300-720 Sample Questions

300-720 Sample Questions & Answers

Content and message filters tie with DKIM, SPF and DMARC authentication for the heaviest weight, alongside mail-policy administration, Talos-based antispam and graymail control, LDAP and SMTP session handling, and spam-quarantine management.

Launch the full 300-720 simulator →

Showing 8 of 17 free samples.

  1. Question 1IntermediateSelect 2

    When email authentication is configured on Cisco ESA, which two key types should be selected on the signing profile? (Choose two.)

    Show answer & explanation

    Correct answers: A, C

  2. Question 2IntermediateSelect 2

    What are two phases of the Cisco ESA email pipeline? (Choose two.)

    Show answer & explanation

    Correct answers: B, D

  3. Question 3IntermediateSelect 2

    Which two action types are performed by Cisco ESA message filters? (Choose two.)

    Show answer & explanation

    Correct answers: A, D

  4. Question 4Intermediate

    Which setting affects the aggressiveness of spam detection?

    Show answer & explanation

    Correct answer: B

  5. Question 5Advanced

    LDAP · Configuring Recipient Validation with LDAP

    A multinational corporation is configuring their Cisco ESA to query a Microsoft Active Directory infrastructure for recipient validation. The directory structure is complex, with users distributed across multiple Organization Units (OUs) based on region. The administrator needs to ensure that the query efficiently finds users regardless of their OU without triggering excessive timeouts or load. Which Base DN and Scope configuration strategy provides the MOST efficient and accurate lookup?

    Show answer & explanation

    Correct answer: C

    To search the entire directory structure including all nested OUs (Organization Units) from a top-level point, the Base DN must be set to the domain root, and the Scope must be set to 'Subtree'. 'Base' only searches the specific object itself, and 'One Level' only searches the immediate children, neither of which would find users distributed in deep OUs.

  6. Question 6Intermediate

    LDAP · Troubleshooting with CLI Tools

    An administrator is verifying the LDAP configuration on a Cisco ESA using the CLI. They need to test if the appliance can successfully connect to the LDAP server and authenticate using the configured credentials. Which command should be used?

    Show answer & explanation

    Correct answer: B

    The ldaptest command is used to verify the LDAP configuration, test connectivity, and perform sample queries to ensure the system is functioning as expected. ldapconfig is used for configuration, not testing.

  7. Question 7Intermediate

    LDAP · Configuring Recipient Validation with LDAP

    A large enterprise uses an LDAP Directory Harvest Attack (DHA) prevention query. Valid external senders are receiving bounces indicating 'User Unknown' even for legitimate recipients. Upon investigation, it is discovered that the LDAP server is occasionally unreachable due to network latency. What configuration change on the Cisco ESA will prevent legitimate mail from being rejected during these outages?

    Show answer & explanation

    Correct answer: A

    In the LDAP profile settings, the administrator can define the behavior when the LDAP server is unreachable. Setting this to 'Accept' ensures that mail is not rejected due to directory unavailability, though it temporarily disables recipient validation. This is the fail-open approach.

  8. Question 8Advanced

    LDAP · Configuring LDAP Alias Consolidation

    Case Study: TechAdvantage Inc.

    TechAdvantage Inc. is migrating their email infrastructure. They require that end-users be able to manage their own spam quarantines. The users are authenticated via an external LDAP server. The security policy mandates that users must log in using their primary email address, but they should also see quarantined messages sent to their alias addresses (e.g., [email protected] should see mail for [email protected]).

    However, currently, users only see messages sent to the specific address they use to log in. The administrator has verified that the LDAP 'accept' query is working correctly for mail delivery.

    Which specific LDAP query type must be configured and associated with the Spam Quarantine to resolve this visibility issue?

    Show answer & explanation

    Correct answer: B

    The LDAP Alias Consolidation query is specifically designed to map multiple email aliases to a single unique user attribute (usually the primary email or UID). When enabled on the Spam Quarantine, it allows the system to aggregate all quarantined messages for all aliases belonging to a user and display them in a single view upon login.

Ready for the real thing?

The full 300-720 simulator has every exam-style question, timed mode, and instant scoring.