300-720 Exam Details

  • Exam Code
    :300-720
  • Exam Name
    :Securing Email with Cisco Email Security Appliance (SESA)
  • Certification
    :CCNP Security
  • Vendor
    :Cisco
  • Total Questions
    :148 Q&As
  • Last Updated
    :Jan 06, 2026

Cisco 300-720 Online Questions & Answers

  • Question 1:

    A trusted partner of an organization recently experienced a new campaign that was leveraging JavaScript attachments to trick users into executing malware. As a result, they created a local policy to deny messages with JavaScript attachments. Which action should the administrator of the organization take to ensure encrypted communications are delivered to the intended partner recipient?

    A. Insert the X-PostX-Use-Script' header with a value of false to the encrypted messages
    B. Select JavaScript-free' option within the Cisco Secure Email Encryption Service Add-in
    C. Create an outgoing content filter and add the Encrypt and Deliver Nov/ action with Use-Script option deselected
    D. Create a new encryption profile and deselect the 'Use-Script' envelope settings option

  • Question 2:

    What is a benefit of deploying Cisco Secure Email and Web Manager?

    A. centralized management of software updates for Cisco Secure Email Gateway
    B. centralized management of logs for Cisco Secure Email Gateway
    C. centralized management of quarantined email
    D. centralized management of botnet directories

  • Question 3:

    A security administrator deployed a Cisco Secure Email Gateway appliance with a mail policy configured to store suspected spam for review. The appliance is the DMZ and only the standard HTTP/HTTPS ports are allowed by the firewall. An administrator wants to ensure that users can view any suspected spam that was blocked. Which action must be taken to meet this requirement?

    A. Enable the external Spam Quarantine and enter the IP address and port for the Secure Email and Web Manager
    B. Enable the Spam Quarantine and leave the default settings unchanged
    C. Enable End-User Quarantine Access and point to an LDAP server for authentication
    D. Enable the Spam Quarantine and specify port 80 for HTTP and port 443 for HTTPS

  • Question 4:

    A company has recently updated their security policy and now wants to drop all email messages larger than 100 MB coming from external sources. The Cisco Secure Email Gateway is LDAP integrated and all employee accounts are in the

    group "Employees".

    Which filter rule configuration provides the desired outcome?

    A. if (mail-from-group == 'Employees') and (body-size > "100M") {drop()}
    B. if (mail-from-group != 'Employees') and (body-size > 100M) {drop();}
    C. if (mail-from-group == 'Employees') and (body-size > 100M) {bounce();}
    D. if ('mail-from-group != Employees') and (body-size > 100M) {drop();}

  • Question 5:

    What are the two different phases in the process of Cisco Secure Email Gateway performing S/MIME encryption? (Choose two.)

    A. Attach the encrypted public key to the message
    B. Encrypt the message body using the session key
    C. Send the encrypted message to the sender
    D. Attach the encrypted symmetric key to the message
    E. Create a pseudo-random session key

  • Question 6:

    The CEO added a sender to a safelist but does not receive an important message expected from the trusted sender. An engineer evaluates message tracking on a Cisco ESA and determines that the message was dropped by the antivirus engine. What is the reason for this behavior?

    A. End-user safelists apply to antispam engines only.
    B. The sender didn't mark the message as urgent.
    C. Administrative access is required to create a safelist.
    D. The sender is included in an ISP blocklist.

  • Question 7:

    An organization has multiple Cisco ESA devices deployed, resulting in several spam quarantines to manage. To manage the quarantined messages, the administrator enabled the centralized spam quarantine on the Cisco SMA and configured the external spam quarantine on the Cisco ESA devices. However, messages are still being directed to the local quarantine on the Cisco ESA devices. What change is necessary to complete the configuration?

    A. Modify the incoming mail policies on the Cisco ESA devices to redirect to the external quarantine.
    B. Disable the external spam quarantine on the Cisco ESA devices.
    C. Disable the local spam quarantine on the Cisco ESA devices.
    D. Modify the external spam quarantine settings on the Cisco ESA devices and change the port to 25.

  • Question 8:

    Which restriction is in place for end users accessing the spam quarantine on Cisco ESA devices?

    A. The end user must be assigned to the Guest role.
    B. Access via a link in a notification in mandatory.
    C. Authentication is required when accessing via a link in a notification.
    D. Direct access via web browser requires authentication.

  • Question 9:

    The CEO sent an email indicating that all emails containing a string of 123ABCDEFGHJ cannot be delivered and must be sent into quarantine for further inspection. Given the requirement, which regular expression should be used to match on that criteria?

    A. \d{3}[A璟]{9}
    B. {3}\d{9}[A璟]
    C. \w{3}[A璟]{9}
    D. \\D{3}[A璟]{9}

  • Question 10:

    An organization wants to designate help desk personnel to assist with tickets that request the release of messages from the spam quarantine because company policy does not permit end-user quarantine access to employees directly. Which two roles must be used for these personnel to release messages while restricting access to make configuration changes in the Cisco ESA? (Choose two.)

    A. Administrator
    B. Read-Only Operator
    C. Technician
    D. Quarantine Administrator
    E. Help Desk User

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Cisco exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 300-720 exam preparations and Cisco certification application, do not hesitate to visit our Vcedump.com to find your solutions here.