300-720 Exam Details

  • Exam Code
    :300-720
  • Exam Name
    :Securing Email with Cisco Email Security Appliance (SESA)
  • Certification
    :CCNP Security
  • Vendor
    :Cisco
  • Total Questions
    :248 Q&As
  • Last Updated
    :Jul 11, 2026

Cisco 300-720 Online Questions & Answers

  • Question 71:

    An engineer is tasked with reviewing mail logs to confirm that messages sent from domain abc.com are passing SPF verification and being accepted by the Cisco ESA. The engineer notices that SPF verification is not being performed and that SPF is not being referenced in the logs for messages sent from domain abc.com.

    Why is the verification not working properly?

    A. SPF verification is disabled in the Recipient Access Table.
    B. SPF verification is disabled on the Mail Flow Policy.
    C. The SPF conformance level is set to SIDF compatible on the Mail Flow Policy.
    D. An SPF verification Content Filter has not been created.

  • Question 72:

    DRAG DROP

    Drag and drop authentication options for End-User Quarantine Access from the left onto the corresponding configuration steps on the right.

    Select and Place:

  • Question 73:

    A Cisco ESA administrator has several mail policies configured. While testing policy match using a specific sender, the email was not matching the expected policy.

    What is the reason of this?

    A. The "From" header is checked against all policies in a top-down fashion.
    B. The message header with the highest priority is checked against each policy in a top-down fashion.
    C. The "To" header is checked against all policies in a top-down fashion.
    D. The message header with the highest priority is checked against the Default policy in a top-down fashion.

  • Question 74:

    An organization wants to designate help desk personnel to assist with tickets that request the release of messages from the spam quarantine because company policy does not permit end-user quarantine access to employees directly. Which two roles must be used for these personnel to release messages while restricting access to make configuration changes in the Cisco ESA? (Choose two.)

    A. Administrator
    B. Read-Only Operator
    C. Technician
    D. Quarantine Administrator
    E. Help Desk User

  • Question 75:

    What are organizations trying to address when implementing a SPAM quarantine?

    A. true positives
    B. false negatives
    C. false positives
    D. true negatives

  • Question 76:

    A Cisco ESA administrator must provide outbound email authenticity and configures a DKIM signing profile to handle this task. What is the next step to allow this organization to use DKIM for their outbound email?

    A. Configure the Trusted Sender Group message authenticity policy.
    B. Export the DNS TXT record to provide to the DNS registrar.
    C. Import the DNS record of the service provider into the Cisco ESA.
    D. Enable the DKIM service checker.

  • Question 77:

    Which two are configured in the DMARC verification profile? (Choose two.)

    A. name of the verification profile
    B. minimum number of signatures to verify
    C. ESA listeners to use the verification profile
    D. message action into an incoming or outgoing content filter
    E. message action to take when the policy is reject/quarantine

  • Question 78:

    An engineer wants to ensure that emails received by company users that contain URLs do not make them susceptible to data loss from accessing malicious or undesired external content sources.

    Which two features must be configured on Cisco Secure Email Gateway to meet this requirement? (Choose two.)

    A. antivirus scanning
    B. URL filtering
    C. graymail detection
    D. data loss prevention
    E. antispam scanning

  • Question 79:

    Which benefit does enabling external spam quarantine on Cisco SMA provide?

    A. ability to back up spam quarantine from multiple Cisco ESAs to one central console
    B. access to the spam quarantine interface on which a user can release, duplicate, or delete
    C. ability to scan messages by using two engines to increase a catch rate
    D. ability to consolidate spam quarantine data from multiple Cisco ESA to one central console

  • Question 80:

    The CEO added a sender to a safelist but does not receive an important message expected from the trusted sender. An engineer evaluates message tracking on a Cisco ESA and determines that the message was dropped by the antivirus engine. What is the reason for this behavior?

    A. End-user safelists apply to antispam engines only.
    B. The sender didn't mark the message as urgent.
    C. Administrative access is required to create a safelist.
    D. The sender is included in an ISP blocklist.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Cisco exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 300-720 exam preparations and Cisco certification application, do not hesitate to visit our Vcedump.com to find your solutions here.