Skip to main content

250-428 Real Exam Questions

Administration of Symantec Endpoint Protection 14

165 questions available · Page 1 of 17

Updated Exam DumpsVerified AnswersPass Guarantee

Get Complete Exam Dumps
Question 1 Multiple choice

In which two areas can host groups be used? (Select two.)

  1. A

    Locations

  2. B

    Download Insight

  3. C

    IPS

  4. D

    Application and Device Control

  5. E

    Firewall

Show answer and explanation

Correct answers: C, E

Question 2 Single choice

Which option is a characteristic of a Symantec Endpoint Protection (SEP) domain?

  1. A

    Each domain has its own management server and database.

  2. B

    Every administrator from one domain can view data in other domains.

  3. C

    Data for each domain is stored in its own separate SEP database.

  4. D

    Domains share the same management server and database.

Show answer and explanation

Correct answer: D

Explanation

References:
https://support.symantec.com/en_US/article.HOWTO80764.html

Question 3 Single choice

Which Symantec Endpoint Protection defense mechanism provides protection against threats that propagate from system to system through the use of autotun.inf files?

  1. A

    Host Integrity

  2. B

    SONAR

  3. C

    Application and Device Control

  4. D

    Emulator

Show answer and explanation

Correct answer: C

Question 4 Single choice

A financial company enforces a security policy that prevents banking system workstations from connecting to the Internet.

Which Symantec Endpoint Protection technology is ineffective on this company's workstations?

  1. A

    Insight

  2. B

    Intrusion Prevention

  3. C

    Network Threat Protection

  4. D

    Browser Intrusion Prevention

Show answer and explanation

Correct answer: A

Question 5 Single choice

An administrator wants to have the SEPM run a batch file as the result of a notification.

What directory does a batch file need to be in for the batch file to run?

  1. A

    \Program Files\Symantec\Symantec Endpoint Protection Manager\tomcat

  2. B

    \Program Files\Symantec\Symantec Endpoint Protection Manager\data

  3. C

    \Program Files\Symantec\Symantec Endpoint Protection Manager\bin

  4. D

    \Program Files\Symantec\Symantec Endpoint Protection Manager\bin64

Show answer and explanation

Correct answer: C

Explanation

References:
https://www.symantec.com/connect/forums/batch-files-under-notification-conditions

Question 6 Single choice

A company needs to configure an Application and Device Control policy to block read/write access to all USB removable media on its Symantec Endpoint Protection (SEP) systems.

Which tool should an administrator use to format the GUID and device IDs as required by SEP?

  1. A

    CheckSum.exe

  2. B

    DeviceTree.exe

  3. C

    TaskMgr.exe

  4. D

    DevViewer.exe

Show answer and explanation

Correct answer: D

Question 7 Single choice

What is the difference between a Block versus a Terminate action, when creating an Application Control rule?

  1. A

    A Block action prevents a child process from running. A Terminate action kills the application making the request or the caller process.

  2. B

    A Block action excludes the child process from being scanned. A Terminate action prevents the process from running.

  3. C

    A Block action places the process in Quarantine. A Terminate action kills the application making the request or the caller process.

  4. D

    A Block action prevents the process to be left alone. A Terminate action prevents the process from running.

Show answer and explanation

Correct answer: C

Explanation

References:
https://support.symantec.com/us/en/article.HOWTO80867.html

Question 8 Single choice

An administrator uses the search criteria displayed in the image below.

Which results ore returned from the query?

  1. A

    Only VMware Servers in the Default Group

  2. B

    All Windows 2012 Servers in the Default Group

  3. C

    Only Windows 2012 Servers that are Virtualized in the Default Group

  4. D

    All Windows 2012 Servers and all Virtualized Servers in the Default Group

Show answer and explanation

Correct answer: D

Question 9 Single choice

A Symantec Endpoint Protection administrator needs to prevent users from modifying files in a specific program folder that is on all client machines.

What does the administrator need to configure?

  1. A

    a file and folder exception in the Exception policy

  2. B

    an application rule set in the Application and Device Control policy

  3. C

    a file fingerprint list and System Lockdown

  4. D

    the Tamper Protection settings for the client folder

Show answer and explanation

Correct answer: B

Question 10 Single choice

Which action must a Symantec Endpoint Protection administrator take before creating custom Intrusion Prevention signatures?

  1. A

    Change the custom signature order

  2. B

    Create a Custom Intrusion Prevention Signature library

  3. C

    Define signature variables

  4. D

    Enable signature logging

Show answer and explanation

Correct answer: B

Explanation

References:
https://support.symantec.com/en_US/article.HOWTO80877.html