300-720 · Question #157
Refer to the exhibit. Which additional configuration action must be taken to protect against Directory Harvest Attacks?
The correct answer is C. In the mail flow policy, configure Directory Harvest Attack Prevention. Directory Harvest Attack (DHA) Prevention on the Cisco Secure Email Gateway is configured within the Mail Flow Policy, not in the LDAP Server profile or Listener Settings. In the mail flow policy, administrators can set a maximum number of invalid recipients per hour; when…
Question
Refer to the exhibit. Which additional configuration action must be taken to protect against Directory Harvest Attacks?
Exhibit
Options
- AWhen LDAP Queries are configured, Directory Harvest Attack Prevention is enabled by default.
- BIn the LDAP Server profile, configure Directory Harvest Attack Prevention
- CIn the mail flow policy, configure Directory Harvest Attack Prevention.
- DIn the Listener Settings, modify the LDAP Queries configuration to use the Work Queue
How the community answered
(63 responses)- A3% (2)
- B2% (1)
- C89% (56)
- D6% (4)
Explanation
Directory Harvest Attack (DHA) Prevention on the Cisco Secure Email Gateway is configured within the Mail Flow Policy, not in the LDAP Server profile or Listener Settings. In the mail flow policy, administrators can set a maximum number of invalid recipients per hour; when exceeded, the connection is dropped, preventing attackers from enumerating valid addresses. Option A is incorrect because DHAP is not automatically enabled when LDAP queries are configured. Option B is incorrect because DHAP settings are not found in the LDAP Server profile itself. Option D is incorrect because modifying LDAP queries in Listener Settings does not configure DHAP; the Work Queue is a separate processing stage.
Topics
Community Discussion
No community discussion yet for this question.
