350-701 · Question #757
The security team has installed a Cisco Secure Email Gateway. During setup, a large number of email messages containing the string "abcde1111111111" are being blocked. The security team wants to…
The correct answer is B. Apply a policy to route all blocked emails to a separate quarantine folder. To investigate blocked email messages for potential phishing or malware, the security team must route them to a separate quarantine folder for analysis.
Question
The security team has installed a Cisco Secure Email Gateway. During setup, a large number of email messages containing the string "abcde1111111111" are being blocked. The security team wants to investigate and determine if the emails are part of a phishing or malware attack. Which configuration step must the security team apply?
Options
- AImplement a policy to only allow email from trusted to the network senders.
- BApply a policy to route all blocked emails to a separate quarantine folder.
- CConfigure sender domain reputation policy to check if sender email domain is known to be
- DConfigure a policy to disable spam filtering in order to expedite email delivery.
How the community answered
(24 responses)- A13% (3)
- B75% (18)
- C4% (1)
- D8% (2)
Why each option
To investigate blocked email messages for potential phishing or malware, the security team must route them to a separate quarantine folder for analysis.
Implementing a policy to only allow email from trusted senders would block even more emails and prevent investigation of the current blocked messages.
Routing blocked emails to a separate quarantine folder allows the security team to review the content of these specific emails to determine if they are legitimate, phishing, or malware, without releasing them to end-users or deleting them immediately.
Configuring sender domain reputation policy would help prevent future bad emails but doesn't provide access to the already blocked emails for investigation.
Disabling spam filtering would allow potentially malicious emails to reach user inboxes, increasing risk and preventing investigation in a controlled environment.
Concept tested: Email security incident investigation (quarantine)
Source: https://www.cisco.com/c/en/us/td/docs/security/ces/email_security_appliance/12-0/user_guide/b_ESA_Admin_Guide_12_0/b_ESA_Admin_Guide_12_0_chapter_0100.html#task_DE81177626F64566BE6B042C0E8EC61D
Topics
Community Discussion
No community discussion yet for this question.