Cisco · Practice Exam · Professional · CCNP Security · Updated for 2026

Cisco 300-720 SESA Secure Email Gateway Practice Exam

Cover the full 300-720 v1.1 blueprint — Secure Email Gateway administration, spam control with Talos, content and message filters, LDAP and SMTP sessions, email authentication and encryption, and quarantines and delivery — with objective-mapped questions, immediate feedback in Learn mode, and full timed simulation in Exam mode.

Start 24-hour free trial →
Product renamed: In the v1.1 update Cisco renamed the appliance from Email Security Appliance (ESA) to Secure Email Gateway, and the exam title changed to match. The domains and weights are otherwise the same as v1.0; v1.1 also added virtual machines, certificate authorities, logging, and Cisco Secure Email Threat Defense. Study materials that still say “ESA” describe the same product.
500+
Practice questions
2
Study modes
100%
Cisco-source-linked
24h
Free trial

300-720 exam at a glance

Vendor
Cisco
Exam code
300-720 (SESA)
Full name
Securing Email with Cisco Secure Email Gateway
Product
Cisco Secure Email Gateway (formerly Email Security Appliance / ESA)
Level
Professional
Blueprint
v1.1
Duration
90 minutes
Role in CCNP
CCNP Security concentration exam — pair with the SCOR 350-701 core to earn CCNP Security
Also earns
Cisco Certified Specialist – Email Content Security
Domains
Six, with published weights (see below); they sum to 100%
Prerequisites
None formally required; TCP/IP (DNS, SSH, FTP, SNMP, HTTP/S), IP routing, and basic email/security knowledge is recommended
Delivery
Pearson VUE; test center or online proctored

Sources: Cisco — SESA (300-720) exam page · Cisco — CCNP Security v1.1 Release Notes (PDF). Verify current details with Cisco before scheduling.

About the Cisco 300-720 SESA exam

The 300-720 SESA exam validates the skills to deploy, configure, and operate the Cisco Secure Email Gateway — the Talos-powered email security platform (formerly the Email Security Appliance) that defends against spam, phishing, business email compromise, malware, and data loss through mail policies, filters, authentication, encryption, and quarantines. For how certification exams work generally, see the certification study guides in our Learning Hub.

SESA is a CCNP Security concentration exam. To earn CCNP Security you pass two exams: the SCOR 350-701 core (Implementing and Operating Cisco Security Core Technologies) plus one concentration — SESA being the email-security option. Passing SESA on its own also earns the Cisco Certified Specialist – Email Content Security credential. Its content-security twin is the web appliance exam SWSA (300-725); directory authentication overlaps with SISE (300-715).

Every PowerKram practice question maps to one of the six weighted domains and links to Cisco’s own exam material, so a weak spot becomes a specific study step rather than a guess.

300-720 exam domains and weights (v1.1)

Cisco publishes six weighted domains for the 300-720 exam, and they sum to 100%. Two domains tie for the largest share at 20% — Content and Message Filters, and Email Authentication and Encryption — so plan to spend the most time building filters and configuring SPF/DKIM/DMARC and encryption. Confirm the current weights on Cisco’s exam topics before scheduling.

Administration

Configure Secure Email Gateway features (hardware and virtual-machine specs, initial setup, routing/delivery, GUI, certificate authorities, logging); centralized services on the Secure Email and Web Manager; mail policies; and integration with SecureX and Secure Email Threat Defense.

15%
Spam Control with Talos SenderBase and Antispam

Control spam with SenderBase/Talos reputation, antispam scanning, safelists and blocklists, and Directory Harvest Attack Prevention (DHAP) on listeners.

15%
Content and Message Filters

Build content and message filters that scan bodies and attachments for keywords, patterns, and conditions and take actions (quarantine, drop, modify) — including data-loss-prevention scenarios. One of two largest domains.

20%Largest (tied)
LDAP and SMTP Sessions

Integrate LDAP for accept, routing, masquerading, group, and end-user queries; and manage SMTP session behavior on public and private listeners.

15%
Email Authentication and Encryption

Configure SPF, DKIM signing/verification, and DMARC; forged-email detection; and email encryption (including flagging messages for encryption). One of two largest domains.

20%Largest (tied)
System Quarantines and Delivery Methods

Configure spam, policy, virus, and outbreak quarantines (local and centralized); manage end-user quarantine access; and control delivery via virtual gateways and delivery methods.

15%

Source: Cisco’s official 300-720 weighted blueprint (domains confirmed in the Cisco CCNP Security v1.1 Release Notes, which also confirms the weights are unchanged from v1.0). Weights are Cisco’s and sum to 100%. Verify the current edition before scheduling.

Who the 300-720 exam is for

SESA is aimed at engineers who secure and operate enterprise email:

  • Email security and messaging engineers deploying and operating the Cisco Secure Email Gateway.
  • Security operations staff tuning spam control, filters, and quarantines against phishing and BEC.
  • Administrators configuring SPF/DKIM/DMARC, encryption, and LDAP integration.
  • CCNP Security candidates choosing the email-security concentration alongside the SCOR 350-701 core.

Pair email security with its web counterpart SWSA (300-725), deepen identity/LDAP with SISE (300-715), or add perimeter defense with SNCF (300-710). For where email-security skills lead, see the cybersecurity career paths in our Career Hub.

What this 300-720 practice exam delivers

Learn mode

Get the correct answer, the explanation, and a direct link to Cisco’s exam material each question maps to — immediately after each question. Ideal for filter-logic and authentication questions where exact configuration matters.

Exam mode

Timed, full-length simulation spanning all six domains at the real 90-minute pace — so test day feels familiar.

Source-linked explanations

Every answer links to Cisco’s own SESA exam material, so you can verify each Secure Email Gateway configuration and policy choice against the source.

Score by weighted domain

Results break down across the six weighted domains so you can see exactly which email-security area needs more work.

Sample 300-720 practice questions

Ten free questions across the 300-720 weighted domains, with full explanations and source links to Cisco’s exam material. The complete bank is available with the 24-hour trial.

Question 1 · Administration (15%)

Which Cisco appliance centralizes reporting, tracking, and quarantines across multiple Secure Email Gateways?

  1. The Cisco Secure Email and Web Manager (formerly Security Management Appliance)
  2. A desktop label printer
  3. A wireless access point
  4. A KVM switch
Show answer & explanation

Correct: A. The Cisco Secure Email and Web Manager (renamed from the Security Management Appliance / SMA) centralizes reporting, message tracking, and spam/policy/virus/outbreak quarantines across multiple gateways — a named administration/centralized-services topic.

Why not the others: a label printer (B), an access point (C), and a KVM switch (D) have nothing to do with centralized email management.

Source: Cisco — SESA: administration / centralized services → Further reading: PowerKram — SWSA (300-725) →
Question 2 · Spam Control with Talos (15%)

Which listener feature limits how many invalid recipients a sender can attempt per hour, defending against attackers probing for valid addresses?

  1. Increasing the screen brightness
  2. Directory Harvest Attack Prevention (DHAP)
  3. Disabling all logging
  4. A louder chassis fan
Show answer & explanation

Correct: B. Directory Harvest Attack Prevention caps invalid recipients per hour on a listener, blocking attempts to enumerate valid addresses by testing random recipients — a named spam/listener defense.

Why not the others: screen brightness (A), disabling logging (C), and fan noise (D) do nothing to stop directory harvesting.

Source: Cisco — SESA: spam control (DHAP) → Further reading: PowerKram — SISE (300-715) →
Question 3 · Content and Message Filters (20%)

An administrator must scan message bodies and attachments for a list of prohibited words and quarantine any match. Which tool is designed for this?

  1. An NTP server
  2. A DHCP scope
  3. Content filters using dictionaries and conditions
  4. A spanning-tree change
Show answer & explanation

Correct: C. Content filters scan bodies and attachments against dictionaries, patterns, and conditions and then take actions such as quarantine, drop, or modify — the standard mechanism for keyword-based control, including DLP-style scenarios.

Why not the others: an NTP server (A) syncs time, a DHCP scope (B) assigns addresses, and a spanning-tree change (D) is switching — none scan email content.

Source: Cisco — SESA: content and message filters →
Question 4 · Content and Message Filters (20%)

Which filter feature detects when a message’s display name impersonates an internal executive to catch business-email-compromise attempts?

  1. A brighter status LED
  2. Increasing the MTU
  3. A second power supply
  4. Forged Email Detection
Show answer & explanation

Correct: D. Forged Email Detection compares the From/display name against a dictionary of protected users (e.g. executives) to flag spoofing — a content-filter condition aimed squarely at BEC.

Why not the others: a status LED (A), MTU (B), and a second PSU (C) provide no impersonation detection.

Source: Cisco — SESA: forged email detection →
Question 5 · LDAP and SMTP Sessions (15%)

Which LDAP query type lets the Secure Email Gateway reject messages for addresses that don’t exist in the directory, before they’re accepted?

  1. A DNS PTR lookup
  2. An LDAP accept (recipient validation) query
  3. An SNMP walk
  4. A traceroute
Show answer & explanation

Correct: B. An LDAP accept query validates recipients against the directory so mail for non-existent users is rejected at the listener — reducing load and backscatter. Accept, routing, masquerade, group, and end-user queries are the named LDAP integration types.

Why not the others: a DNS PTR lookup (A), SNMP walk (C), and traceroute (D) don’t validate email recipients against a directory.

Source: Cisco — SESA: LDAP queries →
Question 6 · LDAP and SMTP Sessions (15%)

Which listener type on the Secure Email Gateway typically receives inbound email from the internet and applies anti-spam and anti-virus before routing to internal servers?

  1. A public listener
  2. A screensaver listener
  3. A print listener
  4. A DHCP listener
Show answer & explanation

Correct: A. A public listener accepts inbound mail from external senders and applies reputation, anti-spam, anti-virus, and content policies before delivering to internal mail servers; private listeners typically handle outbound/internal mail. Listener type is core to SMTP-session configuration.

Why not the others: there is no “screensaver” (B), “print” (C), or “DHCP” (D) listener on the gateway — those are invented terms.

Source: Cisco — SESA: SMTP listeners →
Question 7 · Email Authentication and Encryption (20%)

Which mechanism cryptographically signs outbound messages so recipients can verify they weren’t altered and truly came from your domain?

  1. Telnet
  2. A louder alarm
  3. Disabling TLS
  4. DKIM (DomainKeys Identified Mail) signing
Show answer & explanation

Correct: D. DKIM adds a cryptographic signature (using a domain key) so receivers can verify message integrity and domain authenticity. With SPF and DMARC, it’s a core part of the authentication domain configured on the gateway signing profile.

Why not the others: Telnet (A) is unencrypted remote access, an alarm (B) is irrelevant, and disabling TLS (C) weakens security rather than authenticating mail.

Source: Cisco — SESA: email authentication (DKIM) → Further reading: PowerKram — SISE (300-715) →
Question 8 · Email Authentication and Encryption (20%)

A policy requires finance users to flag certain outbound messages for encryption. Which gateway capability enforces this?

  1. A longer power cable
  2. Painting the chassis
  3. Content/encryption filters that trigger Cisco email encryption on flagged messages
  4. Turning the gateway off at night
Show answer & explanation

Correct: C. A content/outgoing filter can detect a flag (e.g. a subject tag or DLP match) and apply Cisco email encryption to the message before delivery — the standard way to let users request encryption while enforcing it centrally.

Why not the others: a power cable (A), painting the chassis (B), and powering off at night (D) can’t apply encryption policy.

Source: Cisco — SESA: email encryption →
Question 9 · System Quarantines and Delivery (15%)

What validates end users via LDAP when they log in to access their personal spam quarantine?

  1. A BIOS password
  2. A Wi-Fi captive portal
  3. The Spam Quarantine End-User Authentication Query
  4. A screensaver password
Show answer & explanation

Correct: C. The Spam Quarantine End-User Authentication Query authenticates users against LDAP so they can log in and manage their own quarantined messages — a named quarantine-configuration item.

Why not the others: a BIOS password (A), a Wi-Fi captive portal (B), and a screensaver password (D) don’t authenticate end-user quarantine access.

Source: Cisco — SESA: spam quarantine authentication →
Question 10 · System Quarantines and Delivery (15%)

Which feature lets the gateway present multiple source IP addresses for outbound delivery, useful for separating mail streams or managing reputation?

  1. A screensaver
  2. Virtual gateways
  3. A brighter LED
  4. A second monitor
Show answer & explanation

Correct: B. Virtual gateways let one appliance send outbound mail from multiple IP addresses/interfaces, separating streams (e.g. marketing vs transactional) and managing sending reputation independently — a named delivery-method capability.

Why not the others: a screensaver (A), a brighter LED (C), and a second monitor (D) have nothing to do with outbound delivery.

Source: Cisco — SESA: delivery methods (virtual gateways) → Further reading: PowerKram — SNCF (300-710) →

Keep going: Learning & Career resources

SESA is the email-security concentration in the CCNP Security track. Two PowerKram hubs back this exam.

Deep dive: the Secure Email Gateway, the CCNP Security path, and study strategy

What the Secure Email Gateway does

The Cisco Secure Email Gateway inspects inbound and outbound mail: reputation and anti-spam (Talos/SenderBase), anti-virus and Advanced Malware Protection, content and message filters, DLP, authentication (SPF/DKIM/DMARC), encryption, and quarantines. Understanding the email pipeline — listener → reputation/anti-spam → anti-virus/AMP → content/message filters → authentication → quarantine/delivery — ties the six domains together. See SWSA (300-725) →

How SESA fits CCNP Security

CCNP Security requires two exams: the SCOR 350-701 core plus one concentration. SESA is the email-security concentration; its web counterpart SWSA (300-725), identity via SISE (300-715), and firewalls via SNCF (300-710) are related options. Passing SESA alone also earns Cisco Certified Specialist – Email Content Security. See SISE (300-715) →

Realistic study path

The two largest domains (20% each) are Content and Message Filters and Email Authentication and Encryption, so weight your labs there: build filters with dictionaries and conditions, configure SPF/DKIM/DMARC and forged-email detection, and set up encryption. Because v1.1 renamed ESA to Secure Email Gateway and added VMs, certificate authorities, logging, and Secure Email Threat Defense, make sure your materials reflect the current blueprint. Finish with objective-mapped practice and a timed run. See SNCF (300-710) →

Frequently asked questions

What is the 300-720 SESA exam?
300-720 SESA is “Securing Email with Cisco Secure Email Gateway,” a CCNP Security concentration exam. It tests deploying, configuring, and operating the Cisco Secure Email Gateway (formerly Email Security Appliance) — administration, spam control, content and message filters, LDAP and SMTP sessions, email authentication and encryption, and quarantines and delivery.
Why do some materials say “ESA” and others “Secure Email Gateway”?
Cisco renamed the product from Email Security Appliance (ESA) to Secure Email Gateway in the v1.1 update, and the exam title changed to match. They are the same product; older materials using “ESA” still apply, though v1.1 added virtual machines, certificate authorities, logging, and Secure Email Threat Defense.
Is 300-720 a CCNP exam by itself?
SESA is a CCNP Security concentration exam. To earn CCNP Security you pass the SCOR 350-701 core plus one concentration such as SESA. Passing SESA on its own also earns the Cisco Certified Specialist – Email Content Security credential.
What are the exam domains and weights?
Six weighted domains that sum to 100%: Administration (15%), Spam Control with Talos SenderBase and Antispam (15%), Content and Message Filters (20%), LDAP and SMTP Sessions (15%), Email Authentication and Encryption (20%), and System Quarantines and Delivery Methods (15%). Content/Message Filters and Email Authentication/Encryption tie for the largest at 20%.
How long is the exam?
The exam runs 90 minutes. It uses a scaled score, and Cisco does not publish a fixed public cut score. Confirm current details on Cisco’s exam page before scheduling.

Start your free 24-hour 300-720 practice trial

Full access to the question bank, both study modes, source-linked explanations, and score-by-weighted-domain across all six SESA domains. No credit card required.

Start free trial →