300-720 · Question #61
When outbreak filters are configured, which two actions are used to protect users from outbreaks? (Choose two.)
The correct answer is A. redirect D. delay. Cisco ESA Outbreak Filters use two primary actions to protect users: Delay (D) holds suspicious messages in quarantine for a configurable period, allowing Talos threat intelligence to update with new signatures before the message is released or dropped - buying time to catch…
Question
When outbreak filters are configured, which two actions are used to protect users from outbreaks? (Choose two.)
Options
- Aredirect
- Breturn
- Cdrop
- Ddelay
- Eabandon
How the community answered
(39 responses)- A87% (34)
- B8% (3)
- C3% (1)
- E3% (1)
Explanation
Cisco ESA Outbreak Filters use two primary actions to protect users: Delay (D) holds suspicious messages in quarantine for a configurable period, allowing Talos threat intelligence to update with new signatures before the message is released or dropped - buying time to catch newly emerging threats. Redirect (A) rewrites embedded URLs in suspicious messages to point through Cisco's web security proxy; if a user clicks the link after it has been identified as malicious, they are blocked. Return, drop, and abandon are not valid Outbreak Filter actions - Drop would be too aggressive for uncertain threats, and the others are not part of the Outbreak Filter action set.
Topics
Community Discussion
No community discussion yet for this question.