Map each scenario to the right Cisco content security component: Umbrella for DNS-layer and cloud proxy, WSA for web filtering and HTTPS decryption, ESA for mail authentication. The key skill is choosing the feature that actually enforces the stated policy rather than a related one.
Start practicing
Content Security — choose a session length
Free · No account required
Domain overview
Content Security covers Cisco's email and web security appliances plus cloud-delivered DNS and proxy protection. Questions present deployment scenarios and ask you to pick the correct Cisco ESA, WSA, Umbrella, or SMA feature, configure policy enforcement, and match email authentication or traffic-decryption mechanisms to the stated requirement.
Exam objectives
Cisco Umbrella DNS-layer security, intelligent proxy, and cloud-delivered policy enforcement versus on-premises WSA
Cisco WSA access policies, URL filtering categories, AUP, and HTTPS decryption for blocked categories
Cisco ESA email authentication using SPF, DKIM cryptographic signatures, and DMARC alignment
Cisco SMA, ESA/WSA policy configuration, and message tracking or reporting for content security
Confusing Umbrella DNS-layer protection with WSA proxy filtering; DNS blocks resolution while the proxy inspects and decrypts web traffic.
Selecting SPF when the question demands a cryptographic signature; that is DKIM, and DMARC builds on both for alignment.
Forgetting that HTTPS decryption requires a certificate and decryption policy on WSA before category-based blocking can see inside traffic.
Click any question to see the full explanation and answer options, or start a focused practice session above.
A security administrator notices that a significant volume of spam is bypassing the Cisco ESA's anti-spam filters. Upon investigation, they find that the messages have a mid-range SBRS score of 5.0. Which action should the administrator take to improve spam detection?
2A Cisco WSA administrator wants to block access to social media sites for all users during work hours. The proxy is deployed in explicit mode. Which policy type should the administrator use to enforce this restriction?
3Which Cisco content security solution uses DNS to block access to malicious domains and provides cloud-based proxy protection?
4A company is implementing DMARC for its domain. The administrator wants to instruct receivers to reject emails that fail SPF or DKIM checks. Which DMARC policy should the administrator set?
5Which Cisco WSA feature allows administrators to control bandwidth usage per user or group by limiting the amount of bandwidth consumed for specific applications?
6A security analyst receives an alert that a user clicked a link in an email that led to a malicious website. The email was allowed by the Cisco ESA because it passed SPF, DKIM, and DMARC checks. Later analysis reveals the email was sent from a compromised account within the same domain. Which type of attack best describes this scenario?
7An organization is using Cisco Firepower NGFW to enforce content filtering. They want to block social media applications like Facebook and Twitter but allow LinkedIn for business purposes. Which feature should be used to differentiate between these applications?
8Which Cisco email security feature uses SHA-256 hash lookups to detect known malware in email attachments?
9Which TWO statements about Cisco Umbrella SIG are true?
10To protect against phishing attacks that use fraudulent emails to trick users into revealing credentials, which email authentication technology verifies the sending domain's DNS records for a digital signature?
11An organization wants to enforce a policy that blocks outbound emails containing Social Security numbers. Which feature of Cisco ESA should be configured?
12A security engineer is configuring Cisco WSA in explicit proxy mode. Which traffic interception method is being used when each endpoint browser is configured with the proxy address?
13Which Cisco Umbrella feature provides protection against malicious domains by blocking DNS requests to known bad sites?
14Which Cisco technology uses SHA-256 file hashes to determine if a file is malicious by querying a cloud database?
15A security engineer is troubleshooting an issue where users can bypass the Cisco WSA by using HTTPS. What must be enabled on the WSA to inspect encrypted traffic?
16What is the correct order of email authentication checks recommended by Cisco?
17In Cisco ESA, which feature uses TALOS intelligence to provide real-time protection against newly identified email threats before signature updates are available?
18What is the primary purpose of DMARC in email authentication?
19A SOC analyst is investigating a BEC attack. Which three indicators should be examined in the email headers to detect the spoofing? (Choose three.)
20An organization wants to prevent users from accessing known malicious websites. Which Cisco WSA feature should be configured to block access based on website reputation?
21A security administrator receives an alert that an email with an attachment was blocked by the Cisco Email Security Appliance (ESA). The attachment was identified as malware using cloud lookup. Which technology was used to detect the threat?
22An organization is implementing email authentication to prevent domain spoofing. They have deployed SPF and DKIM. Which additional record should they publish to instruct receiving mail servers on how to handle emails that fail SPF or DKIM checks?
23A company wants to enforce that all outbound emails containing credit card numbers are blocked. Which Cisco ESA feature should be configured to achieve this?
24A network administrator is configuring Cisco WSA to intercept web traffic transparently. Which protocol should be used to redirect traffic from the router to the WSA?
25An organization has deployed Cisco WSA in explicit proxy mode. Users are required to authenticate using their Active Directory credentials. Which WSA feature enables transparent user identification without requiring users to manually log in?
26A security analyst notices that a user is downloading a file from a website. The Cisco WSA is configured to perform AMP file scanning. What happens when the file's SHA-256 hash is not found in the local cache?
27During a phishing simulation, an employee receives an email that appears to be from the CEO requesting an urgent wire transfer. This type of attack is known as:
28A Cisco WSA administrator wants to prioritize bandwidth for video conferencing applications while limiting recreational streaming. Which feature should be configured?
29An organization is using Cisco ESA and wants to ensure that emails sent from their domain are authenticated using a cryptographic signature. Which email authentication method should be configured?
30Which TWO of the following are capabilities of Cisco Umbrella SIG? (Choose TWO.)
31A security team is investigating an email threat that bypassed the Cisco ESA. The email appears to be from the CFO asking for a wire transfer. Which THREE of the following are characteristics of this attack? (Choose THREE.)
32Which TWO of the following are valid methods for deploying Cisco WSA? (Choose TWO.)
33A security engineer is configuring the Cisco ESA to block spam. The engineer wants to rely on a reputation-based system that scores senders based on global email traffic patterns. Which technology should be used?
34An organization wants to prevent employees from accessing social media websites during work hours. Which Cisco WSA feature should be used to enforce this policy?
35A network administrator wants to deploy Cisco WSA as a transparent proxy to inspect web traffic without changing browser settings. Which protocol should be used to redirect traffic to the WSA?
36Which Cisco security solution provides DNS-layer security to block access to malicious domains before a connection is established?
37An organization uses Cisco ESA to enforce DLP policies. Which of the following is an example of a DLP policy that can be configured on the ESA?
38Which Cisco technology provides visibility into the performance of SaaS applications such as Microsoft 365?
39A security engineer is configuring Cisco Firepower NGFW to block social media applications. Which feature should be used to achieve this?
40Which email authentication method allows the domain owner to publish a policy that instructs receiving mail servers on how to handle messages that fail SPF and DKIM checks?
41A security analyst is investigating a Business Email Compromise (BEC) attack. Which two indicators are commonly associated with BEC attacks? (Choose two.)
42An organization is deploying Cisco WSA in explicit proxy mode. Which three considerations are important for this deployment? (Choose three.)
43Which two Cisco solutions can be used to provide cloud-based content security including DNS-layer protection and cloud proxy? (Choose two.)
44An organization wants to prevent outbound email containing credit card numbers from leaving the network. Which Cisco ESA feature should be configured?
45A security engineer needs to block access to social media websites for all users except those in the HR department. The solution must integrate with Active Directory. Which Cisco WSA feature should be used?
46An email administrator receives reports of a targeted phishing campaign where attackers impersonate the CEO to request wire transfers. Which Cisco ESA feature provides the best defense against this Business Email Compromise (BEC) attack?
47A company uses Cisco Umbrella SIG to enforce security policies. An employee attempts to visit a website categorized as 'Phishing' but the request is allowed. What is the most likely cause?
48Which Cisco technology uses SenderBase reputation scores (SBRS) to evaluate incoming email?
49A user reports slow performance when accessing cloud-based applications. Which Cisco tool provides visibility into SaaS application performance?
50Which Cisco ESA feature uses SHA-256 cloud lookups to detect malware in email attachments?
51An organization using Cisco Firepower NGFW wants to block all social media traffic while allowing other web traffic. Which feature should be configured?
52A security engineer is configuring Cisco WSA for HTTPS inspection but notices that some encrypted traffic is being bypassed. The WSA is configured with a decryption policy that excludes traffic to financial websites. What is the most likely reason for the bypass?
53Which Cisco content security solution provides DNS-layer protection and a cloud proxy to enforce security policies?
54A security analyst notices that emails from a trusted partner's domain are being quarantined by the Cisco ESA. The analyst wants to verify the email authentication status. Which TWO authentication mechanisms should be checked?
55An organization is deploying Cisco WSA to enforce acceptable use policies. The administrator wants to block access to social media and streaming video, while also decrypting HTTPS traffic for these categories. Which THREE configuration steps are required?
56A company is experiencing an increase in spear-phishing attacks targeting executives. Which TWO Cisco ESA features should be configured to mitigate this threat?
57A company is using Cisco WSA with explicit proxy mode. The security team wants to enforce HTTPS inspection for all web traffic from the finance department to detect malicious content in encrypted connections. However, they want to exclude traffic to financial institutions' websites due to compliance reasons. Which configuration approach should be used to achieve this?
58An organization wants to protect against Business Email Compromise (BEC) attacks where attackers spoof the CEO's email address to request wire transfers. Which email authentication method is specifically designed to help prevent domain spoofing by allowing senders to specify how email that fails authentication should be handled?
59A company uses Cisco Umbrella SIG to secure internet access for remote users. The security team wants to block access to social media websites but allow access to business-related websites that may share the same IP addresses. Which Umbrella feature should be used to enforce this granular control?
60A company is deploying Cisco ESA and wants to protect against malware delivered via email attachments. Which TWO features can be used together to provide both signature-based detection and behavioral analysis?
61A company is using Cisco WSA with transparent proxy via WCCP. The security team wants to identify which users are accessing banned websites and also enforce bandwidth limits for video streaming. Which TWO features should be configured on the WSA?
62An organization wants to prevent sensitive data such as credit card numbers from being sent via email. Which TWO features of Cisco ESA can be used to achieve this?
63A security team is deploying Cisco Umbrella for DNS-layer security. They want to prevent endpoint users from bypassing the DNS filtering by manually changing their DNS server settings to an external resolver. Which Cisco Umbrella component should they implement to enforce this?
64An administrator is configuring Cisco ESA to handle inbound email. They want to ensure that messages claiming to be from a trusted partner domain are rejected if they fail DMARC alignment, even if they pass SPF or DKIM individually. Which Cisco ESA feature should be configured to enforce this?
65A network security engineer is configuring Cisco Firepower NGFW to block access to a specific URL category. They want to ensure that the policy applies to both HTTP and HTTPS traffic without decrypting SSL. Which feature should they use?
66A security administrator is configuring Cisco WSA to scan outbound uploads for data loss prevention. They want to ensure that files containing credit card numbers are blocked when uploaded to any website. Which WSA feature should be configured?
67A security team is configuring Cisco Umbrella to protect a remote branch where users frequently connect directly to the internet without VPN. They want to enforce web filtering policies and block malicious domains for these roaming users without installing a virtual appliance on the branch router. Which deployment method should they use?
68A security administrator is configuring Cisco ESA to protect against inbound email that contains malicious attachments. The administrator wants to quarantine messages that contain files with macro-enabled Office extensions before they reach user mailboxes. Which Cisco ESA feature should be configured to meet this requirement?
69A security administrator is configuring a Cisco Secure Email Gateway (formerly ESA) to detect and block outbound messages containing customer credit card numbers. The compliance team requires that messages be quarantined when a valid card number pattern is found, and that the detection engine ignore common false-positive patterns such as sequential digits. Which feature should the administrator configure to meet these requirements?
70A network security team is deploying Cisco Firepower Threat Defense (FTD) managed by Cisco Secure Firewall Management Center. They need to decrypt outbound HTTPS traffic so that file policies can inspect downloaded files, but they must not break connections to sites that use certificate pinning. Which FTD feature should be used to selectively bypass decryption for those sites?
71A security engineer is configuring Cisco Umbrella to protect a remote branch that uses the Cisco AnyConnect Secure Mobility Client. The engineer wants DNS requests from roaming users to be inspected by Umbrella even when they are off the corporate network. Which configuration on the Umbrella dashboard is required to accomplish this?
72A security engineer is tuning a Cisco Secure Email Gateway (ESA) to reduce false positives for inbound mail. The organization receives a high volume of legitimate marketing messages that are being quarantined. The engineer wants to use features that influence spam scoring based on sender reputation and message content. Which two ESA features should be examined to adjust how messages are evaluated? (Choose two.)
73A network security team is deploying Cisco Secure Web Appliance to enforce acceptable use and malware protection for outbound web traffic. They need to integrate the appliance with the existing Cisco identity infrastructure so that policies can be applied per user rather than per IP address. Which two authentication mechanisms should they configure on the WSA to achieve user-based policy enforcement? (Choose two.)
74A security operations team is investigating alerts from Cisco Secure Email and Web Manager (formerly Cisco Content Security Management Appliance). They want to reduce false positives in Cisco ESA spam detection without degrading legitimate mail flow. Which two actions should they take? (Choose two.)
75An administrator is configuring Cisco Firepower Management Center to block outbound access to a list of known malicious domains. The requirement is to use the reputation data that Cisco curates and updates automatically, without manually maintaining the domain list. Which Firepower feature should be used?
76A security administrator is configuring Cisco Web Security Appliance (WSA) to inspect HTTPS traffic for malware. The administrator wants to ensure that the WSA can decrypt, inspect, and re-encrypt traffic without causing certificate errors for users. Which configuration is required on the WSA?
77A security operations center is using Cisco Firepower Management Center (FMC) to manage a Firepower NGFW. They want to block outbound traffic that matches known malware command-and-control (C2) domains and IP addresses. The analyst wants to ensure the blocklist is automatically updated from Cisco Talos intelligence. Which feature should be configured on the FMC?
78A company uses Cisco Secure Email Gateway and wants to prevent outbound email from being flagged as spam by recipients because of spoofing. The security team has already published SPF records and wants to add cryptographic signing so that receiving servers can verify the domain. Which record should be published in DNS?
79A security engineer is deploying Cisco Secure Firewall to inspect traffic for malicious content. The engineer needs to ensure that the firewall can detect and block threats in both inbound and outbound directions, and that file transfers are inspected for malware. Which two configurations are required to achieve this? (Choose two.)
80A security analyst is investigating an alert from Cisco Secure Network Analytics (formerly Stealthwatch) indicating a host is communicating with a known command-and-control server. The analyst wants to quickly identify the user and device associated with the host IP address. Which Cisco solution should be integrated with Secure Network Analytics to provide this identity context?
81A security engineer is deploying Cisco Secure Network Analytics (formerly Stealthwatch) to detect anomalous traffic that may indicate data exfiltration. The engineer needs to configure the system to monitor internal-to-external traffic and generate alarms for suspicious flows. Which two actions are required to achieve this? (Choose two.)
82A company has deployed Cisco Secure Firewall (Firepower) with SSL decryption to inspect outbound HTTPS traffic. Users report that some banking websites fail to load and show certificate errors after decryption is enabled. The security team wants to allow these sites without decryption while still inspecting other HTTPS traffic. Which action should be taken on the Secure Firewall to resolve this?
83A company is using Cisco Umbrella to enforce DNS-layer security. An employee attempts to visit a domain that is categorized as 'Command and Control' by Umbrella. The security team wants to ensure the user sees a block page and that the attempt is logged. Which Umbrella feature should be verified as enabled to meet this requirement?
84A network security administrator is configuring Cisco Firepower NGFW to block outbound traffic to known malicious IP addresses and domains. The administrator wants to ensure that the system can automatically update its threat intelligence without manual intervention. Which feature should be enabled to achieve this?
85A security operations team is using Cisco Identity Services Engine (ISE) to enforce endpoint compliance. They want to ensure that endpoints connecting to the network have up-to-date antivirus signatures and operating system patches before being granted full access. Which ISE feature should they configure?
86A company is deploying Cisco Email Security Appliance (ESA) in a clustered configuration. The administrator wants to ensure that if the primary ESA fails, inbound SMTP connections are not lost and mail delivery continues with minimal interruption. Which feature should be configured to achieve this?
87A security administrator is configuring Cisco Web Security Appliance (WSA) to inspect HTTPS traffic. The administrator wants to decrypt and inspect traffic from internal users while avoiding certificate errors on managed endpoints. Which two actions must be performed to achieve this? (Choose two.)
88A network security engineer is configuring Cisco Firepower Management Center (FMC) to block traffic based on the URL category of websites. The engineer wants to ensure that when a user attempts to access a site categorized as 'Malware', the connection is blocked and an event is generated. Which type of policy should be used to accomplish this?
Map each scenario to the right Cisco content security component: Umbrella for DNS-layer and cloud proxy, WSA for web filtering and HTTPS decryption, ESA for mail authentication. The key skill is choosing the feature that actually enforces the stated policy rather than a related one.
The Courseiva 350-701 question bank contains 88 questions in the Content Security domain, covering the 15% of the exam attributed to this domain in the official Cisco blueprint. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Content Security domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included