Content Security
Drill 20 practice questions focused entirely on Content Security for the Cisco 350-701 exam. Tap an answer for instant feedback and a full explanation — no sign-up, always free.
A compliance team at a healthcare provider requires that any outbound email containing patient records (matching a HIPAA content dictionary) must still be delivered to external recipients but must be protected in transit and at rest on the recipient side. The security engineer creates an outgoing mail policy on the Cisco Secure Email Gateway with a DLP policy that matches the HIPAA classifier. Which primary action should be assigned to the DLP policy to satisfy this requirement?
An email administrator configures anti-malware protection on a Cisco Secure Email Gateway using the Sophos anti-virus engine. During testing, a message is received that the engine identifies as containing an unrepairable virus in the attachment. The administrator wants the gateway to prevent the infected message from ever reaching the recipient's mailbox while still generating a delivery status notification to relevant parties. Which action for 'Infected Messages' in the mail policy achieves this goal?
A financial services company runs a Cisco Secure Email Gateway (ESA). Compliance requires that any outbound message containing customer Social Security Numbers must be prevented from leaving the organization and held for a compliance officer to review before any release decision is made. The security engineer must configure an outgoing mail policy that inspects message content and applies the appropriate action. Which ESA configuration meets this requirement?
A messaging administrator is configuring a Cisco Secure Email Gateway (ESA) to improve the deliverability and authenticity of the company's outbound mail. Remote receiving servers have been rejecting some legitimate messages because they cannot cryptographically confirm that the mail truly originated from the company's domain and was not altered in transit. Which ESA feature should the administrator configure on the outbound mail flow to address this requirement?
Users at a company complain that their inboxes are flooded with legitimate marketing newsletters, subscription confirmations, and social network notifications that are not spam but are unwanted. Management wants these messages identified and controlled separately from true spam, and wants users to be able to safely opt out of the mailing lists without exposing themselves to malicious unsubscribe links. Which Cisco Secure Email Gateway feature should the administrator enable to meet this requirement?
A messaging administrator notices that a Cisco Secure Email Gateway (ESA) is accepting inbound SMTP connections for thousands of nonexistent recipients at the company's domain, causing large volumes of bounce messages and consuming queue resources. The company runs Microsoft Active Directory internally. Which ESA feature should the administrator configure to reject messages addressed to invalid mailboxes during the SMTP conversation and help mitigate directory harvest attacks?
An email administrator on a Cisco Secure Email Gateway needs a custom rule that inspects and modifies certain inbound messages before any per-recipient content filters or anti-spam engines evaluate them. The rule must apply gateway-wide, independent of mail policies, and act on raw message attributes as early as possible in the email pipeline. Which feature should the administrator use to meet this requirement?
An email administrator receives a complaint that a business partner never received an invoice sent three hours ago through the Cisco Secure Email Gateway. The administrator needs to confirm whether the message reached the ESA, what verdicts were applied, and whether the appliance actually attempted delivery to the recipient's domain. Which ESA tool should the administrator use to answer all of these questions in a single view?
A security engineer for a manufacturing firm needs the Cisco Secure Email Gateway (ESA) to protect users during the window between when a new malware campaign begins and when traditional antivirus signatures become available. The requirement is to quarantine suspicious messages that reference not-yet-classified threats, dynamically re-scan them as intelligence matures, and release them automatically once deemed safe. Which ESA feature meets this requirement?
An email administrator at a manufacturing company runs a Cisco Secure Email Gateway (ESA) with an on-box spam quarantine. Users complain that legitimate newsletters from a trusted vendor are consistently classified as spam and held in quarantine, forcing them to manually release the messages each week. The administrator wants to empower individual users to ensure that mail from this specific sender always bypasses the anti-spam engine without weakening spam protection for other senders or requiring administrator intervention for each user. Which feature should the administrator enable to meet this requirement?
An email administrator wants the Cisco Secure Email Gateway to verify that inbound messages originate from IP addresses authorized to send mail for the sender's domain, using DNS TXT records published by the sending domain. Which feature must be enabled to accomplish this on the incoming mail policy?
A financial services company must guarantee that all outbound email to a business partner domain (partner.example.com) is transmitted only over an encrypted channel. If encryption cannot be negotiated with the partner's mail server, the message must NOT be delivered in cleartext. Which configuration on the Cisco Secure Email Gateway meets this requirement?
An administrator on a Cisco Secure Email Gateway is tuning the anti-spam mail policy for the Sales team. Marketing newsletters that users legitimately subscribed to are being flagged as 'suspected spam' (positive spam score below the definite-spam threshold), and users complain they never see these messages to release them. The administrator wants suspected-spam messages held where end users can review and release them individually without administrator involvement, while confirmed spam is still dropped. Which configuration meets this requirement?
A company is deploying a Cisco Secure Web Appliance (SWA) for a group of managed corporate laptops. The security team wants full control over which client traffic goes to the proxy, requires no changes to network infrastructure such as routers or switches, and needs the ability to specify different proxy behavior for different destination URLs (for example, bypassing the proxy for internal SaaS domains). Which traffic redirection method best meets all of these requirements?
A network engineer must deploy the Cisco Secure Web Appliance (SWA) so that internal clients are redirected to the proxy without any changes to their browser or operating system proxy settings. The organization already runs Cisco ASA and Catalyst switches at the aggregation layer and wants to avoid manual PAC file distribution. Which traffic redirection method should the engineer implement on the network devices to transparently steer HTTP/HTTPS traffic to the SWA?
A network administrator at a company using Cisco Umbrella must ensure that a specific set of newly registered competitor domains is always blocked for all users, regardless of the domains' assigned content category or reputation. The list of domains changes frequently and must be maintained manually by the security team. Which Umbrella configuration element should the administrator use to meet this requirement?
A network engineer deploys Cisco Umbrella using only DNS-layer security (no proxy, no SIG tunnel). Marketing complains that a specific SaaS collaboration site is being fully blocked, but security policy only requires blocking the file-upload subsection of that site while allowing the rest. The engineer confirms the domain is categorized in a blocked content category. What is the correct explanation of Umbrella's behavior in this DNS-only deployment?
A network administrator has deployed Cisco Umbrella using DNS-layer security for all branch offices. Users report that some websites in categories rated as risky are being fully allowed or fully blocked at the domain level, but the security team wants Umbrella to inspect only the specific URLs and files from domains that have both trusted and risky content (such as file-sharing sites) — without proxying all internet traffic. Which Umbrella capability should the administrator enable to achieve this selective HTTP/HTTPS inspection?
A company wants to enforce Cisco Umbrella DNS-layer security for laptops that frequently leave the corporate network, and also wants to preserve the internal client IP address in Umbrella reports for on-network desktops that use internal DNS servers. Which combination of Umbrella components should the administrator deploy to meet BOTH requirements?
A network administrator at a mid-size firm reports that users are occasionally reaching malicious domains that are only hours old and not yet classified into any content category. The administrator is building a Cisco Umbrella DNS policy and wants to proactively block these emerging threats without maintaining custom block lists. Which Umbrella setting should be enabled in the policy to address this requirement?
More 350-701 practice
Keep going with the other Cisco CCNP Security SCOR (350-701) domains, or take a full timed mock exam.
← Back to 350-701 overview