Cisco CCNP Security Core (SCOR) 350-701Content SecurityMedium

A security administrator is evaluating a Cisco Secure Email Gateway (formerly ESA) for advanced threat protection. The organization frequently deals with highly targeted phishing campaigns that include zero-day malware attachments. Which feature of the ESA would provide the most effective defense against such sophisticated threats by analyzing suspicious files in a safe, isolated environment?

  1. AAnti-spam filtering
  2. BFile reputation and sandboxing
  3. CMailbox Auto Remediation
  4. DURL rewriting and reputation filtering
Show answer & explanation

Correct answer: B. File reputation and sandboxing

File reputation and sandboxing (specifically, Cisco's Advanced Malware Protection - AMP for Email) is designed to detect and analyze zero-day malware. Sandboxing executes suspicious files in a secure, isolated virtual environment to observe their behavior without risking the production network.

Why the other options are wrong

  • A. Anti-spam filtering primarily identifies and blocks unwanted bulk email, not sophisticated zero-day malware attachments.
  • C. Mailbox Auto Remediation is used to remove emails from user inboxes after a threat has been identified, but it's a post-delivery action, not a primary defense against zero-day attachments.
  • D. URL rewriting and reputation filtering protect against malicious links in emails, but not against direct file attachments containing zero-day malware.

Email Sandboxing

A technique used by email security gateways to execute suspicious email attachments in a virtual, isolated environment to observe their behavior for malicious activity.

  • Detects zero-day and advanced malware.
  • Prevents malware from reaching end-user systems.
  • Part of Advanced Malware Protection (AMP).

Memory trick: Sandbox isolates the unknown, reputation flags the bad.

More Content Security questions