Cisco CCNP Security Core (SCOR) 350-701Content SecurityMedium
A security team is deploying a new Cisco Secure Email Gateway (formerly ESA) to protect against advanced email threats. The requirement is to identify and quarantine emails that contain suspicious attachments, such as obfuscated executables or password-protected archives, before they reach user inboxes. The solution should also analyze the behavior of these attachments in a safe environment. Which content security feature directly addresses this requirement?
- AEmail Encryption Gateway
- BAnti-Spam Filtering
- CEmail Sandboxing
- DData Loss Prevention (DLP)
Show answer & explanationAnswer & explanation
Correct answer: C. Email Sandboxing
Email Sandboxing is specifically designed to analyze suspicious attachments by executing them in a virtual, isolated environment to observe their behavior without risking the production network. This helps detect zero-day malware and advanced threats that bypass traditional signature-based detection.
Why the other options are wrong
- A. Email Encryption Gateways encrypt outbound emails for confidentiality, not analyze inbound attachments for malware.
- B. Anti-Spam filtering focuses on unsolicited bulk email, not advanced attachment analysis.
- D. DLP prevents sensitive data from leaving the organization, not analyzing inbound attachments for malware.
Email Sandboxing
A content security technology that executes suspicious email attachments in a virtual, isolated environment to safely observe their behavior and identify malicious intent, protecting against zero-day and advanced malware.
- Provides a safe environment to detonate unknown files.
- Detects polymorphic and evasive malware that bypasses signatures.
- Generates reports on file behavior for analysis.
Memory trick: Suspicious Attachments Sent to Sandbox, Safely Scrutinized.