[Dec 20, 2021] Free CCNP Security 300-720 Official Cert Guide PDF Download
Cisco 300-720 Official Cert Guide PDF
Target Audience
The Cisco 300-720 is designed for people who work around Email security and other networking domains. Some of the specialists who are targeted by this test include security engineers, network administrators, network architects, network engineers, and more.
NEW QUESTION 47
What is the default port to deliver emails from the Cisco ESA to the Cisco SMA using the centralized Spam Quarantine?
- A. 0
- B. 1
- C. 2
- D. 3
Answer: A
Explanation:
Reference:
https://www.cisco.com/c/en/us/support/docs/security/email-security-appliance/118692-configure- esa-00.html
NEW QUESTION 48
Which action on the Cisco ESA provides direct access to view the safelist/blocklist?
- A. Debug the mail flow policy.
- B. Monitor Incoming/Outgoing Listener.
- C. Export the SLBL to a .csv file.
- D. Show the SLBL cache on the CLI.
Answer: C
Explanation:
Explanation/Reference: https://www.cisco.com/c/en/us/support/docs/security/email-security-appliance/117922-technote- esa-00.html
NEW QUESTION 49
When the Cisco ESA is configured to perform antivirus scanning, what is the default timeout value?
- A. 30 seconds
- B. 60 seconds
- C. 90 seconds
- D. 120 seconds
Answer: B
Explanation:
Reference:
https://www.cisco.com/c/en/us/td/docs/security/esa/esa12-0/user_guide/ b_ESA_Admin_Guide_12_0/b_ESA_Admin_Guide_chapter_01011.html
NEW QUESTION 50
What is a valid content filter action?
- A. skip antispam
- B. quarantine
- C. decrypt on delivery
- D. archive
Answer: B
Explanation:
Reference:
https://www.cisco.com/c/en/us/td/docs/security/esa/esa12-0/user_guide/ b_ESA_Admin_Guide_12_0/b_ESA_Admin_Guide_chapter_01010.html#con_1158022
NEW QUESTION 51
When DKIM signing is configured, which DNS record must be updated to load the DKIM public signing key?
- A. AAAA record
- B. MX record
- C. PTR record
- D. TXT record
Answer: D
NEW QUESTION 52
A Cisco ESA administrator was notified that a user was not receiving emails from a specific domain. After reviewing the mail logs, the sender had a negative sender-based reputation score.
What should the administrator do to allow inbound email from that specific domain?
- A. Modify the firewall to allow emails from the domain.
- B. Add the domain into the allow list.
- C. Ask the user to add the sender to the email application's allow list.
- D. Create a new inbound mail policy with a message filter that overrides Talos.
Answer: B
NEW QUESTION 53
What is the default HTTPS port when configuring spam quarantine on Cisco ESA?
- A. 0
- B. 1
- C. 2
- D. 3
Answer: C
NEW QUESTION 54 
Refer to the exhibit. How should this configuration be modified to stop delivering Zero Day malware attacks?
- A. Apply Prepend on Modify Message Subject under Malware Attachments.
- B. Change Unscannable Action from Deliver As Is to Quarantine.
- C. Configure mailbox auto-remediation.
- D. Change File Analysis Pending action from Deliver As Is to Quarantine.
Answer: C
NEW QUESTION 55
Which two statements about configuring message filters within the Cisco ESA are true? (Choose two.)
- A. The filterconfig command executed from the CLI is used to configure message filters.
- B. Message filters configuration within the web user interface is located within Incoming Content Filters.
- C. Message filters can be configured only from the web user interface.
- D. Message filters can be configured only from the CLI.
- E. The filters command executed from the CLI is used to configure the message filters.
Answer: D,E
Explanation:
Explanation/Reference:
Reference: https://www.cisco.com/c/en/us/support/docs/security/email-security-appliance/213940-esa- using-a-message-filter-to-take-act.html
NEW QUESTION 56
When outbreak filters are configured, which two actions are used to protect users from outbreaks? (Choose two.)
- A. drop
- B. abandon
- C. redirect
- D. delay
- E. return
Answer: C,D
NEW QUESTION 57
Which action is a valid fallback when a client certificate is unavailable during SMTP authentication on Cisco ESA?
- A. SMTP TLS
- B. LDAP BIND
- C. SMTP AUTH
- D. LDAP Query
Answer: C
Explanation:
Reference:
https://www.cisco.com/c/en/us/td/docs/security/esa/esa12-0/user_guide/ b_ESA_Admin_Guide_12_0/b_ESA_Admin_Guide_12_0_chapter_011011.html
NEW QUESTION 58
Which two factors must be considered when message filter processing is configured? (Choose two.)
- A. mail policies
- B. lateral processing
- C. MIME structure of the message
- D. message-filter order
- E. structure of the combined packet
Answer: C,D
Explanation:
Reference:
https://www.cisco.com/c/en/us/td/docs/security/esa/esa12-0/user_guide/ b_ESA_Admin_Guide_12_0/b_ESA_Admin_Guide_chapter_01000.html
NEW QUESTION 59
An analyst creates a new content dictionary to use with Forged Email Detection.
Which entry will be added into the dictionary?
- A. ^Alpha\ Beta$
- B. [email protected]
- C. Alpha Beta
- D. mycompany.com
Answer: D
Explanation:
Reference:
https://www.cisco.com/c/en/us/products/collateral/security/email-security-appliance/ whitepaper_C11-737596.html
NEW QUESTION 60
An analyst creates a new content dictionary to use with Forged Email Detection.
Which entry will be added into the dictionary?
- A. ^Alpha\ Beta$
- B. [email protected]
- C. Alpha Beta
- D. mycompany.com
Answer: D
NEW QUESTION 61
Which action is a valid fallback when a client certificate is unavailable during SMTP authentication on Cisco ESA?
- A. SMTP TLS
- B. LDAP BIND
- C. SMTP AUTH
- D. LDAP Query
Answer: C
Explanation:
Explanation/Reference: https://www.cisco.com/c/en/us/td/docs/security/esa/esa12-0/user_guide/ b_ESA_Admin_Guide_12_0/b_ESA_Admin_Guide_12_0_chapter_011011.html
NEW QUESTION 62
When DKIM signing is configured, which DNS record must be updated to load the DKIM public signing key?
- A. AAAA record
- B. MX record
- C. PTR record
- D. TXT record
Answer: D
Explanation:
Reference:
https://www.cisco.com/c/en/us/support/docs/security/email-security-appliance/213939-esa- configure-dkim-signing.html
NEW QUESTION 63
Which suboption must be selected when LDAP is configured for Spam Quarantine End-User Authentication?
- A. Entity ID
- B. Update Frequency
- C. Designate as the active query
- D. Server Priority
Answer: C
NEW QUESTION 64
How does the graymail safe unsubscribe feature function?
- A. It checks the URI reputation and category and allows the content filter to take an action on it.
- B. It redirects the end user who clicks the unsubscribe button to a sandbox environment to allow a safe unsubscribe.
- C. It checks the reputation of the URI and performs the unsubscribe process on behalf of the end user.
- D. It strips the malicious content of the URI before unsubscribing.
Answer: C
Explanation:
Explanation/Reference: https://www.cisco.com/c/en/us/support/docs/security/email-security-appliance/200383- Graymail-Detection-and-Safe-Unsubscribin.html
NEW QUESTION 65
Which action on the Cisco ESA provides direct access to view the safelist/blocklist?
- A. Debug the mail flow policy.
- B. Monitor Incoming/Outgoing Listener.
- C. Export the SLBL to a .csv file.
- D. Show the SLBL cache on the CLI.
Answer: C
NEW QUESTION 66
......
Which Subjects are on the Cisco 300-720 Exam
Candidates must know the exam topics before they start preparation. Because it will really help them in hitting the core. Our Cisco 300-720 dumps will include the following topics:
- Email Authentication and Encryption 20%
- LDAP and SMTP Sessions 15%
- System Quarantines and Delivery Methods 15%
- Cisco Email Security Appliance Administration 15%
- Content and Message filters 20%
- Spam Control with Talos SenderBase and Antispam 15%
Free 300-720 Exam Dumps to Improve Exam Score: https://www.passexamdumps.com/300-720-valid-exam-dumps.html
Exam 300-720: New Brain Dump Professional - PassExamDumps: https://drive.google.com/open?id=1iJyKo9X5UmXAwbAuimPysrpj7dk3pQoo
