350-701 · Question #731
An engineer must configure a Cisco Secure Email Gateway to use DLP for a company. The company also wants to see the content of emails that violate the DLP policy. Which configuration must be…
The correct answer is B. Matched Content Logging. To allow viewing of email content that violates a DLP policy on a Cisco Secure Email Gateway, the 'Matched Content Logging' setting must be enabled.
Question
An engineer must configure a Cisco Secure Email Gateway to use DLP for a company. The company also wants to see the content of emails that violate the DLP policy. Which configuration must be modified in the Data Loss Prevention Settings section to meet the requirements?
Options
- ADLP Message Action
- BMatched Content Logging
- CSecure Reply All
- DSecure Message Forwarding
How the community answered
(41 responses)- A2% (1)
- B88% (36)
- C2% (1)
- D7% (3)
Why each option
To allow viewing of email content that violates a DLP policy on a Cisco Secure Email Gateway, the 'Matched Content Logging' setting must be enabled.
DLP Message Action determines the disposition of a violating message (e.g., quarantine, encrypt, drop), but not whether its content is logged for review.
On the Cisco Secure Email Gateway, the 'Matched Content Logging' configuration within the Data Loss Prevention settings specifically controls whether the actual content that triggered a DLP policy violation is logged. Enabling this allows administrators to review the sensitive information flagged by the policy.
Secure Reply All is a feature related to email encryption for replies, not to logging the content of DLP policy violations.
Secure Message Forwarding relates to secure email delivery mechanisms and does not control the logging of violating content for DLP policies.
Concept tested: Cisco Secure Email Gateway DLP logging
Source: https://www.cisco.com/c/en/us/td/docs/security/ces/esa_cca/ESA-CiscoContentAnalytics/ESA-CiscoContentAnalytics.html
Topics
Community Discussion
No community discussion yet for this question.