2023 300-720 Dumps PDF - 300-720 Real Exam Questions Answers
Valid 300-720 Test Answers & Cisco 300-720 Exam PDF
NEW QUESTION # 29
What is the default behavior of any listener for TLS communication?
- A. preferred-verify
- B. preferred
- C. off
- D. required
Answer: C
Explanation:
The default behavior of any listener for TLS communication is B. off. This means that TLS is not allowed for incoming connections to the listener and connections to the listener do not require encrypted Simple Mail Transfer Protocol (SMTP) conversations. This is stated in the web search result 1. To enable TLS for a listener, you need to configure the Use TLS option in the mail flow policy settings for the listener on the Mail Policies > HAT Overview page1. You can choose from three different settings for TLS: No, Preferred, or Required1.
NEW QUESTION # 30
Which ESA function maintains a set of rules that control incoming connections from remote hosts for a listener?
- A. Sender group
- B. HAT
- C. LDAP
- D. VEST
- E. RAT
Answer: B
NEW QUESTION # 31
When virtual gateways are configured, which two distinct attributes are allocated to each virtual gateway address? (Choose two.)
- A. external spam quarantine
- B. DHCP server address
- C. DNS server address
- D. domain
- E. IP address
Answer: D,E
Explanation:
Reference:
https://www.cisco.com/c/en/us/support/docs/security/email-security-appliance/118542-qa-esa- 00.html
NEW QUESTION # 32
What is the purpose of Cisco Email Encryption on Cisco ESA?
- A. to authenticate direct communication between a sender and Cisco ESA
- B. to ensure anonymity between a recipient and MTA
- C. to ensure integrity between a sender and MTA
- D. to ensure privacy between Cisco ESA and MTA
Answer: D
NEW QUESTION # 33
A Cisco Secure Email Gateway appliance is processing many messages that are sent to invalid recipients verification. Which two steps are required to accomplish this task? (Choose two.)
- A. Configure incoming mail policy to query LDAP server
- B. Enable LDAP authentication on a listener
- C. Configure the LDAP query on a listener
- D. Enable external LDAP authentication
- E. Configure LDAP server profiles
Answer: C,E
Explanation:
To enable LDAP recipient verification on a Cisco Secure Email Gateway appliance, you need to configure the LDAP query on a listener and configure LDAP server profiles. The LDAP query specifies the criteria for matching recipient addresses against an LDAP directory. The LDAP server profile defines the connection settings and authentication credentials for accessing an LDAP server2. Reference = User Guide for AsyncOS 12.0 for Cisco Email Security Appliances - GD (General Deployment) - Configuring LDAP Queries [Cisco Secure Email Gateway] - Cisco
NEW QUESTION # 34
Which two are configured in the DMARC verification profile? (Choose two.)
- A. message action to take when the policy is reject/quarantine
- B. message action into an incoming or outgoing content filter
- C. name of the verification profile
- D. ESA listeners to use the verification profile
- E. minimum number of signatures to verify
Answer: A,C
NEW QUESTION # 35
Spreadsheets containing credit card numbers are being allowed to bypass the Cisco ESA.
Which outgoing mail policy feature should be configured to catch this content before it leaves the network?
- A. outbreak filtering
- B. data loss prevention
- C. file analysis
- D. file reputation filtering
Answer: B
Explanation:
Data Loss Prevention (DLP) is an outgoing mail policy feature that should be configured to catch this content before it leaves the network. DLP allows Cisco ESA to scan outgoing messages for sensitive or confidential data, such as credit card numbers, social security numbers, health records, etc., and apply appropriate actions, such as encrypt, quarantine, notify, etc., to prevent data leakage or loss.
The other options are not valid outgoing mail policy features to catch this content before it leaves the network, because they do not scan for sensitive or confidential data in messages.
NEW QUESTION # 36
An engineer is testing mail flow on a new Cisco ESA and notices that messages for domain abc.com are stuck in the delivery queue. Upon further investigation, the engineer notices that the messages pending delivery are destined for 192.168.1.11, when they should instead be routed to 192.168.1.10.
What configuration change needed to address this issue?
- A. Add an address list for domain abc.com.
- B. Modify the Routing Tables and add a route for IP address to 192.168.1.10.
- C. Modify the SMTP route for the domain and change the IP address to 192.168.1.10.
- D. Modify Destination Controls entry for the domain abc.com.
Answer: C
NEW QUESTION # 37
An administrator notices that the Cisco Secure Email Gateway delivery queue on an appliance is consistently full. After further investigation, it is determined that the IP addresses currently in use by appliance are being rate-limited by some destinations. The administrator creates a new interface with an additional IP address using virtual gateway technology, but the issue is not solved Which configuration change resolves the issue?
- A. Use the CLI command deliveryconfig to set the new interface as the primary interface for mail delivery
- B. Use the CLI command loadbalance auto to enable mail delivery over all interfaces.
- C. Use the CLI command altsrchost to set the new interface as the source IP address for all mail.
- D. Use the CLI command alt-src-host to set the new interface as a possible delivery candidate.
Answer: A
Explanation:
Determining Which Interface is Used for Mail Delivery Unless you specify the output interface via the deliveryconfig</code> command or via a message filter ( alt-src-host ), or through the use of a virtual gateway, the output interface is selected by the AsyncOS routing table. https://www.cisco.com/c/en/us/td/docs/security/esa/esa11-1/user_guide/b_ESA_Admin_Guide_11_1/b_ESA_Admin_Guide_chapter_011001.html?bookSearch=true
NEW QUESTION # 38
Which global setting is configured under Cisco ESA Scan Behavior?
- A. minimum depth of attachment recursion to scan
- B. attachment scanning timeout
- C. minimum attachment size to scan
- D. actions for unscannable messages due to attachment type
Answer: B
Explanation:
Reference:
https://community.cisco.com/t5/email-security/cisco-ironport-esa-security-services-scan-behavior- impact-on-av/td-p/3923243
NEW QUESTION # 39
DRAG DROP
Drag and drop the AsyncOS methods for performing DMARC verification from the left into the correct order on the right.
Select and Place:
Answer:
Explanation:
Explanation/Reference:
https://www.cisco.com/c/en/us/td/docs/security/esa/esa11-1/user_guide/b_ESA_Admin_Guide_11_1/ b_ESA_Admin_Guide_11_1_chapter_010101.html
NEW QUESTION # 40
An engineer is tasked with creating a content filter to catch attachments, including credit card numbers, and hold them for review until further action is taken. Which component on a Cisco Secure Email Gateway must be configured to meet this requirement?
- A. Content Filter
- B. Outbreak Filter
- C. Spam Quarantine
- D. Policy Quarantine
Answer: A
Explanation:
Content filter is a component on a Cisco Secure Email Gateway that must be configured to catch attachments, including credit card numbers, and hold them for review until further action is taken. Content filter allows you to define rules based on message content and apply actions such as quarantine, encrypt, or modify. Reference = [User Guide for AsyncOS 12.0 for Cisco Email Security Appliances - GD (General Deployment) - Content Filters [Cisco Secure Email Gateway] - Cisco]
NEW QUESTION # 41
What are two primary components of content filters? (Choose two.)
- A. policies
- B. content
- C. actions
- D. conditions
- E. subject
Answer: C,D
NEW QUESTION # 42
Which attack is mitigated by using Bounce Verification?
- A. eavesdropping
- B. smurf
- C. denial of service
- D. spoof
Answer: C
NEW QUESTION # 43
What are two prerequisites for implementing undesirable URL protection in Cisco ESA? (Choose two.)
- A. Enable antispam scanning.
- B. Enable outbreak filters.
- C. Enable email relay.
- D. Enable port bouncing.
- E. Enable antivirus scanning.
Answer: A,B
NEW QUESTION # 44
Which action is a valid fallback when a client certificate is unavailable during SMTP authentication on Cisco ESA?
- A. SMTP TLS
- B. LDAP Query
- C. LDAP BIND
- D. SMTP AUTH
Answer: D
NEW QUESTION # 45
What is the default behavior of any listener for TLS communication?
- A. preferred-verify
- B. preferred
- C. off
- D. required
Answer: C
NEW QUESTION # 46
An administrator identifies that, over the past week, the Cisco ESA is receiving many emails from certain senders and domains which are being consistently quarantined. The administrator wants to ensure that these senders and domain are unable to send anymore emails.
Which feature on Cisco ESA should be used to achieve this?
- A. safelist
- B. incoming mail policies
- C. S/MIME Sending Profile
- D. blocklist
Answer: B
NEW QUESTION # 47
Which feature must be configured before an administrator can use the outbreak filter for nonviral threats?
- A. antivirus
- B. data loss prevention
- C. antispam
- D. quarantine threat level
Answer: C
Explanation:
Explanation/Reference: https://www.cisco.com/c/en/us/td/docs/security/esa/esa12-0/user_guide/ b_ESA_Admin_Guide_12_0/b_ESA_Admin_Guide_chapter_01110.html
NEW QUESTION # 48
......
300-720 Exam Dumps - PDF Questions and Testing Engine: https://www.passtestking.com/Cisco/300-720-practice-exam-dumps.html
Realistic 300-720 Exam Dumps with Accurate & Updated Questions: https://drive.google.com/open?id=1L9Kt6Vv4IOykayJ_MFsE80LX-JjpHcsG