How to Manually Update Outbreak Filter Rules on Cisco Secure Email Gateway?

Answer Correct answer: D — In Security Services > Outbreak Filters, click Update Rules Now to fetch only the outdated Outbreak Filter rules from Cisco's update servers.

An engineer is deploying a Cisco Secure Email Gateway and must ensure it reaches the Cisco update servers to retrieve new rules. The engineer must now manually configure the Outbreak Filter rules on an AsyncOS for Cisco Secure Email Gateway. Only outdated rules must be replaced. Up-to-date rules must be retained. Which action must the engineer take next to complete the configuration?

  1. Use the outbreakconfig command in CLI.
  2. Select Outbreak Filters.
  3. Perform a backup/restore of the database.
  4. Click Update Rules Now. Correct Answer

Community Votes

D
83%
A
17%

83% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests the GUI action that fetches Outbreak Filter rule updates versus CLI/Database options, with the trap being outbreakconfig, which only displays or edits filters already on the appliance.

On an AsyncOS-based Cisco Secure Email Gateway, manually refreshing Outbreak Filter rules is done from Security Services > Outbreak Filters by clicking Update Rules Now, which pulls only stale rules from Cisco's update servers while current rules stay in place. This page confirms why that action, not the outbreakconfig CLI command, completes the configuration.

Picking outbreakconfig (A) because it is the only Outbreak Filter-specific CLI command; it configures and displays existing filter settings but never downloads new rules from Cisco's update servers.

Community Discussion (8 comments)

madboy2 👍 1 Selected: D
only D make sense
Nian 👍 1 Selected: D
outbreakconfig (A) will only show existing filter rules. The CLI command updateconfig will download and update the rules. D is the GUI-based way to update
EMoshi 👍 1 Selected: D
However, if for some reason your email gateway is not able to reach Cisco’s update servers for new rules over a period of time, it is possible that your locally-cached scores are no longer valid, i.e., if a known viral attachment type now has an update in the anti-virus software and/or is no longer a threat. At this time, you may wish to no longer quarantine messages with these characteristics. You can manually download updated outbreak rules from Cisco’s update servers by clicking Update Rules Now. The Update Rules Now button does not “flush” all existing outbreak rules on the email gateway. It only replaces outbreak rules that have been updated. If there are no updates available on Cisco’s update servers, then the email gateway will not download any outbreak rules when you click this button. https://www.cisco.com/c/en/us/td/docs/security/esa/esa15-0/user_guide/b_ESA_Admin_Guide_15-0.pdf
kloug 👍 1
Answer a
dfb0b7d 👍 1 Selected: D
You can manually download updated outbreak rules from Cisco’s update servers by clicking Update Rules Now https://www.cisco.com/c/en/us/td/docs/security/esa/esa15-0/user_guide/b_ESA_Admin_Guide_15-0.pdf
cbaina 👍 1 Selected: D
Arian is correct
Arian5431 👍 3
D correct answer download this pdf and search for outbreak filter rules and you can see the bottom to click for updates https://www.cisco.com/c/en/us/td/docs/security/esa/esa15-0/user_guide/b_ESA_Admin_Guide_15-0.pdf
devildog 👍 1 Selected: A
I believe A. is the correct option, I don't understand how performing a backup/restore will complete the configuration.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Clicking Update Rules Now on the Security Services > Outbreak Filters page is the manual action that tells AsyncOS to contact Cisco's update servers and retrieve the newest Outbreak Filter rule set. The update is incremental by design: the appliance compares its local rule version against the server's and downloads only the rules that changed, which is exactly the stated requirement that "only outdated rules must be replaced" and up-to-date rules be retained. Because the task is a manual refresh of rules rather than a change to filter settings, this button is the step that actually completes the configuration. Cisco's ESA 15.0 admin guide documents this same page and control for manual rule updates, and the strong community vote for D reflects that documentation.

Why the Other Options Are Wrong

A is wrong because outbreakconfig is the CLI command for viewing and configuring Outbreak Filter settings such as enable/disable, thresholds, and message modification — as Nian noted, it "will only show existing filter rules" and pushes nothing new from Cisco. B is wrong because merely selecting Outbreak Filters only opens the settings page; it changes no values and downloads no rules, so it is a navigation step, not the completing action. C is wrong because backup and restore moves configuration and database contents between appliances and has no mechanism for contacting Cisco's update servers, a point devildog made when questioning how a restore could ever finish this configuration.

Community Comment Notes

Most learners landed on D: dfb0b7d stated that you can "manually download updated outbreak rules from Cisco's update servers" with this control, and madboy2 dismissed the alternatives as making no sense. Nian drew the useful CLI distinction, explaining that outbreakconfig only displays existing filter rules while the actual download is performed by an update command, and Arian5431 pointed readers to the ESA 15.0 admin guide where the update control is documented. A small minority — devildog and kloug — argued for A, and while their objection to the backup/restore option is valid, A still only shows or edits filters already present rather than fetching replacements.

Official Reference

Exam Strategy

When an email security question says the engineer must "manually" refresh rules and the options mix a GUI button with CLI commands, separate configuring filters from updating filters — only one action downloads new rules. Treat outbreakconfig as a settings command unless the option explicitly names a rule-update command such as outbreakupdate.

Frequently Asked Questions

Why is the outbreakconfig CLI command not the right step to update Outbreak Filter rules?

outbreakconfig only displays and configures existing Outbreak Filter settings on the appliance; it does not contact Cisco's update servers. The rule download is performed by the Update Rules Now action in the GUI.

Does Update Rules Now replace all Outbreak Filter rules or only outdated ones?

The refresh is incremental: AsyncOS compares local rule versions with Cisco's servers and downloads only changed rules, so up-to-date rules are retained as the question requires.

Related Analysis

← Back to 350-701 Study Guide