Which benefit does enabling external spam quarantine on Cisco SMA provide?
A. ability to back up spam quarantine from multiple Cisco ESAs to one central console
B. access to the spam quarantine interface on which a user can release, duplicate, or delete
C. ability to scan messages by using two engines to increase a catch rate
D. ability to consolidate spam quarantine data from multiple Cisco ESA to one central console
An analyst creates a new content dictionary to use with Forged Email Detection. Which entry will be added into the dictionary?
A. mycompany.com
B. Alpha Beta
C. ^Alpha\ Beta$
Which two features of Cisco Email Security are added to a Sender Group to protect an organization against email threats? (Choose two.)
A. NetFlow
B. geolocation-based filtering
C. heuristic-based filtering
D. senderbase reputation filtering
E. content disarm and reconstruction
Which two certificate authority lists are available in Cisco ESA? (Choose two.)
A. default
B. system
C. user
D. custom
E. demo
When the Cisco ESA is configured to perform antivirus scanning, what is the default timeout value?
A. 30 seconds
B. 90 seconds
C. 60 seconds
D. 120 seconds
Which scenario prevents a message from being sent to the quarantine as an action in the scan behavior on Cisco ESA?
A. A policy quarantine is missing.
B. More than one email pipeline is defined.
C. The "modify the message subject" is already set.
D. The "add custom header" action is performed first.
A network administrator notices that there are a high number of queries to the LDAP server. The mail logs show an entry "550 Too many invalid recipients | Connection closed by foreign host." Which feature must be used to address this?
A. DHAP
B. SBRS
C. LDAP
D. SMTP
Which feature must be activated on a Cisco ESA to combat backscatter?
A. Graymail Detection
B. Bounce Profile
C. Forged Email Detection
D. Bounce Verification
A Cisco ESA administrator recently enabled the Outbreak Filters Global Service Setting to detect Viral as well as Non-Viral threat detection, with no detection of Non-Viral threats after 24 hours of monitoring Outbreak Filters. What is the reason that Non-Viral threat detection is not detecting any positive verdicts?
A. The Outbreak Filters option Graymail Header must be enabled.
B. The Outbreak Filters option URL Rewriting must be enabled.
C. Non-Viral threat detection requires AntiSpam or Intelligent Multi-Scan enablement to properly function.
D. Non-Viral threat detection requires AntiVirus or AMP enablement to properly function.
A network administrator has enabled virus scanning with the Sophos antivirus engine and set the "drop infected mail" option on a Cisco ESA; however, end users are still complaining about the large number of phishing emails they receive. What must be done to resolve this problem?
A. Configure Reputation Filtering
B. Configure Content Filtering
C. Configure Outbreak Filtering
D. Change the antivirus engine to McAfee.
An engineer is tasked with creating a content filter to catch attachments, including credit card numbers, and hold them for review until further action is taken. Which component on a Cisco ESA must be configured to meet this requirement?
A. Spam Quarantine
B. Outbreak Filter
C. Policy Quarantine
D. Content Filter
An administrator notices that incoming emails with certain attachments do not get delivered to all recipients when the emails have multiple recipients in different domains like cisco.com and test.com. The same emails when sent only to recipients in cisco.com are delivered properly. How must the Cisco ESA be configured to avoid this behavior?
A. Modify DLP configuration to ensure that all attachments are permitted for test.com.
B. Modify DLP configuration to exempt DLP scanning for messages sent to test.com domain.
C. Modify mail policies so email recipients do not match multiple policies.
D. Modify mail policies for cisco.com to ensure that emails are not dropped.
The CEO added a sender to a safelist but does not receive an important message expected from the trusted sender. An engineer evaluates message tracking on a Cisco ESA and determines that the message was dropped by the antivirus engine. What is the reason for this behavior?
A. End-user safelists apply to antispam engines only.
B. The sender didn't mark the message as urgent.
C. Administrative access is required to create a safelist.
D. The sender is included in an ISP blocklist.
What are the two different phases in the process of Cisco Secure Email Gateway performing S/MIME encryption? (Choose two.)
A. Attach the encrypted public key to the message
B. Encrypt the message body using the session key
C. Send the encrypted message to the sender
D. Attach the encrypted symmetric key to the message
E. Create a pseudo-random session key
What is a benefit of deploying Cisco Secure Email and Web Manager?
A. centralized management of software updates for Cisco Secure Email Gateway
B. centralized management of logs for Cisco Secure Email Gateway
C. centralized management of quarantined email
D. centralized management of botnet directories