nerdexam
Cisco

300-720 · Question #186

An organization is enforcing TLS with an external party. The external business employs its own internal CA so the Secure Email Gateway cannot verify the TLS connection. Which action must an engineer…

The correct answer is B. Enable a custom list on the Network > Certificates page and upload the certificates for the trusted. When an external partner uses a private (internal) Certificate Authority, the Cisco Secure Email Gateway does not trust it by default because the CA is not in its built-in trust store. To resolve this, an engineer must navigate to Network > Certificates, enable a custom…

Email Authentication and Encryption

Question

An organization is enforcing TLS with an external party. The external business employs its own internal CA so the Secure Email Gateway cannot verify the TLS connection. Which action must an engineer take for the Cisco Secure Email Gateway to trust the connection?

Options

  • AModify Destination Controls and set TLS Support to Required for all external and internal
  • BEnable a custom list on the Network > Certificates page and upload the certificates for the trusted
  • CEdit Destination Controls and add the external party domain to the Destination Control Table as
  • DChoose Add Certificate on the Network > Certificates page and create a self-signed certificate.

How the community answered

(28 responses)
  • A
    7% (2)
  • B
    79% (22)
  • C
    4% (1)
  • D
    11% (3)

Explanation

When an external partner uses a private (internal) Certificate Authority, the Cisco Secure Email Gateway does not trust it by default because the CA is not in its built-in trust store. To resolve this, an engineer must navigate to Network > Certificates, enable a custom certificate list, and upload the external party's CA certificate (or certificate chain). This tells the SEG to trust TLS connections whose certificates are signed by that private CA. Simply requiring TLS (Option A) or modifying the Destination Control Table (Option C) does not add trust for an unknown CA. Creating a self-signed certificate (Option D) is unrelated to trusting the remote party's CA.

Topics

#TLS Trust#Certificate Management#External CA#Cisco ESA

Community Discussion

No community discussion yet for this question.

Full 300-720 Practice