nerdexam
Cisco

300-720 · Question #137

A company security policy requires that the finance department have an easy way to apply encryption to their outbound messages that contain sensitive data. Users must be able to flag the messages…

The correct answer is D. Create an encryption profile and an outgoing content filter that includes \[SECURE\] within the. The requirement is for users to manually flag messages for encryption rather than having the ESA automatically scan and encrypt all messages. The correct approach is to create an encryption profile AND an outgoing content filter that triggers when [SECURE] appears in the…

Cisco ESA Encryption and Message Tracking

Question

A company security policy requires that the finance department have an easy way to apply encryption to their outbound messages that contain sensitive data. Users must be able to flag the messages that require encryption versus a Cisco ESA scanning all messages and automatically encrypting via detection. Which action enables this capability?

Options

  • ACreate an outgoing content filter with no conditions and with the Encrypt and Deliver Now action
  • BCreate a DLP policy manager message action with encryption enabled and apply it to active DLP
  • CCreate an encryption profile with [SECURE] in the Subject setting and enable encryption on the
  • DCreate an encryption profile and an outgoing content filter that includes [SECURE] within the

How the community answered

(21 responses)
  • A
    10% (2)
  • B
    10% (2)
  • C
    5% (1)
  • D
    76% (16)

Explanation

The requirement is for users to manually flag messages for encryption rather than having the ESA automatically scan and encrypt all messages. The correct approach is to create an encryption profile AND an outgoing content filter that triggers when [SECURE] appears in the subject line. When a finance user adds [SECURE] to the subject of an email, the content filter matches it and applies the encryption profile before delivery. Option C is close but incomplete-it only describes creating an encryption profile with [SECURE] in the profile's subject setting, which is not the same as the content filter matching on [SECURE] in the user's outgoing email subject. Option A would encrypt everything unconditionally. Option B uses DLP, which requires the ESA to scan content automatically rather than relying on user-flagging.

Topics

#Email Encryption#Content Filters#Cisco ESA Configuration#User-Initiated Encryption

Community Discussion

No community discussion yet for this question.

Full 300-720 Practice