300-720 · Question #159
A trusted partner of an organization recently experienced a new campaign that was leveraging JavaScript attachments to trick users into executing malware. As a result, they created a local policy to…
The correct answer is D. Create a new encryption profile and deselect the 'Use-Script' envelope settings option. To deliver encrypted communications to a partner who denies JavaScript attachments, the administrator should create an encryption profile that disables the 'Use-Script' envelope setting for that partner.
Question
A trusted partner of an organization recently experienced a new campaign that was leveraging JavaScript attachments to trick users into executing malware. As a result, they created a local policy to deny messages with JavaScript attachments. Which action should the administrator of the organization take to ensure encrypted communications are delivered to the intended partner recipient?
Options
- AInsert the X-PostX-Use-Script' header with a value of false to the encrypted messages
- BSelect JavaScript-free' option within the Cisco Secure Email Encryption Service Add-in
- CCreate an outgoing content filter and add the Encrypt and Deliver Nov/ action with Use-Script
- DCreate a new encryption profile and deselect the 'Use-Script' envelope settings option.
How the community answered
(21 responses)- A5% (1)
- B10% (2)
- C14% (3)
- D71% (15)
Why each option
To deliver encrypted communications to a partner who denies JavaScript attachments, the administrator should create an encryption profile that disables the 'Use-Script' envelope setting for that partner.
While related, `X-PostX-Use-Script` is an internal header, and controlling this functionality is primarily done via the encryption profile settings, not direct header manipulation for policy compliance.
Creating a new encryption profile and deselecting the 'Use-Script' envelope settings option is the correct action to ensure encrypted messages are delivered. This setting controls whether the encrypted message uses a JavaScript-based viewer, and disabling it ensures the message envelope does not trigger the partner's policy against JavaScript attachments.
Concept tested: Cisco ESA secure email encryption profile configuration
Source: https://www.cisco.com/c/en/us/td/docs/security/esa/esa12-0/user_guide/b_ESA_Admin_Guide_12_0/b_ESA_Admin_Guide_12_0_chapter_01001.html
Topics
Community Discussion
No community discussion yet for this question.