300-720 Securing Email with Cisco Secure Email Gateway (SESA) Practice Questions
Prepare for 300-720 with more than an answer.
- Exam fee
- $300 USD
- Level
- Professional
- Valid for
- 3 years
Domains covered on the exam 6
- Cisco Email Security Appliance Administration15%
- Spam Control with Talos SenderBase and Antispam15%
- Content and Message Filters20%
- LDAP and SMTP Sessions15%
- Email Authentication and Encryption20%
- System Quarantines and Delivery Methods15%
- 1
Case Study: TechAdvantage Inc.
TechAdvantage Inc. is migrating their email infrastructure. They require that end-users be able to manage their own spam quarantines. The users are authenticated via an external LDAP server. The security policy mandates that users must log in using their primary email address, but they should also see quarantined messages sent to their alias addresses (e.g., [email protected] should see mail for [email protected]).
However, currently, users only see messages sent to the specific address they use to log in. The administrator has verified that the LDAP 'accept' query is working correctly for mail delivery.
Which specific LDAP query type must be configured and associated with the Spam Quarantine to resolve this visibility issue?
Show answer details
Correct answer: B
The LDAP Alias Consolidation query is specifically designed to map multiple email aliases to a single unique user attribute (usually the primary email or UID). When enabled on the Spam Quarantine, it allows the system to aggregate all quarantined messages for all aliases belonging to a user and display them in a single view upon login.
- 2
When configuring SMTP Authentication (SMTP AUTH) on a Cisco ESA listener to allow remote users to send mail, which LDAP query type is required to verify the user's credentials against the directory service?
Show answer details
Correct answer: A
The 'SmtpAuthentication' query (often just labeled as Authentication query in newer GUIs but distinct from ISQ/EUQ auth) is used during the SMTP session to validate the username and password provided by the client against the LDAP server.
- 3
An administrator is configuring a Safe/Block list on the Cisco ESA. They notice that a sender blocked in the Global Blocklist is still successfully delivering mail to a specific user who has whitelisted that sender in their personal Safelist. What is the default precedence order for Safelist/Blocklist evaluation that explains this behavior?
Show answer details
Correct answer: A
By default, the User Safelist has the highest precedence to ensure that end-users can receive business-critical mail even if it is caught by broader filters. Therefore, a User Safelist entry overrides the Global Blocklist.
- 4
A university has two distinct email domains:
student.uni.eduandstaff.uni.edu. They require that all outbound email from thestudent.uni.edudomain be sent from a specific IP interface (192.0.2.50) to isolate its reputation from the staff domain. Which feature on the Cisco ESA should be configured to achieve this source-based routing?Show answer details
Correct answer: A
Virtual Gateways allow the ESA to group IP addresses and hostnames for delivery. By creating a Virtual Gateway assigned to 192.0.2.50 and mapping the
student.uni.edudomain to it using thealtsrchostcommand or GUI settings, the administrator can force outbound mail for that domain to exit via that specific interface. - 5
Which TWO statements accurately describe the behavior of the Policy, Virus, and Outbreak Quarantine compared to the Spam Quarantine? (Select TWO)
Show answer details
Correct answer: A, B
The Policy, Virus, and Outbreak Quarantine (PVO) is designed for administrators to review policy violations, potential viruses, and outbreak threats. End-users typically do not have access to this quarantine.
Both the Spam Quarantine and the PVO Quarantine can be centralized on a Cisco Security Management Appliance (SMA) for unified management across multiple ESAs.
- 6
Case Study: SecureFlow Logistics
SecureFlow Logistics manages a high-volume email environment with a cluster of four Cisco ESAs. They are experiencing an issue where valid automated shipment notifications sent from their internal ERP system (10.10.20.5) are being delayed. The mail logs show that these messages are often queued in the 'Delivery' queue with the status 'Connection refused by destination'.
The destination is an external partner's mail server. SecureFlow's administrator suspects that the partner is rate-limiting the connection because all four ESAs are sending mail simultaneously using the same public NAT IP.
To resolve this without changing the public IP, the administrator decides to limit the concurrency of connections to this specific partner domain.
Which configuration location is appropriate for setting a limit on concurrent connections to a specific destination domain?
Show answer details
Correct answer: A
Destination Controls allow administrators to define specific delivery parameters for individual domains, including the maximum number of concurrent connections, messages per connection, and TLS requirements. This is the correct place to throttle connections to a specific partner.
- 7
Which SMTP extension does Cisco ESA support for email security?
Show answer details
Correct answer: D
- 8
Which feature utilizes sensor information obtained from Talos intelligence to filter email servers connecting into the Cisco ESA?
Show answer details
Correct answer: A
