300-720 · Question #154
A security administrator deployed a Cisco Secure Email Gateway appliance with a mail policy configured to store suspected spam for review. The appliance is the DMZ and only the standard HTTP/HTTPS…
The correct answer is C. Enable End-User Quarantine Access and point to an LDAP server for authentication. The requirement is that end users can view their own quarantined spam messages, and only standard HTTP (port 80) and HTTPS (port 443) ports are allowed by the firewall. To allow users to access the End-User Quarantine, you must enable End-User Quarantine Access and configure…
Question
A security administrator deployed a Cisco Secure Email Gateway appliance with a mail policy configured to store suspected spam for review. The appliance is the DMZ and only the standard HTTP/HTTPS ports are allowed by the firewall. An administrator wants to ensure that users can view any suspected spam that was blocked. Which action must be taken to meet this requirement?
Options
- AEnable the external Spam Quarantine and enter the IP address and port for the Secure Email and
- BEnable the Spam Quarantine and leave the default settings unchanged.
- CEnable End-User Quarantine Access and point to an LDAP server for authentication.
- DEnable the Spam Quarantine and specify port 80 for HTTP and port 443 for HTTPS
How the community answered
(21 responses)- A5% (1)
- B10% (2)
- C81% (17)
- D5% (1)
Explanation
The requirement is that end users can view their own quarantined spam messages, and only standard HTTP (port 80) and HTTPS (port 443) ports are allowed by the firewall. To allow users to access the End-User Quarantine, you must enable End-User Quarantine Access and configure authentication, typically via an LDAP server so users can log in with their existing directory credentials. This uses standard HTTPS (port 443) for the web interface, which is already permitted. Option A (external spam quarantine) refers to using Cisco Secure Email and Web Manager. Option B (default settings) does not enable end-user access by default. Option D is partially correct on ports but omits the critical authentication step required for individual user access.
Topics
Community Discussion
No community discussion yet for this question.