Configuring HAT for Incoming Mail on Cisco Email Security Appliance

Configure email security features with Cisco Security Email Threat Defense
Answer Correct answer: B — Configure the Host Access Table (HAT) to accept incoming connections to the listener and determine the mail policy for processing.

An engineer is deploying a Cisco Email Security Appliance and must configure a sender group that decides which mail policy will process the mail. The configuration must accept incoming mails and relay the outgoing mails from the internal server. Which component must be configured to accept the connection to the listener and meet these requirements on a Cisco Secure Email Gateway?

  1. access list
  2. HAT Correct Answer
  3. RAT
  4. sender list

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests knowledge of ESA mail flow components, specifically identifying that the HAT controls incoming connection acceptance and policy assignment, unlike RAT or access lists which serve different purposes.

The Host Access Table (HAT) is the correct component to configure for accepting incoming mail connections and determining which policy processes the email on a Cisco Secure Email Gateway. This page explains how HATs function as sender groups linked to listeners.

Candidates often confuse HAT with RAT (Recipient Access Table), mistakenly believing RAT handles incoming senders when it actually governs recipient validation for outbound messages.

Community Discussion (3 comments)

dfb0b7d 👍 1 Selected: B
The HAT maintains a set of rules that control incoming connections from remote hosts for a listener. Every configured listener has its own HAT. You configure HATs for both public and private listeners. By default, the HAT is defined to take different actions depending on the listener type: Public listeners. The HAT is set to accept email from all hosts. Private listeners. The HAT is set up to relay email from the host(s) you specify, and reject all other hosts. You can define the way in which remote hosts attempt to connect to a listener. You group remote host definitions into sender groups. A sender group is a list of remote hosts defined for the purpose of handling email from those senders in the same way. https://www.cisco.com/c/en/us/td/docs/security/esa/esa15-5-1/user_guide/b_ESA_Admin_Guide_15-5-1/b_ESA_Admin_Guide_12_1_chapter_0110.html
Demon_Queen_Velverosa 👍 1 Selected: B
-Public: We need public listener for incoming email, in other word ESA listens, controls and receives connection from external hosts or domains. Who is sending email for US. The control of these connection is based on HAT (Host Access Table) A HAT is a sender group that decides which mail policy will process the mail. If the Mail Policy associated to this HAT is defined with an Action: ACCEPT “Connection Behavior”, this means that this is for incoming mail. ESA applies an incoming mail policy with a bunch inspection engine. -Private: We need private listener for outgoing mail, in other words, we need to route email sent from your internal domain to external hosts. If the Mail Policy associated to this HAT is defined with an Action: RELAY “Connection Behavior” and the sender IP internal SMTP server. This means that this is for outgoing mail. ESA applies an outgoing mail policy with a bunch inspection engine.
Premium_Pils 👍 1 Selected: B
https://community.cisco.com/t5/security-blogs/cisco-esa-rat-hat-and-mail-flow-policy-simplified/ba-p/4453226 https://www.cisco.com/c/en/us/support/docs/security/email-security-appliance/118136-qanda-esa-00.html

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The Host Access Table (HAT) is explicitly designed to control incoming connections from remote hosts to a listener. As noted in community discussions, "A HAT is a sender group that decides which mail policy will process the mail." By configuring the HAT associated with the public listener, the engineer can accept incoming emails and apply the necessary mail policies for processing.

Why the Other Options Are Wrong

RAT (Option C) is used for validating recipients during outbound mail relay, not for accepting incoming connections. An access list (Option A) provides basic IP filtering at the network layer but does not define the sender group logic required for mail policy selection. A sender list (Option D) is a grouping object used within mail policies for conditional actions but does not control the initial listener connection acceptance.

Community Comment Notes

Community consensus strongly supports B, with users noting that "The HAT maintains a set of rules that control incoming connections from remote hosts for a listener." One commenter clarified that for public listeners, the HAT typically accepts email from all hosts by default, aligning with the requirement to accept incoming mail.

Official Reference

Exam Strategy

When studying ESA mail flow, clearly distinguish between inbound and outbound components: HAT/RAT for access control, and Sender/Recipient lists for policy targeting. Focus on the specific role of each table in the mail pipeline to avoid confusion during exam scenarios.

Frequently Asked Questions

What is the difference between HAT and RAT in Cisco ESA?

HAT controls incoming connections from senders (inbound), while RAT validates recipients for outgoing mail (outbound).

Can I use an access list instead of a HAT?

No, access lists only filter IPs. HATs are required to map senders to specific mail policies for content processing.

Related Analysis

← Back to 350-701 Study Guide