Cisco CCNP Security Core (SCOR) 350-701Content SecurityEasy

A security engineer is deploying a Cisco Secure Email Gateway (ESA) and needs to implement policies that block emails containing specific keywords or phrases, such as 'confidential' or 'internal use only', when sent to external recipients. Which type of policy on the ESA is primarily used to achieve this content-based filtering?

  1. AOutbreak Filter Policy
  2. BContent Filter Policy
  3. CAnti-Spam Policy
  4. DMessage Filter Policy
Show answer & explanation

Correct answer: B. Content Filter Policy

Content Filter Policies on the Cisco ESA are used to inspect the body, subject, or attachments of emails for specific keywords, regular expressions, or other content-based criteria. This allows for granular control over what sensitive information leaves the organization.

Why the other options are wrong

  • A. Outbreak Filter Policies provide a rapid response to new virus outbreaks or zero-day attacks by blocking emails based on anomalies, not specific content strings.
  • C. Anti-Spam Policies detect and block unsolicited commercial email, not specific keywords in legitimate outbound communications.
  • D. Message Filters are more generic email manipulation rules, often used for routing or simple header-based actions, but Content Filters are specialized for deep content inspection.

ESA Content Filters

Cisco Secure Email Gateway (ESA) policies that inspect email content (subject, body, attachments) for specific keywords, patterns, or data types to enforce security or compliance rules.

  • Used for data loss prevention (DLP) and compliance.
  • Can be applied to inbound and outbound mail.
  • Supports regular expressions and dictionaries.

Memory trick: Content filters read the email's heart.

More Content Security questions