Exam Details

  • Exam Code
    :300-720
  • Exam Name
    :Securing Email with Cisco Email Security Appliance (SESA)
  • Certification
    :CCNP Security
  • Vendor
    :Cisco
  • Total Questions
    :148 Q&As
  • Last Updated
    :Mar 26, 2025

Cisco CCNP Security 300-720 Questions & Answers

  • Question 11:

    A Cisco ESA is configured such that emails with a reputation score above -6 are logged and those with a score below -6 are logged, encrypted, and then delivered. An email body contains a shortened URL that exceeds the nested shortened URLs limit. Which action is taken against the email?

    A. It is encrypted but not logged.

    B. It is logged but not encrypted.

    C. It is logged and dropped.

    D. It is logged and encrypted.

  • Question 12:

    A remote financial institution is implementing email encryption. It is required that all inbound emails use SMTP over TLS. What must be done to accomplish this?

    A. Disable TLS certificates.

    B. Utilize Cisco Registered Envelope Service.

    C. Leverage Cisco Talos Threat Intelligence Group.

    D. Enable Application Inspection and Control for SMTP.

  • Question 13:

    What is the default primary email attribute used in a spam quarantine end-user authentication query when using LDAP authentication to an Active Directory server?

    A. userAccount

    B. mailLocalAddress

    C. sAMAccountName

    D. proxyAddresses

  • Question 14:

    Which components are required when encrypting SMTP with TLS on Cisco ESA when the sender requires TLS verification?

    A. self-signed certificate in PKCS#7 format

    B. X.509 certificate and matching private key from a CA

    C. self-signed certificate in PKCS#12 format

    D. DER certificate and matching public key from a CA

  • Question 15:

    The Cisco ESA is processing many messages that are sent to invalid recipients. To reduce this excessive processing, an engineer is preparing to use LDAP for recipient verification. Which two steps are required to accomplish this task? (Choose two.)

    A. Configure LDAP server profiles.

    B. Enable external LDAP authentication.

    C. Configure the LDAP query.

    D. Enable LDAP authentication on a listener.

    E. Configure incoming mail policy to query LDAP server.

  • Question 16:

    An engineer is reviewing the SMTP routing table on a Cisco ESA using the smtproutes CLI command and discovers an IPv6 route for 2620:104:4360:9232::23. What type of IPv6 route does this represent?

    A. Network route

    B. Subnet route

    C. Device route

    D. Prefix route

  • Question 17:

    An engineer must limit responses from the gateway that are directed to invalid email addresses. How should the LDAP server be configured to accomplish this goal?

    A. Validate the sender email address via an LDAP query during the SMTP conversation.

    B. Validate the sender email address via SMTP Call-Ahead to query an external SMTP server.

    C. Limit the number of invalid recipients per sender to stop responses after crossing the threshold.

    D. Limit the number of invalid responses per recipient to stop responses after crossing the threshold.

  • Question 18:

    A Cisco ESA administrator must provide outbound email authenticity and configures a DKIM signing profile to handle this task. What is the next step to allow this organization to use DKIM for their outbound email?

    A. Configure the Trusted Sender Group message authenticity policy.

    B. Export the DNS TXT record to provide to the DNS registrar.

    C. Import the DNS record of the service provider into the Cisco ESA.

    D. Enable the DKIM service checker.

  • Question 19:

    A network engineer is implementing a virus outbreak filter on a Cisco ESA by using the Outbreak Filters feature with plans to perform an additional scan by using a content filter. Which action must be taken by the Outbreak Filters?

    A. Scan processed messages by using two engines simultaneously.

    B. Send a copy of messages to quarantine.

    C. Send processed messages to the Cisco ESA.

    D. Scan processed messages by using a secondary instance of the Cisco ESA.

  • Question 20:

    An organization wants to prevent proprietary patent documents from being shared externally via email. The network administrator reviewed the DLP policies on the Cisco ESA and could not find an existing policy with the appropriate matching patterns. Which type of DLP policy template must be used to create a policy that meets this requirement?

    A. regulatory compliance

    B. acceptable use

    C. custom policy

    D. privacy protection

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Cisco exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 300-720 exam preparations and Cisco certification application, do not hesitate to visit our Vcedump.com to find your solutions here.