Weekend Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: merry71

Free Endpoint Security Complete - R2 Technical Specialist Practice Questions

Exams4sure Dumps

Exam style questions across every 250-580 domain

Last Update 1 day ago
Total Questions : 150

Start with our free 250-580 practice questions, carefully crafted to mirror the domains, phrasing, and difficulty of the real Endpoint Security exam. Each 250-580 exam question comes with a detailed rationale that explains not just which answer is correct but why the others fall short. That's how concepts stick. Use the free set to benchmark yourself: identify your Symantec weak domains, see where you're losing marks, and build a focused study plan in minutes.

250-580 PDF

250-580 PDF (Printable)
$46.5
$154.99

250-580 Testing Engine

250-580 PDF (Printable)
$51
$169.99

250-580 PDF + Testing Engine

250-580 PDF (Printable)
$63.9
$212.99
Question # 1

How should an administrator set up an alert to be notified when manual remediation is needed on an endpoint?

Options:

A.  

Add a Single Risk Event notification and specify "Left Alone" for the action taken. Choose to log the notification and send an e-mail to the system administrators.

B.  

Add a Client security alert notification and specify "Left Alone" for the action taken. Choose to log the notification and send an e-mail to the system administrators.

C.  

Add a System event notification and specify "Left Alone" for the action taken. Choose to log the notification and send an e-mail to the system administrators.

D.  

Add a New risk detected notification and specify "Left Alone" for the action taken. Choose to log the notification and send an emailto the system administrators.

Discussion 0
Question # 2

When a SEPM is enrolled in ICDm, which policy can only be managed from the cloud?

Options:

A.  

LiveUpdate

B.  

Firewall

C.  

Network Intrusion Prevention

D.  

Intensive Protection

Discussion 0
Question # 3

An organization identifies a threat in its environment and needs to limit the spread of the threat. How should the SEP Administrator block the threat using Application and Device Control?

Options:

A.  

Gather the MD5 hash of the file and create an Application Content Rule that blocks the file based on the file fingerprint.

B.  

Gather the process name of the file and create an Application Content Rule that blocks the file based on the device ID type.

C.  

Gather the MD5 hash of the file and create an Application Content Rule that uses regular expression matching.

D.  

Gather the MD5 hash of the file and create an Application Content Rule that blocks the file based on specific arguments.

Discussion 0
Question # 4

Which statement demonstrates how Symantec EDR hunts and detects IoCs in the environment?

Options:

A.  

Searching the EDR database and multiple data sources directly

B.  

Viewing PowerShell processes

C.  

Detecting Memory Exploits in conjunction with SEP

D.  

Detonating suspicious files using cloud-based or on-premises sandboxing

Discussion 0
Question # 5

Files are blocked by hash in the deny list policy. Which algorithm is supported, in addition to MD5?

Options:

A.  

SHA2

B.  

SHA256

C.  

SHA256 "salted"

D.  

MD5 "Salted"

Discussion 0
Question # 6

What should an administrator know regarding the differences between a Domain and a Tenant in ICDm?

Options:

A.  

A tenant can contain multiple domains

B.  

Each customer can have one domain and many tenants

C.  

A domain can contain multiple tenants

D.  

Each customer can have one tenant and no domains

Discussion 0
Question # 7

Which SES security control protects a user against data leakage if they encounter a man-in-the-middle attack?

Options:

A.  

IPv6 Tunneling

B.  

IPS

C.  

Firewall

D.  

VPN

Discussion 0
Question # 8

When are events generated within SEDR?

Options:

A.  

When an incident is selected

B.  

When an activityoccurs

C.  

When any event is opened

D.  

When entities are viewed

Discussion 0
Question # 9

A file has been identified as malicious.

Which feature of SEDR allows an administrator to manually block a specific file hash?

Options:

A.  

Playbooks

B.  

Quarantine

C.  

Allow List

D.  

Block List

Discussion 0
Question # 10

Which SES feature helps administrators apply policies based on specific endpoint profiles?

Options:

A.  

Policy Bundles

B.  

Device Profiles

C.  

Policy Groups

D.  

Device Groups

Discussion 0

Free Exams Sample Questions