nerdexam
Cisco

700-280 · Question #30

Which three options are Cisco ESA facilities that can use LDAP group queries? (Choose three.)

The correct answer is C. Message filters E. Incoming mail policies F. Content filters. On Cisco ESA, LDAP group queries allow the appliance to consult a directory service and make decisions based on whether a sender or recipient belongs to a specific group - and this capability is supported in Message filters (C), Incoming mail policies (E), and Content filters…

Implement and Configure Cisco Email Security Appliances

Question

Which three options are Cisco ESA facilities that can use LDAP group queries? (Choose three.)

Options

  • AAnti-spam settings
  • BSender groups
  • CMessage filters
  • DRAT
  • EIncoming mail policies
  • FContent filters
  • GDestination controls
  • HSenderBase reputation filtering

How the community answered

(54 responses)
  • A
    4% (2)
  • B
    2% (1)
  • C
    89% (48)
  • G
    6% (3)

Explanation

On Cisco ESA, LDAP group queries allow the appliance to consult a directory service and make decisions based on whether a sender or recipient belongs to a specific group - and this capability is supported in Message filters (C), Incoming mail policies (E), and Content filters (F), which are all policy enforcement points that evaluate per-message attributes and can trigger LDAP lookups dynamically during processing.

The distractors are wrong for these reasons:

  • Sender groups (B) classify senders by IP/domain/reputation at connection time, not by directory group membership.
  • RAT (D) (Recipient Access Table) only determines whether the ESA accepts mail for a given recipient address - it has no LDAP group query capability.
  • Anti-spam settings (A), Destination controls (G), and SenderBase reputation filtering (H) operate on reputation scores, delivery parameters, or statistical analysis - none of which involve querying an LDAP directory for group membership.

Memory tip: Think "MCF - Messages, Content, and mail (incoming) policies Filter based on LDAP groups." These three are the active policy enforcement layers that evaluate message content and recipient attributes mid-flow, making them the natural fit for dynamic LDAP group lookups. Everything else either acts at the connection layer (Sender groups, RAT) or uses non-directory data sources (SenderBase, anti-spam, destination controls).

Topics

#LDAP group queries#ESA facilities#Message filtering#Access controls

Community Discussion

No community discussion yet for this question.

Full 700-280 Practice