Cisco 300-720 SESA Secure Email Gateway Practice Exam
Cover the full 300-720 v1.1 blueprint — Secure Email Gateway administration, spam control with Talos, content and message filters, LDAP and SMTP sessions, email authentication and encryption, and quarantines and delivery — with objective-mapped questions, immediate feedback in Learn mode, and full timed simulation in Exam mode.
Start 24-hour free trial →300-720 exam at a glance
- Vendor
- Cisco
- Exam code
- 300-720 (SESA)
- Full name
- Securing Email with Cisco Secure Email Gateway
- Product
- Cisco Secure Email Gateway (formerly Email Security Appliance / ESA)
- Level
- Professional
- Blueprint
- v1.1
- Duration
- 90 minutes
- Role in CCNP
- CCNP Security concentration exam — pair with the SCOR 350-701 core to earn CCNP Security
- Also earns
- Cisco Certified Specialist – Email Content Security
- Domains
- Six, with published weights (see below); they sum to 100%
- Prerequisites
- None formally required; TCP/IP (DNS, SSH, FTP, SNMP, HTTP/S), IP routing, and basic email/security knowledge is recommended
- Delivery
- Pearson VUE; test center or online proctored
Sources: Cisco — SESA (300-720) exam page · Cisco — CCNP Security v1.1 Release Notes (PDF). Verify current details with Cisco before scheduling.
About the Cisco 300-720 SESA exam
The 300-720 SESA exam validates the skills to deploy, configure, and operate the Cisco Secure Email Gateway — the Talos-powered email security platform (formerly the Email Security Appliance) that defends against spam, phishing, business email compromise, malware, and data loss through mail policies, filters, authentication, encryption, and quarantines. For how certification exams work generally, see the certification study guides in our Learning Hub.
SESA is a CCNP Security concentration exam. To earn CCNP Security you pass two exams: the SCOR 350-701 core (Implementing and Operating Cisco Security Core Technologies) plus one concentration — SESA being the email-security option. Passing SESA on its own also earns the Cisco Certified Specialist – Email Content Security credential. Its content-security twin is the web appliance exam SWSA (300-725); directory authentication overlaps with SISE (300-715).
Every PowerKram practice question maps to one of the six weighted domains and links to Cisco’s own exam material, so a weak spot becomes a specific study step rather than a guess.
300-720 exam domains and weights (v1.1)
Cisco publishes six weighted domains for the 300-720 exam, and they sum to 100%. Two domains tie for the largest share at 20% — Content and Message Filters, and Email Authentication and Encryption — so plan to spend the most time building filters and configuring SPF/DKIM/DMARC and encryption. Confirm the current weights on Cisco’s exam topics before scheduling.
Configure Secure Email Gateway features (hardware and virtual-machine specs, initial setup, routing/delivery, GUI, certificate authorities, logging); centralized services on the Secure Email and Web Manager; mail policies; and integration with SecureX and Secure Email Threat Defense.
Control spam with SenderBase/Talos reputation, antispam scanning, safelists and blocklists, and Directory Harvest Attack Prevention (DHAP) on listeners.
Build content and message filters that scan bodies and attachments for keywords, patterns, and conditions and take actions (quarantine, drop, modify) — including data-loss-prevention scenarios. One of two largest domains.
Integrate LDAP for accept, routing, masquerading, group, and end-user queries; and manage SMTP session behavior on public and private listeners.
Configure SPF, DKIM signing/verification, and DMARC; forged-email detection; and email encryption (including flagging messages for encryption). One of two largest domains.
Configure spam, policy, virus, and outbreak quarantines (local and centralized); manage end-user quarantine access; and control delivery via virtual gateways and delivery methods.
Source: Cisco’s official 300-720 weighted blueprint (domains confirmed in the Cisco CCNP Security v1.1 Release Notes, which also confirms the weights are unchanged from v1.0). Weights are Cisco’s and sum to 100%. Verify the current edition before scheduling.
Who the 300-720 exam is for
SESA is aimed at engineers who secure and operate enterprise email:
- Email security and messaging engineers deploying and operating the Cisco Secure Email Gateway.
- Security operations staff tuning spam control, filters, and quarantines against phishing and BEC.
- Administrators configuring SPF/DKIM/DMARC, encryption, and LDAP integration.
- CCNP Security candidates choosing the email-security concentration alongside the SCOR 350-701 core.
Pair email security with its web counterpart SWSA (300-725), deepen identity/LDAP with SISE (300-715), or add perimeter defense with SNCF (300-710). For where email-security skills lead, see the cybersecurity career paths in our Career Hub.
What this 300-720 practice exam delivers
Learn mode
Get the correct answer, the explanation, and a direct link to Cisco’s exam material each question maps to — immediately after each question. Ideal for filter-logic and authentication questions where exact configuration matters.
Exam mode
Timed, full-length simulation spanning all six domains at the real 90-minute pace — so test day feels familiar.
Source-linked explanations
Every answer links to Cisco’s own SESA exam material, so you can verify each Secure Email Gateway configuration and policy choice against the source.
Score by weighted domain
Results break down across the six weighted domains so you can see exactly which email-security area needs more work.
Sample 300-720 practice questions
Ten free questions across the 300-720 weighted domains, with full explanations and source links to Cisco’s exam material. The complete bank is available with the 24-hour trial.
Which Cisco appliance centralizes reporting, tracking, and quarantines across multiple Secure Email Gateways?
- The Cisco Secure Email and Web Manager (formerly Security Management Appliance)
- A desktop label printer
- A wireless access point
- A KVM switch
Show answer & explanation
Correct: A. The Cisco Secure Email and Web Manager (renamed from the Security Management Appliance / SMA) centralizes reporting, message tracking, and spam/policy/virus/outbreak quarantines across multiple gateways — a named administration/centralized-services topic.
Why not the others: a label printer (B), an access point (C), and a KVM switch (D) have nothing to do with centralized email management.
Source: Cisco — SESA: administration / centralized services → Further reading: PowerKram — SWSA (300-725) →Which listener feature limits how many invalid recipients a sender can attempt per hour, defending against attackers probing for valid addresses?
- Increasing the screen brightness
- Directory Harvest Attack Prevention (DHAP)
- Disabling all logging
- A louder chassis fan
Show answer & explanation
Correct: B. Directory Harvest Attack Prevention caps invalid recipients per hour on a listener, blocking attempts to enumerate valid addresses by testing random recipients — a named spam/listener defense.
Why not the others: screen brightness (A), disabling logging (C), and fan noise (D) do nothing to stop directory harvesting.
Source: Cisco — SESA: spam control (DHAP) → Further reading: PowerKram — SISE (300-715) →An administrator must scan message bodies and attachments for a list of prohibited words and quarantine any match. Which tool is designed for this?
- An NTP server
- A DHCP scope
- Content filters using dictionaries and conditions
- A spanning-tree change
Show answer & explanation
Correct: C. Content filters scan bodies and attachments against dictionaries, patterns, and conditions and then take actions such as quarantine, drop, or modify — the standard mechanism for keyword-based control, including DLP-style scenarios.
Why not the others: an NTP server (A) syncs time, a DHCP scope (B) assigns addresses, and a spanning-tree change (D) is switching — none scan email content.
Source: Cisco — SESA: content and message filters →Which filter feature detects when a message’s display name impersonates an internal executive to catch business-email-compromise attempts?
- A brighter status LED
- Increasing the MTU
- A second power supply
- Forged Email Detection
Show answer & explanation
Correct: D. Forged Email Detection compares the From/display name against a dictionary of protected users (e.g. executives) to flag spoofing — a content-filter condition aimed squarely at BEC.
Why not the others: a status LED (A), MTU (B), and a second PSU (C) provide no impersonation detection.
Source: Cisco — SESA: forged email detection →Which LDAP query type lets the Secure Email Gateway reject messages for addresses that don’t exist in the directory, before they’re accepted?
- A DNS PTR lookup
- An LDAP accept (recipient validation) query
- An SNMP walk
- A traceroute
Show answer & explanation
Correct: B. An LDAP accept query validates recipients against the directory so mail for non-existent users is rejected at the listener — reducing load and backscatter. Accept, routing, masquerade, group, and end-user queries are the named LDAP integration types.
Why not the others: a DNS PTR lookup (A), SNMP walk (C), and traceroute (D) don’t validate email recipients against a directory.
Source: Cisco — SESA: LDAP queries →Which listener type on the Secure Email Gateway typically receives inbound email from the internet and applies anti-spam and anti-virus before routing to internal servers?
- A public listener
- A screensaver listener
- A print listener
- A DHCP listener
Show answer & explanation
Correct: A. A public listener accepts inbound mail from external senders and applies reputation, anti-spam, anti-virus, and content policies before delivering to internal mail servers; private listeners typically handle outbound/internal mail. Listener type is core to SMTP-session configuration.
Why not the others: there is no “screensaver” (B), “print” (C), or “DHCP” (D) listener on the gateway — those are invented terms.
Source: Cisco — SESA: SMTP listeners →Which mechanism cryptographically signs outbound messages so recipients can verify they weren’t altered and truly came from your domain?
- Telnet
- A louder alarm
- Disabling TLS
- DKIM (DomainKeys Identified Mail) signing
Show answer & explanation
Correct: D. DKIM adds a cryptographic signature (using a domain key) so receivers can verify message integrity and domain authenticity. With SPF and DMARC, it’s a core part of the authentication domain configured on the gateway signing profile.
Why not the others: Telnet (A) is unencrypted remote access, an alarm (B) is irrelevant, and disabling TLS (C) weakens security rather than authenticating mail.
Source: Cisco — SESA: email authentication (DKIM) → Further reading: PowerKram — SISE (300-715) →A policy requires finance users to flag certain outbound messages for encryption. Which gateway capability enforces this?
- A longer power cable
- Painting the chassis
- Content/encryption filters that trigger Cisco email encryption on flagged messages
- Turning the gateway off at night
Show answer & explanation
Correct: C. A content/outgoing filter can detect a flag (e.g. a subject tag or DLP match) and apply Cisco email encryption to the message before delivery — the standard way to let users request encryption while enforcing it centrally.
Why not the others: a power cable (A), painting the chassis (B), and powering off at night (D) can’t apply encryption policy.
Source: Cisco — SESA: email encryption →What validates end users via LDAP when they log in to access their personal spam quarantine?
- A BIOS password
- A Wi-Fi captive portal
- The Spam Quarantine End-User Authentication Query
- A screensaver password
Show answer & explanation
Correct: C. The Spam Quarantine End-User Authentication Query authenticates users against LDAP so they can log in and manage their own quarantined messages — a named quarantine-configuration item.
Why not the others: a BIOS password (A), a Wi-Fi captive portal (B), and a screensaver password (D) don’t authenticate end-user quarantine access.
Source: Cisco — SESA: spam quarantine authentication →Which feature lets the gateway present multiple source IP addresses for outbound delivery, useful for separating mail streams or managing reputation?
- A screensaver
- Virtual gateways
- A brighter LED
- A second monitor
Show answer & explanation
Correct: B. Virtual gateways let one appliance send outbound mail from multiple IP addresses/interfaces, separating streams (e.g. marketing vs transactional) and managing sending reputation independently — a named delivery-method capability.
Why not the others: a screensaver (A), a brighter LED (C), and a second monitor (D) have nothing to do with outbound delivery.
Source: Cisco — SESA: delivery methods (virtual gateways) → Further reading: PowerKram — SNCF (300-710) →Keep going: Learning & Career resources
SESA is the email-security concentration in the CCNP Security track. Two PowerKram hubs back this exam.
Deep dive: the Secure Email Gateway, the CCNP Security path, and study strategy
What the Secure Email Gateway does
The Cisco Secure Email Gateway inspects inbound and outbound mail: reputation and anti-spam (Talos/SenderBase), anti-virus and Advanced Malware Protection, content and message filters, DLP, authentication (SPF/DKIM/DMARC), encryption, and quarantines. Understanding the email pipeline — listener → reputation/anti-spam → anti-virus/AMP → content/message filters → authentication → quarantine/delivery — ties the six domains together. See SWSA (300-725) →
How SESA fits CCNP Security
CCNP Security requires two exams: the SCOR 350-701 core plus one concentration. SESA is the email-security concentration; its web counterpart SWSA (300-725), identity via SISE (300-715), and firewalls via SNCF (300-710) are related options. Passing SESA alone also earns Cisco Certified Specialist – Email Content Security. See SISE (300-715) →
Realistic study path
The two largest domains (20% each) are Content and Message Filters and Email Authentication and Encryption, so weight your labs there: build filters with dictionaries and conditions, configure SPF/DKIM/DMARC and forged-email detection, and set up encryption. Because v1.1 renamed ESA to Secure Email Gateway and added VMs, certificate authorities, logging, and Secure Email Threat Defense, make sure your materials reflect the current blueprint. Finish with objective-mapped practice and a timed run. See SNCF (300-710) →
Frequently asked questions
What is the 300-720 SESA exam?
Why do some materials say “ESA” and others “Secure Email Gateway”?
Is 300-720 a CCNP exam by itself?
What are the exam domains and weights?
How long is the exam?
Start your free 24-hour 300-720 practice trial
Full access to the question bank, both study modes, source-linked explanations, and score-by-weighted-domain across all six SESA domains. No credit card required.
Start free trial →