Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Proofpoint TPAD01 Exam - Topic 5 Question 10 Discussion

You wish to ensure that all emails to an external partner are sent over a secure connection. What should you do?
B) Add the partner's domain to the TLS Domains list with a setting of ''Always.''
A) Add the partner's domain to the TLS Domains list with a setting of ''If Available.''
C) Configure the TLS Minimum Protocol Version to something greater than zero.
D) Configure the SMTP service to use the partner's certificate when sending mail.

Proofpoint TPAD01 Exam - Topic 5 Question 10 Discussion

Actual exam question for Proofpoint's TPAD01 exam
Question #: 10
Topic #: 5
[All TPAD01 Questions]

You wish to ensure that all emails to an external partner are sent over a secure connection. What should you do?

Show Suggested Answer Hide Answer
Suggested Answer: B

The correct answer is B. Add the partner's domain to the TLS Domains list with a setting of ''Always.'' Proofpoint's TLS guidance explains that opportunistic TLS is the default behavior for SMTP unless stricter policy is configured for specific destinations. To require secure transport to a specific partner domain, the administrator must explicitly enforce TLS for that domain rather than merely allowing it when available. Proofpoint describes TLS as a mechanism to encrypt messages in transit between sending and receiving mail servers, and that requirement becomes mandatory only when policy is configured to insist on TLS for the target domain.

Option A is incorrect because ''If Available'' still allows mail to be delivered without TLS if the remote server does not negotiate it, which does not satisfy the requirement to ensure secure delivery. Option C changes general protocol posture but does not by itself force TLS for one specific partner domain. Option D is also not the normal administrative control used for outbound partner enforcement in Proofpoint's course context. In the Threat Protection Administrator course, secure partner delivery is handled through domain-specific TLS enforcement settings, and the tested answer is to require TLS by setting the domain entry to Always. That ensures the Proofpoint system attempts secure SMTP and does not simply fall back to unencrypted transport for that external partner.


Contribute your Thoughts:

0/2000 characters
Clement
2 hours ago
I don't think option D is right because using the partner's certificate seems more related to receiving emails rather than sending them securely.
upvoted 0 times
...
Jacob
5 days ago
I feel like option C is important too, but it seems more about the protocol version rather than ensuring the connection itself.
upvoted 0 times
...
Tresa
10 days ago
I remember practicing a question like this, and I think adding the domain to the TLS list is key, but I can't recall if "If Available" is secure enough.
upvoted 0 times
...
Lynelle
16 days ago
I think option B makes the most sense since it ensures that emails are always sent securely, but I'm not entirely sure if that's the only requirement.
upvoted 0 times
...

Save Cancel