Exam Details

  • Exam Code
    :250-441
  • Exam Name
    :Administration of Symantec Advanced Threat Protection 3.0
  • Certification
    :Symantec Certified Specialist
  • Vendor
    :Symantec
  • Total Questions
    :95 Q&As
  • Last Updated
    :May 08, 2024

Symantec Symantec Certified Specialist 250-441 Questions & Answers

  • Question 31:

    Which National Institute of Standards and Technology (NIST) cybersecurity function is defined as "finding incursions"?

    A. Protect

    B. Identify

    C. Respond

    D. Detect

  • Question 32:

    Which two ATP control points are able to report events that are detected using Vantage? Enter the two control point names:

    A. ATP: network ATP: Endpoint

  • Question 33:

    An ATP administrator is setting up an Endpoint Detection and Response connection.

    Which type of authentication is allowed?

    A. Active Directory authentication

    B. SQL authentication

    C. LDAP authentication

    D. Symantec Endpoint Protection Manager (SEPM) authentication

  • Question 34:

    Refer to the exhibit. An Incident Responder wants to see what was detected on a specific day by the IPS engine.

    Which item must the responder choose from the drop-down menu?

    A. Insight

    B. Cynic

    C. Vantage

    D. Blacklist

  • Question 35:

    Which two questions can an Incident Responder answer when analyzing an incident in ATP? (Choose two.)

    A. Does the organization need to do a healthcheck in the environment?

    B. Are certain endpoints being repeatedly attacked?

    C. Is the organization being attacked by this external entity repeatedly?

    D. Do ports need to be blocked or opened on the firewall?

    E. Does a risk assessment need to happen in the environment?

  • Question 36:

    In which scenario should an Incident Responder manually submit a file to the Cynic portal?

    A. There is a file on a USB that an Incident Responder wants to analyze in a sandbox.

    B. An Incident Responder is unable to remember the password to the .zip archive.

    C. The file has generated multiple incidents in the ATP manager and an Incident Responder wants to blacklist the file.

    D. The file is a legitimate application and an Incident Responder wants to report it to Symantec as a false positive.

  • Question 37:

    What is the role of Vantage within the Advanced Threat Protection (ATP) solution?

    A. Network detection component

    B. Event correlation

    C. Reputation-based security

    D. Detonation/sandbox

  • Question 38:

    Which two actions can an Incident Responder take in the Cynic portal? (Choose two.)

    A. Configure a SIEM feed from the portal to the ATP environment

    B. Configure email reports on convictions

    C. Submit false positive and false negative files

    D. Query hashes

    E. Submit hashes to Insight

  • Question 39:

    An Incident Responder discovers an incident where all systems are infected with a file that has the same name and different hash. As a result, the organism view has multiple entries for the malicious file.

    What is causing this issue?

    A. This is a polymorphic threat

    B. This is a DDoS attack

    C. The file has multiple hashes

    D. The file is trying to phone home

  • Question 40:

    An Incident Responder launches a search from ATP for a file hash. The search returns the results immediately. The responder reviews the Symantec Endpoint Protection Manager (SEPM) command status and does NOT see an indicators of compromise (IOC) search command.

    How is it possible that the search returned results?

    A. The search runs and returns results in ATP and then displays them in SEPM.

    B. This is only an endpoint search.

    C. This is a database search; a command is NOT sent to SEPM for this type of search.

    D. The browser cached result from a previous search with the same criteria.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Symantec exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 250-441 exam preparations and Symantec certification application, do not hesitate to visit our Vcedump.com to find your solutions here.