Skip to main content

250-441 Real Exam Questions

Administration of Symantec Advanced Threat Protection 3.0

95 questions available · Page 1 of 10

Updated Exam DumpsVerified AnswersPass Guarantee

Get Complete Exam Dumps
Question 1 Multiple choice

Which two tasks should an Incident Responder complete when recovering from an incident? (Choose two.)

  1. A

    Rejoin healthy endpoints back to the network

  2. B

    Blacklist any suspicious files found in the environment

  3. C

    Submit any suspicious files to Cynic

  4. D

    Isolate infected endpoints to a quarantine network

  5. E

    Delete threat artifacts from the environment

Show answer and explanation

Correct answers: B, E

Question 2 Drag & drop

DRAG DROP

Which level of privilege corresponds to each ATP account type?
Match the correct account type to the corresponding privileges.

Question diagram
Show answer and explanation
Correct answer diagram
Question 3 Single choice

Which action should an Incident Responder take to remediate false positives, according to Symantec best practices?

  1. A

    Blacklist

  2. B

    Whitelist

  3. C

    Delete file

  4. D

    Submit file to Cynic

Show answer and explanation

Correct answer: B

Explanation

References:
https://symwisedownload.symantec.com//resources/sites/SYMWISE/content/live/DOCUMENTATION/10000/DOC10899/en_US/satp_security_ops_guide_3.0.5.pdf?__gda__=1541987119_a3559016c9355c98c2ec53278a8df2a0(119)

Question 4 Single choice

An Incident Responder needs to remediate a group of endpoints but also wants to copy a potentially suspicious file to the ATP file store.

In which scenario should the Incident Responder copy a suspicious file to the ATP file store?

  1. A

    The responder needs to analyze with Cynic

  2. B

    The responder needs to isolate it from the network

  3. C

    The responder needs to write firewall rules

  4. D

    The responder needs to add the file to a whitelist

Show answer and explanation

Correct answer: A

Explanation

References:
https://support.symantec.com/us/en/article.HOWTO128772.html

Question 5 Multiple choice

An Incident Responder has reviewed a STIX report and now wants to ensure that their systems have NOT

been compromised by any of the reported threats.

Which two objects in the STIX report will ATP search against? (Choose two.)

  1. A

    SHA-256 hash

  2. B

    MD5 hash

  3. C

    MAC address

  4. D

    SHA-1 hash

  5. E

    Registry entry

Show answer and explanation

Correct answers: A, B

Explanation

References:
https://support.symantec.com/en_US/article.HOWTO124779.html

Question 6 Single choice

What does a Quarantine Firewall policy enable an ATP Administrator to do?

  1. A

    Isolate a computer while it is manually being remediated

  2. B

    Submit files to a Central Quarantine server

  3. C

    Filter all traffic leaving the network

  4. D

    Intercept all traffic entering the network

Show answer and explanation

Correct answer: A

Question 7 Single choice

Which best practice does Symantec recommend with the Endpoint Detection and Response feature?

  1. A

    Create a unique Cynic account to provide to ATP

  2. B

    Create a unique Symantec Messaging Gateway account to provide to ATP

  3. C

    Create a unique Symantec Endpoint Protection Manager (SEPM) administrator account to provide to

    ATP

  4. D

    Create a unique Email Security.cloud portal account to provide to ATP

Show answer and explanation

Correct answer: C

Question 8 Single choice

Refer to the exhibit. An Incident Responder wants to see what was detected on a specific day by the IPS engine.

Which item must the responder choose from the drop-down menu?

  1. A

    Insight

  2. B

    Cynic

  3. C

    Vantage

  4. D

    Blacklist

Show answer and explanation

Correct answer: A

Question 9 Single choice

An Incident Responder wants to investigate whether msscrt.pdf resides on any systems.

Which search query and type should the responder run?

  1. A

    Database search filename "msscrt.pdf"

  2. B

    Database search msscrt.pdf

  3. C

    Endpoint search filename like msscrt.pdf

  4. D

    Endpoint search filename ="msscrt.pdf"

Show answer and explanation

Correct answer: A

Question 10 Single choice

Which access credentials does an ATP Administrator need to set up a deployment of ATP: Endpoint, Network, and Email?

  1. A

    Email Security.cloud credentials for email correlation, credentials for the Symantec Endpoint Protection Manager (SEPM) database, and a System Administrator login for the SEPM

  2. B

    Active Directory login to the Symantec Endpoint Protection Manager (SEPM) database, and an Email Security.cloud login with full access

  3. C

    Symantec Endpoint Protection Manager (SEPM) login and ATP: Email login with service permissions

  4. D

    Credentials for the Symantec Endpoint Protection Manager (SEPM) database, and an administrator login for Symantec Messaging Gateway

Show answer and explanation

Correct answer: C

Explanation

References:
https://support.symantec.com/us/en/article.howto124667.html