Category of any URL in the message matches the URL category filters
Reputation score of any URL in the message matches URL reputation filters Outbreak Filter rewrites any URL in the message To enable logging of these events, use the outbreakconfig command in the command-line interface (CLI).
https://www.cisco.com/c/en/us/td/docs/security/esa/esa11-1/user_guide/b_ESA_Admin_Guide_11_1/b_ESA_Admin_Guide_chapter_01110.html?bookSearch=true
NEW QUESTION # 63
Which benefit does enabling external spam quarantine on Cisco SMA provide?
- A. ability to scan messages by using two engines to increase a catch rate
- B. ability to back up spam quarantine from multiple Cisco ESAs to one central console
- C. ability to consolidate spam quarantine data from multiple Cisco ESA to one central console
- D. access to the spam quarantine interface on which a user can release, duplicate, or delete
Answer: C
Explanation:
Explanation/Reference: https://www.cisco.com/c/en/us/td/docs/security/security_management/sma/sma11-0/ user_guide/b_SMA_Admin_Guide/b_SMA_Admin_Guide_chapter_010101.html
NEW QUESTION # 64
A network administrator notices that there are a high number of queries to the LDAP server. The mail logs show an entry "550 Too many invalid recipients | Connection closed by foreign host." Which feature must be used to address this?
- A. SBRS
- B. SMTP
- C. LDAP
- D. DHAP
Answer: B
NEW QUESTION # 65
When DKIM signing is configured, which DNS record must be updated to load the DKIM public signing key?
- A. TXT record
- B. MX record
- C. PTR record
- D. AAAA record
Answer: A
NEW QUESTION # 66
Which functionality is impacted if the assigned certificate under one of the IP interfaces is modified?
- A. HTTPS traffic when connecting to the web user interface of the Cisco Secure Email Gateway
- B. emails being received by the Cisco Secure Email Gateway
- C. traffic between the Cisco Secure Email Gateway and the LDAP server
- D. emails being delivered from the Cisco Secure Email Gateway
Answer: A
Explanation:
If the assigned certificate under one of the IP interfaces is modified, then the HTTPS traffic when connecting to the web user interface of the Cisco Secure Email Gateway will be impacted. The administrator must ensure that the certificate is valid and trusted by the browser or client that is used to access the web user interface. Otherwise, the connection may fail or generate a warning message. Reference: [Cisco Secure Email Gateway Administrator Guide - Configuring Certificates]
NEW QUESTION # 67
Refer to the exhibit.

Which configuration allows the Cisco Secure Email Gateway to scan for executables inside the archive file and apply the action as per the content filter?
- A. Modify the content filter to look for exe filename instead of executable filetype.
- B. Configure the recursion depth to a higher value.
- C. Modify the content filter to look for attachment filetype of compressed.
- D. Configure the maximum attachment size to a higher value.
Answer: B
Explanation:
The recursion depth is the number of levels that the Cisco Secure Email Gateway will scan inside an archive file for executables and other file types. If the recursion depth is too low, some executables may not be detected and scanned by the content filter. To allow the appliance to scan for executables inside the archive file and apply the action as per the content filter, you need to configure the recursion depth to a higher value1. Reference = User Guide for AsyncOS 12.0 for Cisco Email Security Appliances - GD (General Deployment) - Configuring File Reputation Filtering and File Analysis [Cisco Secure Email Gateway] - Cisco
NEW QUESTION # 68
An engineer is testing mail flow on a new Cisco ESA and notices that messages for domain abc.com are stuck in the delivery queue. Upon further investigation, the engineer notices that the messages pending delivery are destined for 192.168.1.11, when they should instead be routed to 192.168.1.10.
What configuration change needed to address this issue?
- A. Modify the Routing Tables and add a route for IP address to 192.168.1.10.
- B. Add an address list for domain abc.com.
- C. Modify the SMTP route for the domain and change the IP address to 192.168.1.10.
- D. Modify Destination Controls entry for the domain abc.com.
Answer: C
Explanation:
Reference:
You can use the SMTP route feature on Cisco ESA to specify how messages for a specific domain are routed to their destination. You can modify the SMTP route for the domain abc.com and change the IP address to 192.168.1.10 to ensure that messages are delivered correctly3. Reference = Securing Email with Cisco Email Security Appliance (SESA) v3.1
NEW QUESTION # 69
Which option describes how the Cisco ESA fits into a network?
- A. It handles SMTP-related traffic by routing the packets.
- B. The product should be installed in the DMZ.
- C. It process POP3 messages.
- D. It works as a mail exchange.
Answer: A
NEW QUESTION # 70
What is the default method of remotely accessing a newly deployed Cisco Secure Email Virtual Gateway when a DHCP server is not available?
- A. DHCP is required for the initial IP address assignment
- B. Manual configuration of an IP address is required through the hypervisor console before remote access
- C. Use the IP address of 192.168 42 42 via the Management port
- D. Manual configuration of an IP address is required through the serial port before remote access
Answer: C
Explanation:
The default method of remotely accessing a newly deployed Cisco Secure Email Virtual Gateway when a DHCP server is not available is to use the IP address of 192.168.42.42 via the Management port. This IP address is assigned by default to the Management port of the virtual gateway and can be used to access the web user interface or the command-line interface of the appliance. Reference: [Cisco Secure Email Gateway Installation and Upgrade Guide - Configuring Network Settings]
NEW QUESTION # 71
Which two statements about configuring message filters within the Cisco ESA are true? (Choose two.)
- A. Message filters configuration within the web user interface is located within Incoming Content Filters.
- B. Message filters can be configured only from the CLI.
- C. Message filters can be configured only from the web user interface.
- D. The filters command executed from the CLI is used to configure the message filters.
- E. The filterconfig command executed from the CLI is used to configure message filters.
Answer: B,D
Explanation:
Message filters can only be applied to the ESA via command line. So, you will need command line access to the ESA.
Log into the ESA via command line.
Run the following highlighted commands to apply the message filter to the ESA:
ironport.example.com> filters
Choose the operation you want to perform:
- NEW - Create a new filter.
- IMPORT - Import a filter script from a file.
[]> NEW
Enter filter script. Enter '.' on its own line to end.
large_spam_no_attachment:
if ((body-size > 2097152) AND NOT (attachment-size > 0)) {
quarantine("large_spam");
log-entry("*****This is a large message with no attachments*****");
}
.
1 filters added.
NEW QUESTION # 72
Which two action types are performed by Cisco ESA message filters? (Choose two.)
- A. quarantine actions
- B. discard actions
- C. non-final actions
- D. filter actions
- E. final actions
Answer: C,E
Explanation:
Reference:
https://www.cisco.com/c/en/us/td/docs/security/esa/esa11-1/user_guide/ b_ESA_Admin_Guide_11_1/b_ESA_Admin_Guide_chapter_01000.html
NEW QUESTION # 73
An administrator is managing multiple Cisco ESA devices and wants to view the quarantine emails from all devices in a central location.
How is this accomplished?
- A. Configure a mail policy to determine whether the message is sent to the local or external quarantine.
- B. Configure a user policy to determine whether the message is sent to the local or external quarantine.
- C. Disable the VOF feature before sending SPAM to the external quarantine.
- D. Disable the local quarantine before sending SPAM to the external quarantine.
Answer: A
Explanation:
https://www.cisco.com/c/en/us/td/docs/security/esa/esa12-
0/user_guide/b_ESA_Admin_Guide_12_0/b_ESA_Admin_Guide_12_0_chapter_0100000.html#t ask _1749146
NEW QUESTION # 74
What occurs when configuring separate incoming mail policies?
- A. message aggregation
- B. message exceptions
- C. message detachment
- D. message splintering
Answer: D
Explanation:
Message splintering is a process that occurs when configuring separate incoming mail policies on Cisco ESA. Message splintering means that Cisco ESA will split a single incoming message into multiple copies, each with a different recipient and policy, and apply different security services and actions to each copy.
NEW QUESTION # 75
Refer to the exhibit.
Which SPF record is valid for mycompany.com?
- A. v=spf1 a mx ip4:199.209.31.21 -all
- B. v=spf1 a mx ip4:10.1.10.23 -all
- C. v=spf1 a mx ip4:172.16.18.230 -all
- D. v=spf1 a mx ip4:199.209.31.2 -all
Answer: C
NEW QUESTION # 76
Which of the following types of DNS records deals with mail delivery for a specific domain?
- A. TXT
- B. PTR
- C. MX
- D. A
Answer: C
NEW QUESTION # 77
Drag and drop the AsyncOS methods for performing DMARC verification from the left into the correct order on the right.
Answer:
Explanation:

NEW QUESTION # 78
What is the maximum message size that can be configured for encryption on the Cisco ESA?
- A. 20 MB
- B. 15 MB
- C. 30 MB
- D. 25 MB
Answer: A
Explanation:
Reference:
https://www.cisco.com/c/en/us/support/docs/security/email-security-appliance/117972-technote- esa-00.html
NEW QUESTION # 79
What is the default HTTPS port when configuring spam quarantine on Cisco ESA?
- A. 0
- B. 1
- C. 2
- D. 3
Answer: B
NEW QUESTION # 80
Which feature must be configured before an administrator can use the outbreak filter for nonviral threats?
- A. quarantine threat level
- B. antivirus
- C. antispam
- D. data loss prevention
Answer: C
Explanation:
Explanation/Reference: https://www.cisco.com/c/en/us/td/docs/security/esa/esa12-0/user_guide/ b_ESA_Admin_Guide_12_0/b_ESA_Admin_Guide_chapter_01110.html
NEW QUESTION # 81
An Encryption Profile has been set up on the Cisco ESA.
Drag and drop the steps from the left for creating an outgoing content filter to encrypt emails that contains the subject "Secure:" into the correct order on the right.
Answer:
Explanation:

NEW QUESTION # 82
Which two steps are needed to disable local spam quarantine before external quarantine is enabled? (Choose two.)
- A. Select Security Services and click Spam Quarantine.
- B. Select External Spam Quarantine and click on Configure.
- C. Select Monitor and click Spam Quarantine.
- D. Uncheck the Enable Spam Quarantine check box.
- E. Check the External Safelist/Blocklist check box.
Answer: C,D
NEW QUESTION # 83
Which two action types are performed by Cisco ESA message filters? (Choose two.)
- A. quarantine actions
- B. discard actions
- C. non-final actions
- D. filter actions
- E. final actions
Answer: C,E
NEW QUESTION # 84
A Cisco Secure Email Gateway appliance is processing many messages that are sent to invalid recipients verification. Which two steps are required to accomplish this task? (Choose two.)
- A. Enable external LDAP authentication
- B. Configure LDAP server profiles
- C. Configure incoming mail policy to query LDAP server
- D. Enable LDAP authentication on a listener
- E. Configure the LDAP query on a listener
Answer: B,E
Explanation:
To enable LDAP recipient verification on a Cisco Secure Email Gateway appliance, you need to configure the LDAP query on a listener and configure LDAP server profiles. The LDAP query specifies the criteria for matching recipient addresses against an LDAP directory. The LDAP server profile defines the connection settings and authentication credentials for accessing an LDAP server2. Reference = User Guide for AsyncOS 12.0 for Cisco Email Security Appliances - GD (General Deployment) - Configuring LDAP Queries [Cisco Secure Email Gateway] - Cisco
NEW QUESTION # 85
......
Cover 300-720 Exam Questions Make Sure You 100% Pass: https://examtests.passcollection.com/300-720-valid-vce-dumps.html

