Pre-Summer Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = simple70

Pass the Cisco CCNP Security 300-720 Questions and answers with Dumpstech

Exam 300-720 Premium Access

View all detail and faqs for the 300-720 exam

Practice at least 50% of the questions to maximize your chances of passing.
Viewing page 1 out of 6 pages
Viewing questions 1-10 out of questions
Questions # 1:

An engineer must add cisco.com to the listed domains in Cisco Secure Email Gateway that accept messages. All other domains must be blocked, and the message must be sent back to the sender is Domain Blocked. Which two actions must be taken to meet the requirement? (Choose two.)

Options:

A.

From the IP Reputation Filtering settings, accept Cisco com and reject all other URLs

B.

From the Sender Domain Reputation Filtering settings, accept Cisco com and reject all other URLs.

C.

Configure Domain blocked as a custom threat response.

D.

Accept Cisco com and reject all other URLs in the Recipient Access Table.

E.

Configure Domain blocked as a custom SMTP response

Questions # 2:

Which two features of Cisco Email Security are added to a Sender Group to protect an organization against email threats? (Choose two.)

Options:

A.

NetFlow

B.

geolocation-based filtering

C.

heuristic-based filtering

D.

senderbase reputation filtering

E.

content disarm and reconstruction

Questions # 3:

Which two are configured in the DMARC verification profile? (Choose two.)

Options:

A.

name of the verification profile

B.

minimum number of signatures to verify

C.

ESA listeners to use the verification profile

D.

message action into an incoming or outgoing content filter

E.

message action to take when the policy is reject/quarantine

Questions # 4:

Which two components must be configured to perform DLP scanning? (Choose two.)

Options:

A.

Add a DLP policy on the Incoming Mail Policy.

B.

Add a DLP policy to the DLP Policy Manager.

C.

Enable a DLP policy on the Outgoing Mail Policy.

D.

Enable a DLP policy on the DLP Policy Customizations.

E.

Add a DLP policy to the Outgoing Content Filter.

Questions # 5:

Which two action types are performed by Cisco ESA message filters? (Choose two.)

Options:

A.

non-final actions

B.

filter actions

C.

discard actions

D.

final actions

E.

quarantine actions

Questions # 6:

Which feature must be activated on a Cisco Secure Email Gateway to combat backscatter?

Options:

A.

Graymail Detection

B.

Bounce Verification

C.

Forged Email Detection

D.

Bounce Profile

Questions # 7:

Which type of DNS record would contain the following line, which references the DKIM public key per RFC 6376?

v=DKIM1; p=76E629F05F709EF665853333EEC3F5ADE69A2362BECE406582670456943283BE

Options:

A.

CNAME

B.

AAAA

C.

TXT

D.

PTR

Questions # 8:

What is needed to sign outbound emails using Domain Keys Identified Mail after a signing profile is created in the Cisco Secure Email Gateway?

Options:

A.

Configure in destination controls.

B.

Enable DKIM in an outbound content filter.

C.

Enable DKIM in the mail flow policy.

D.

A signing profile referencing the sender domain is sufficient.

Questions # 9:

Which method enables an engineer to deliver a flagged messag e to a specific virtual gateway address in the most flexible way?

Options:

A.

Set up the interface group with the flag.

B.

Issue the altsrchost command.

C.

Map the envelope sender address to the host.

D.

Apply a filter on the message.

Questions # 10:

Drag and drop the AsyncOS methods for performing DMARC verification from the left into the correct order on the right.

Question # 10

Options:

Viewing page 1 out of 6 pages
Viewing questions 1-10 out of questions