Cisco 300-720 Certification Exam Sample Questions and Answers

CCNP Security Dumps, 300-720 Dumps, Cisco SESA PDF, 300-720 PDF, CCNP Security VCE, Cisco CCNP Security Questions PDF, Cisco Exam VCE, Cisco 300-720 VCE, CCNP Security Cheat SheetBefore you write the Cisco CCNP Security (300-720) certification exam, you may have certain doubts in your mind regarding the pattern of the test, the types of questions asked in it, the difficulty level of the questions and time required to complete the questions. These Cisco Certified Specialist Email Content Security (SESA) sample questions and demo exam help you in removing these doubts and prepare you to take the test.

The best approach to pass your Cisco 300-720 exam is to challenge and improve your knowledge. To test your learning and identify improvement areas with actual exam format, we suggest you practice with Premium Cisco 300-720 Certification Practice Exam. The practice test is one of the most important elements of your Securing Email with Cisco Email Security Appliance (SESA) exam study strategy to discover your strengths and weaknesses, to improve your time management skills and to get an idea of the score you can expect.

Cisco 300-720 (SESA) Sample Questions:

01. Outbound messages currently leave carrying internal host-based sender addresses. The organization wants the envelope and header From addresses rewritten to a uniform public-domain form derived from directory data.
Which LDAP query type performs this rewriting?
a) Masquerade
b) Accept
c) Routing
d) SMTP Authentication
 
02. A gateway is receiving a flood of non-delivery bounce reports for messages the organization never actually sent, a pattern known as backscatter.
Which feature lets the appliance tell a legitimate bounce from this forged one?
a) A bounce profile generating undeliverable notices
b) Destination controls throttling delivery per domain
c) Bounce verification tagging outbound envelope addresses with a key
d) SPF verification checking the bounce sender IP
 
03. During a review of an email-authentication deployment, several claims are made about how the three mechanisms behave.
Which statements are accurate?
(Choose three.)
a) SPF publishes a public signing key in DNS
b) DMARC needs SPF or DKIM to align
c) SPF authorizes the sending IP for a domain
d) DMARC encrypts the message body or attachments for recipients
e) DKIM signs outbound mail and verifies inbound
 
04. A healthcare partner requires that outbound messages containing regulated data reach recipients as a secure envelope they open and authenticate to, regardless of the recipient's mail server.
How is the Cisco Secure Email Encryption Service invoked to do this?
a) An inbound S/MIME verification profile enabled on message receipt
b) A mandatory TLS profile applied on the public listener
c) A DKIM signing profile applied during outbound message processing
d) A content filter or DLP filter action that triggers the envelope encryption
 
05. Marketing sends campaigns through a third-party platform. The platform's mail passes SPF on the platform's own domain, yet the receiving appliance reports a DMARC failure for the campaigns.
What most likely explains the failure?
a) The DMARC policy was published as quarantine rather than none
b) The SPF domain does not align with the From domain
c) The receiving appliance had disabled SPF checking for that domain
d) The sending platform presented a poor SBRS reputation score
 
06. Roaming employees submit outbound mail through the gateway from untrusted networks and must prove their identity with directory credentials before the gateway will relay for them.
Which LDAP query type authenticates these submitting clients?
a) External Authentication
b) Group
c) Accept
d) SMTP Authentication
 
07. An administrator is deciding whether to centralize the PVO quarantines from several gateways onto a Secure Email and Web Manager instead of keeping them local.
Which outcomes are genuine reasons to centralize?
(Choose two.)
a) Quarantined mail is rescanned by a second antivirus engine
b) Retention limits are no longer required on any quarantine
c) Every held message is automatically encrypted on arrival
d) A single console manages held messages from every gateway
e) Held messages are consolidated independently of any one gateway
 
08. One appliance, bound to a single directory, must serve three sign-in needs: administrators opening the management UI, submission clients relaying outbound mail, and end users viewing the spam quarantine.
Which LDAP query type authenticates the administrators' management-UI logins specifically?
a) Spam-quarantine end-user authentication
b) External Authentication
c) SMTP Authentication
d) Group
 
09. The security team wants administrators to sign in to the gateway's management interface using their existing directory accounts instead of local appliance accounts.
Which LDAP query type authenticates those administrator logins?
a) Group
b) Accept
c) External Authentication
d) SMTP Authentication
 
10. Finance staff at Brightpath Logistics report emails whose display name reads as the CFO, but each arrives from an external look-alike domain and passes its own authentication.
Which mechanism is designed to catch this pattern?
a) SPF verification of the sending domain envelope IP address
b) Forged Email Detection matching a dictionary of protected executive display names
c) DKIM verification of the look-alike sending domain message signature
d) A DMARC reject policy published for the sending domain

Solutions:

Question: 01

Answer: a

Question: 02

Answer: c

Question: 03

Answer: b, c, e

Question: 04

Answer: d

Question: 05

Answer: b

Question: 06

Answer: d

Question: 07

Answer: d, e

Question: 08

Answer: b

Question: 09

Answer: c

Question: 10

Answer: b

Note: If you find any error in these Securing Email with Cisco Email Security Appliance (SESA) sample questions, you can update us by write an email on feedback@nwexam.com.

Rating: 5 / 5 (70 votes)