Skip to main content

250-438 Real Exam Questions

Administration of Symantec Data Loss Prevention 15

70 questions available · Page 1 of 7

Updated Exam DumpsVerified AnswersPass Guarantee

Get Complete Exam Dumps
Question 1 Single choice

A DLP administrator needs to remove an agent its associated events from an Endpoint server.

Which Agent Task should the administrator perform to disable the agent's visibility in the Enforce management console?

  1. A

    Delete action from the Agent Health dashboard

  2. B

    Delete action from the Agent List page

  3. C

    Disable action from Symantec Management Console

  4. D

    Change Endpoint Server action from the Agent Overview page

Show answer and explanation

Correct answer: C

Question 2 Single choice

Under the "System Overview" in the Enforce management console, the status of a Network Monitor detection server is shown as "Running Selected." The Network Monitor server's event logs indicate that the packet capture and filereader processes are crashing.

What is a possible cause for the Network Monitor server being in this state?

  1. A

    There is insufficient disk space on the Network Monitor server.

  2. B

    The Network Monitor server's certificate is corrupt or missing.

  3. C

    The Network Monitor server's license file has expired.

  4. D

    The Enforce and Network Monitor servers are running different versions of DLP.

Show answer and explanation

Correct answer: D

Question 3 Drag & drop

DRAG DROP

The Symantec Data Loss risk reduction approach has six stages.

Drag and drop the six correct risk reduction stages in the proper order of Occurrence column.

Question diagram
Show answer and explanation
Correct answer diagram
Explanation

References:
https://www.slideshare.net/iftikhariqbal/symantec-data-loss-prevention-technical-proposal-general

Question 4 Single choice

What is required on the Enforce server to communicate with the Symantec DLP database?

  1. A

    Port 8082 should be opened

  2. B

    CryptoMasterKey.properties file

  3. C

    Symbolic links to .dbf files

  4. D

    SQL*Plus Client

Show answer and explanation

Correct answer: D

Explanation

References:
https://www.symantec.com/connect/articles/three-tier-installation-dlp-product

Question 5 Single choice

Which service encrypts the message when using a Modify SMTP Message response rule?

  1. A

    Network Monitor server

  2. B

    SMTP Prevent

  3. C

    Enforce server

  4. D

    Encryption Gateway

Show answer and explanation

Correct answer: D

Explanation

References:
https://www.symantec.com/connect/articles/network-prevent

Question 6 Single choice

Which option is an accurate use case for Information Centric Encryption (ICE)?

  1. A

    The ICE utility encrypts files matching DLP policy being copied from network share through use of encryption keys.

  2. B

    The ICE utility encrypts files matching DLP policy being copied to removable storage through use of encryption keys.

  3. C

    The ICE utility encrypts files matching DLP policy being copied to removable storage on an endpoint use of certificates.

  4. D

    The ICE utility encrypts files matching DLP policy being copied from network share through use of certificates

Show answer and explanation

Correct answer: B

Explanation

References:
https://help.symantec.com/cs/ICE1.0/ICE/v126756321_v120576779/Using-ICE-with-Symantec-Data-Loss-Preventionabout_dlp?locale=EN_US

Question 7 Multiple choice

Which two locations can Symantec DLP scan and perform Information Centric Encryption (ICE) actions on? (Choose two.)

  1. A

    Exchange

  2. B

    Jiveon

  3. C

    File store

  4. D

    SharePoint

  5. E

    Confluence

Show answer and explanation

Correct answers: C, D

Explanation

References:
https://www.symantec.com/content/dam/symantec/docs/data-sheets/information-centric-
encryption-en.pdf

Question 8 Single choice

A DLP administrator determines that the \SymantecDLP\Protect\Incidents folder on the Enforce server contains. BAD files dated today, while other. IDC files are flowing in and out of the \Incidents directory.
Only .IDC files larger than 1MB are turning to .BAD files.
What could be causing only incident data smaller than 1MB to persist while incidents larger than 1MB change to .
BAD files?

  1. A

    A corrupted policy was deployed.

  2. B

    The Enforce server's hard drive is out of space.

  3. C

    A detection server has excessive filereader restarts.

  4. D

    Tablespace is almost full.

Show answer and explanation

Correct answer: D

Question 9 Single choice

What should an incident responder select in the Enforce management console to remediate multiple incidents simultaneously?

  1. A

    Smart Response on the Incident page

  2. B

    Automated Response on the Incident Snapshot page

  3. C

    Smart Response on an Incident List report

  4. D

    Automated Response on an Incident List report

Show answer and explanation

Correct answer: B

Question 10 Multiple choice

Which two detection technology options ONLY run on a detection server? (Choose two.)

  1. A

    Form Recognition

  2. B

    Indexed Document Matching (IDM)

  3. C

    Described Content Matching (DCM)

  4. D

    Exact Data Matching (EDM)

  5. E

    Vector Machine Learning (VML)

Show answer and explanation

Correct answers: B, D

Explanation

References:
https://support.symantec.com/en_US/article.INFO5070.html