The Cisco 300-720 exam, also known as the Securing Email with Cisco Email Security Appliance (SESA) exam, is a certification exam that tests your knowledge and skills in securing email communication with the use of the Cisco Email Security Appliance.

The exam consists of 60-70 questions and lasts for 90 minutes.
The questions are presented in various formats, including multiple-choice, drag-and-drop, and simulation questions. The exam is available in English and Japanese.

The topics covered in the exam include:

1. Secure Email Gateway Architecture and Features

2. Cisco Email Security Appliance Installation and Configuration

3. Message Filtering

4. Email Encryption

5. System Administration and Troubleshooting

The exam can be taken at any Pearson VUE testing center, and the cost of the exam is $300 USD.
To prepare for the exam, Cisco offers a range of resources, including self-paced e-learning courses, instructor-led training courses, and study groups.

Question 1:

Which suboption must be selected when LDAP is configured for Spam Quarantine End-User Authentication?

A. Designate as the active query

B. Update Frequency

C. Server Priority

D. Entity ID

Reference: https://www.cisco.com/c/en/us/td/docs/security/security_management/sma/sma11-5/user_guide/b_SMA_Admin_Guide_11_5/b_SMA_Admin_Guide_11_5_chapter_01010.html

Question 2:

What are the two phases of the Cisco ESA email pipeline? (Choose two.)

A. reject

B. work queue

C. action

D. delivery

E. quarantine

Reference: https://www.cisco.com/c/en/us/td/docs/security/esa/esa12-1/user_guide/b_ESA_Admin_Guide_12_1/b_ESA_Admin_Guide_12_1_chapter_011.pdf (p.1)

Question 3:

A Cisco ESA administrator has several mail policies configured. While testing policy matches using a specific sender, the email was not matching the expected policy. What is the reason for this?

A. The “From” header is checked against all policies in a top-down fashion.

B. The message header with the highest priority is checked against each policy in a top-down fashion.

C. The “To” header is checked against all policies in a top-down fashion.

D. The message header with the highest priority is checked against the Default policy in a top-down fashion.

Question 4:

Which action must be taken before a custom quarantine that is being used can be deleted?

A. Delete the quarantine that is assigned to a filter.

B. Delete the quarantine that is not assigned to a filter.

C. Delete only the unused quarantine.

D. Remove the quarantine from the message action of a filter.

Reference: https://www.cisco.com/c/en/us/td/docs/security/esa/esa12-0/user_guide/b_ESA_Admin_Guide_12_0/b_ESA_Admin_Guide_12_0_chapter_011111.html

Question 5:

Which global setting is configured under Cisco ESA Scan Behavior?

A. minimum attachment size to scan

B. attachment scanning timeout

C. actions for unscannable messages due to attachment type

D. minimum depth of attachment recursion to scan

Reference: https://community.cisco.com/t5/email-security/cisco-ironport-esa-security-services-scan-behavior-impact-on-av/td-p/3923243

Question 6:

Which two are configured in the DMARC verification profile? (Choose two.)

A. the name of the verification profile

B. the minimum number of signatures to verify

C. ESA listeners to use the verification profile

D. message action into an incoming or outgoing content filter

E. message action to take when the policy is reject/quarantine

Reference: https://www.cisco.com/c/en/us/td/docs/security/esa/esa12-0/user_guide/b_ESA_Admin_Guide_12_0/b_ESA_Admin_Guide_12_0_chapter_010101.html#task_1231917

Question 7:

A Cisco ESA administrator has noticed that new messages being sent to the Centralized Policy Quarantine are being released after one hour. Previously, they were held for a day before being released. What was configured that caused this to occur?

A. The retention period was changed to one hour.

B. The threshold settings were set to override the clock settings.

C. The retention period was set to default.

D. The threshold settings were set to default.

Question 8:

Which two actions are configured on the Cisco ESA to query LDAP servers? (Choose two.)

A. accept

B. relay

C. delay

D. route

E. reject

Reference: https://www.cisco.com/c/en/us/td/docs/security/esa/esa11-0/user_guide_fs/b_ESA_Admin_Guide_11_0/b_ESA_Admin_Guide_chapter_011010.html

Question 9:

Which two configurations are used on multiple LDAP servers to connect with Cisco ESA? (Choose two.)

A. load balancing

B. SLA monitor

C. active-standby

D. failover

E. active-active

You can enter multiple host names to configure the LDAP servers for failover or load-balancing. Separate multiple entries with commas.

Reference: https://www.cisco.com/c/en/us/td/docs/security/ces/user_guide/sma_user_guide/b_SMA_Admin_Guide_ces_11/b_SMA_Admin_Guide_chapter_01010.html

Question 10:

Which two action types are performed by Cisco ESA message filters? (Choose two.)

A. non-final actions

B. filter actions

C. discard actions

D. final actions

E. quarantine actions

Reference: https://www.cisco.com/c/en/us/td/docs/security/esa/esa11-1/user_guide/b_ESA_Admin_Guide_11_1/b_ESA_Admin_Guide_chapter_01000.html

Question 11:

What is the benefit of implementing URL filtering on the Cisco ESA?

A. removes threats from malicious URLs

B. blacklists spam

C. provides URL reputation protection

D. enhances reputation against malicious URLs

Reference: https://www.cisco.com/c/en/us/support/docs/security/email-security-appliance/118775-technote-esa-00.html

Question 12:

Refer to the exhibit. An engineer is trying to connect to a Cisco ESA using SSH and has been unsuccessful. Upon further inspection, the engineer notices that there is a loss of connectivity to the neighboring switch.

latest 300-720 questions 12

Which connection method should be used to determine the configuration issue?

A. Telnet


C. Ethernet

D. serial

Question 13:

Which two statements about configuring message filters within the Cisco ESA are true? (Choose two.)

A. The filters command executed from the CLI is used to configure the message filters.

B. Message filter configuration within the web user interface is located within Incoming Content Filters.

C. The filter config command executed from the CLI is used to configure message filters.

D. Message filters can be configured only from the CLI.

E. Message filters can be configured only from the web user interface.

Reference: https://www.cisco.com/c/en/us/support/docs/security/email-security-appliance/213940-esa-using-a-message-filter-to-take-act.html

Question 14:

Which two factors must be considered when message filter processing is configured? (Choose two.)

A. message-filter order

B. lateral processing

C. structure of the combined packet

D. mail policies

E. MIME structure of the message

Reference: https://www.cisco.com/c/en/us/td/docs/security/esa/esa12-0/user_guide/b_ESA_Admin_Guide_12_0/b_ESA_Admin_Guide_chapter_01000.html

Question 15:

What occurs when configuring separate incoming mail policies?

A. message splintering

B. message exceptions

C. message detachment

D. message aggregation

View answer:


Cisco 300-720 SESA certification value

Cisco 300-720 SESA (Securing Email with Cisco Email Security Appliance) certification is designed for professionals who want to specialize in email security.

It validates the knowledge and skills required to configure, manage, and troubleshoot Cisco Email Security Appliances, as well as to implement email security solutions.

The value of Cisco 300-720 SESA certification is that it provides the following benefits:

1. Expertise in Email Security: This certification demonstrates that you have expertise in email security, including threat protection, email encryption, and email filtering. It also validates your ability to configure, manage, and troubleshoot Cisco Email Security Appliances.

2. Career Opportunities: This certification enhances your career opportunities by validating your expertise in email security. It can open up new job opportunities and increase your earning potential.

3. Recognition: Cisco is a well-known and respected brand in the IT industry, and earning a Cisco certification demonstrates your commitment to your profession and your dedication to staying up-to-date with the latest technologies and best practices.

4. Competitive Advantage: Cisco 300-720 SESA certification provides a competitive advantage over non-certified professionals. It demonstrates your commitment to your profession and your willingness to invest in your career development.

5. Professional Growth: This certification also provides opportunities for professional growth by providing access to training, resources, and networking opportunities with other Cisco-certified professionals.

In summary, Cisco 300-720 SESA certification validates your expertise in email security, enhances your career opportunities, provides recognition and competitive advantage, and supports your professional growth.