nerdexam
Cisco

700-280 · Question #75

What is the default action for DLP with severity of critical?

The correct answer is A. Deliver. By default, DLP policies are configured to deliver messages even when a critical severity violation is detected. This "monitor before enforce" philosophy prevents legitimate business communications from being inadvertently blocked due to policy misconfiguration or false…

Implement and Configure Cisco Email Security Appliances

Question

What is the default action for DLP with severity of critical?

Options

  • ADeliver
  • BDrop
  • CQuarantine
  • DBounce

How the community answered

(37 responses)
  • A
    95% (35)
  • B
    3% (1)
  • C
    3% (1)

Explanation

By default, DLP policies are configured to deliver messages even when a critical severity violation is detected. This "monitor before enforce" philosophy prevents legitimate business communications from being inadvertently blocked due to policy misconfiguration or false positives - organizations must explicitly configure stricter enforcement actions.

Why the distractors are wrong:

  • B. Drop silently discards the message with no notification, which would be a significant, disruptive action that must be deliberately configured - not a safe default.
  • C. Quarantine holds the message for admin review, an active enforcement posture that also requires explicit configuration.
  • D. Bounce returns the message to the sender, exposing that a DLP policy exists and revealing policy details - again, not something enabled by default.

Memory tip: Think of DLP defaults as "Detect, Log, Pass" - the system detects and logs the violation but passes (delivers) the message until an admin consciously decides to enforce stricter controls. The "critical" label describes the severity classification, not the response action.

Topics

#DLP#Email Security#Policy Defaults#Severity Actions

Community Discussion

No community discussion yet for this question.

Full 700-280 Practice