700-280 · Question #17
Which option describes when DLP scanning occurs in the email pipeline?
The correct answer is B. Immediately after outbreak filters. DLP scanning occurs immediately after outbreak filters in the Cisco ESA email pipeline because outbreak filters first assess whether a message resembles a known threat pattern, and only after that stage does DLP evaluate message content for sensitive data policy violations…
Question
Which option describes when DLP scanning occurs in the email pipeline?
Options
- ABetween anti-virus and anti-spam check
- BImmediately after outbreak filters
- CBefore anti-spam check
- DAfter message filters and before content filters
How the community answered
(59 responses)- B95% (56)
- C2% (1)
- D3% (2)
Explanation
DLP scanning occurs immediately after outbreak filters in the Cisco ESA email pipeline because outbreak filters first assess whether a message resembles a known threat pattern, and only after that stage does DLP evaluate message content for sensitive data policy violations - this sequencing ensures DLP isn't wasting cycles on messages already flagged for quarantine.
Why the distractors are wrong:
- A (Between anti-virus and anti-spam): DLP runs far later in the pipeline; anti-virus and anti-spam processing happen well before DLP is invoked.
- C (Before anti-spam): DLP is one of the later-stage scanning engines; placing it before anti-spam would reverse the pipeline's logical threat-triage order.
- D (After message filters and before content filters): This describes a real portion of the pipeline, but it skips over anti-spam, anti-virus, and outbreak filters - DLP comes after all of those, not right after message filters.
Memory tip: Think of the pipeline as a funnel that filters bulk threats first (spam → viruses → outbreaks), then applies fine-grained policy checks (DLP) - "Outbreaks before Oversight" can help you remember that outbreak filters immediately precede DLP.
Topics
Community Discussion
No community discussion yet for this question.