Cisco CCNP Security Core (SCOR) 350-701Content SecurityMedium

A security engineer is troubleshooting an issue where a Cisco Secure Email Gateway (ESA) is blocking legitimate emails due to a high spam score, despite the sender being a trusted partner. The engineer has verified that the sender's IP address is not on any public blacklists. Which ESA feature should be adjusted to allow emails from this specific sender to bypass most spam checks?

  1. AOutbreak Filters configuration
  2. BMessage Filters with content matching
  3. CMail Flow Policies with Sender Groups
  4. DAnti-Spam engine thresholds
Show answer & explanation

Correct answer: C. Mail Flow Policies with Sender Groups

Cisco ESA's Mail Flow Policies, combined with Sender Groups, allow administrators to define specific policies for different groups of senders. By creating a Sender Group for trusted partners and associating it with a Mail Flow Policy that bypasses or reduces spam checks, legitimate emails can be delivered without being blocked.

Why the other options are wrong

  • A. Outbreak Filters provide real-time protection against new threats and are not designed for managing trusted sender exceptions.
  • B. Message Filters are used for more specific content or header-based actions, not typically for overriding anti-spam scores from trusted senders.
  • D. Adjusting global anti-spam thresholds would affect all emails, potentially allowing more spam through.

ESA Sender Groups & Mail Flow Policies

Cisco Secure Email Gateway (ESA) uses Sender Groups within Mail Flow Policies to apply differentiated handling to emails based on the sending source, enabling exceptions for trusted senders.

  • Groups senders (e.g., trusted partners, spammers).
  • Mail Flow Policies apply rules to specific sender groups.
  • Allows bypassing or modifying security checks for trusted sources.

Memory trick: Sender Groups are VIP lanes in the email traffic.

More Content Security questions