DOWNLOAD the newest Actual4Dumps 300-720 PDF dumps from Cloud Storage for free: https://drive.google.com/open?id=1TJOKLPv4ZC57pFex-olaVRW-D6XCEbUp
As the famous saying goes, time is life. Time is so important to everyone because we have to use our limited time to do many things. Especially for candidates to take the 300-720 exam, time is very precious. They must grasp every minute and every second to prepare for it. From the point of view of all the candidates, our 300-720 training quiz give full consideration to this problem. And we can claim that if you study our 300-720 study materials for 20 to 30 hours, you can pass the exam for sure.
| Certification Vendor: | Cisco |
|---|---|
| Exam Name: | Securing Email with Cisco Email Security Appliance |
| Exam Number: | 300-720 SESA |
| Exam Price: | USD 300 |
| Certificate Validity Period: | 3 years |
| Exam Format: | Simulation-based questions, Multiple answer, Multiple choice |
| Exam Duration: | 90 minutes |
| Related Certifications: | CCIE Security Cisco Certified Specialist - Email Content Security CCNP Security |
| Real Exam Qty: | 55-65 |
| Available Languages: | English |
| Recommended Training: | Cisco Email Security Appliance Training (Cisco Learning Network) Securing Email with Cisco ESA Official Training |
| Exam Registration: | Cisco Certification Exam Registration (Pearson VUE) Cisco Exam Overview Page |
| Sample Questions: | Cisco 300-720 Sample Questions |
| Exam Way: | Online proctored or test center (Pearson VUE) |
| Pre Condition: | No formal prerequisites required, but 1-3 years experience in email security or Cisco security technologies is recommended. |
| Official Syllabus URL: | https://www.cisco.com/c/en/us/training-events/training-certifications/exams/current-list/securing-email-with-cisco-email-security-appliance.html |
>> Practice 300-720 Exam Pdf <<
As we have three different versions of the 300-720 exam questions, so you can choose the most suitable version that you want to study with. If you are convenient, you can choose to study on the computer. If you live in an environment without a computer, you can read our 300-720 simulating exam on your mobile phone. Of course, the premise is that you have already downloaded the APP version of our 300-720 study materials. It is the right version for you to apply to all kinds of the eletronic devices.
| Section | Weight | Objectives |
|---|---|---|
| System Quarantines and Delivery Methods | 15% | - Configure quarantine (spam, policy, virus, and outbreak) - Utilize safelists and blocklists to control email delivery - Manage messages in local or external spam quarantines - Configure virtual gateways |
| Email Authentication and Encryption | 20% | - Configure Domain Keys and DKIM signing - Configure SPF and SIDF - Configure DMARC verification - Configure forged email detection - Configure email encryption - Describe S/MIME security services and communication encryption with other MTAs - Manage certificate authorities |
| Spam Control with Talos SenderBase and Antispam | 15% | - Control spam with Talos SenderBase and Antispam - Describe graymail management solution - Configure file reputation filtering and file analysis features - Implement malicious or undesirable URLs protection - Describe the bounce verification feature |
| LDAP and SMTP Sessions | 15% | - Configure and verify LDAP servers and queries (Queries and Directory Harvest Attack) - Understand spam quarantine functions
- Understand SMTP functionality
|
NEW QUESTION # 151
Which method enables an engineer to deliver a flagged message to a specific virtual gateway address in the most flexible way?
Answer: D
Explanation:
The altsrchost command enables an engineer to deliver a flagged message to a specific virtual gateway address in the most flexible way. This command allows you to specify an alternate source host for messages that match a message filter. You can use this command to route messages to different virtual gateways based on the message content or attributes.
References: Securing Email with Cisco Email Security Appliance (SESA) v3.1 , Module 5: Using Message Filters to Enforce Email Policies, Lesson 1: Using Mess age Filters Reference: https://www.cisco.com/c/en/us/td/docs/security/esa/esa11-1/user_guide/ b_ESA_Admin_Guide_11_1/b_ESA_Admin_Guide_chapter_01000.html#con_1133810
NEW QUESTION # 152
When email authentication is configured on Cisco ESA, which two key types should be selected on the signing profile? (Choose two.)
Answer: B,E
Explanation:
With DomainKeys or DKIM email authentication, the sender signs the email using public key cryptography.
Configuring DomainKeys and DKIM Signing A signing key is the private key stored on the appliance.
https://www.cisco.com/c/en/us/td/docs/security/esa/esa11-1/user_guide/b_ESA_Admin_Guide_11_1
/b_ESA_Admin_Guide_chapter_010101.html?bookSearch=true
NEW QUESTION # 153
An engineer wants to ensure that emails received by company users that contain URLs do not make them susceptible to data loss from accessing malicious or undesired external content sources. Which two features must be configured on Cisco Secure Email Gateway to meet this requirement? (Choose two.)
Answer: C,E
Explanation:
To meet the requirement of ensuring that emails received by company users that contain URLs do not make them susceptible to data loss from accessing malicious or undesired external content sources, the administrator must configure two features on Cisco Secure Email Gateway:
antispam scanning and URL filtering. Antispam scanning can block or quarantine messages that are identified as spam based on various criteria, such as sender reputation, message content, and message headers. URL filtering can rewrite or defang URLs in messages that are associated with malicious or undesirable websites, such as phishing, malware, adult, or gambling sites.
NEW QUESTION # 154
Which attack is mitigated by using Bounce Verification?
Answer: D
NEW QUESTION # 155
A network administrator notices that there are a high number of queries to the LDAP server. The mail logs show an entry "550 Too many invalid recipients | Connection closed by foreign host." Which feature must be used to address this?
Answer: B
Explanation:
Reference:
https://www.cisco.com/c/en/us/td/docs/security/esa/esa12-0/user_guide/b_ESA_Admin_Guide_12_0/b_ESA_Admin_Guide_12_0_chapter_011010.html DHAP (Directory Harvest Attack Prevention) is a feature that must be used to address this issue. DHAP is a mechanism that allows Cisco ESA to prevent directory harvest attacks, which are attempts by spammers or hackers to obtain valid email addresses from an LDAP server by sending messages with random or guessed recipients and checking for bounce messages.
To enable DHAP on Cisco ESA, the network administrator can follow these steps:
Select Network > Listeners and click Edit Settings for the listener that receives incoming messages.
Under SMTP Authentication Settings, select Enable Directory Harvest Attack Prevention.
Enter a value for Maximum Invalid Recipients per Hour, which is the number of invalid recipients that triggers DHAP.
Enter a value for Block Sender for (hours), which is the duration that Cisco ESA blocks messages from senders who exceed the maximum invalid recipients per hour.
Click Submit.
NEW QUESTION # 156
......
300-720 Reliable Exam Braindumps: https://www.actual4dumps.com/300-720-study-material.html
BONUS!!! Download part of Actual4Dumps 300-720 dumps for free: https://drive.google.com/open?id=1TJOKLPv4ZC57pFex-olaVRW-D6XCEbUp