Summer Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: buysanta

Exact2Pass Menu

Endpoint Security Complete - R2 Technical Specialist

Last Update 8 hours ago Total Questions : 150

The Endpoint Security Complete - R2 Technical Specialist content is now fully updated, with all current exam questions added 8 hours ago. Deciding to include 250-580 practice exam questions in your study plan goes far beyond basic test preparation.

You'll find that our 250-580 exam questions frequently feature detailed scenarios and practical problem-solving exercises that directly mirror industry challenges. Engaging with these 250-580 sample sets allows you to effectively manage your time and pace yourself, giving you the ability to finish any Endpoint Security Complete - R2 Technical Specialist practice test comfortably within the allotted time.

Question # 11

An organization identifies a threat in its environment and needs to limit the spread of the threat. How should the SEP Administrator block the threat using Application and Device Control?

A.

Gather the MD5 hash of the file and create an Application Content Rule that blocks the file based on the file fingerprint.

B.

Gather the process name of the file and create an Application Content Rule that blocks the file based on the device ID type.

C.

Gather the MD5 hash of the file and create an Application Content Rule that uses regular expression matching.

D.

Gather the MD5 hash of the file and create an Application Content Rule that blocks the file based on specific arguments.

Question # 12

Administrators at a company share a single terminal for configuring Symantec Endpoint Protection. The administrators want to ensure that each administrator using the console is forced to authenticate using their individual credentials. They are concerned that administrators may forget to log off the terminal, which would easily allow others to gain access to the Symantec Endpoint Protection Manager (SEPM) console.

Which setting should the administrator disable to minimize the risk of non-authorized users logging into the SEPM console?

A.

Allow users to save credentials when logging on

B.

Delete clients that have not connected for specified time

C.

Lock account after the specified number of unsuccessful logon attempts

D.

Allow administrators to reset passwords

Question # 13

Which rule types should be at the bottom of the list when an administrator adds device control rules?

A.

Specific "device type" rules

B.

Specific "device model" rules

C.

General "catch all" rules

D.

General "brand defined" rules

Question # 14

A company uses a remote administration tool that is detected as Hacktool.KeyLoggPro and quarantined by Symantec Endpoint Protection (SEP).

Which step can an administrator perform to continue using the remote administration tool without detection by SEP?

A.

Create a Tamper Protect exception for the tool

B.

Create an Application to Monitor exception for the tool

C.

Create a Known Risk exception for the tool

D.

Create a SONAR exception for the tool

Question # 15

A file has been identified as malicious.

Which feature of SEDR allows an administrator to manually block a specific file hash?

A.

Playbooks

B.

Quarantine

C.

Allow List

D.

Block List

Question # 16

An organization has several Symantec Endpoint Protection Management (SEPM) Servers without access to the internet. The SEPM can only run LiveUpdate within a specified "maintenance window" outside of business hours.

What content distribution method should the organization utilize?

A.

JDB file

B.

External LiveUpdate

C.

Internal LiveUpdate

D.

Group Update Provider

Question # 17

Which two (2) security controls are utilized by an administrator to mitigate threats associated with the Discovery phase? (Select two)

A.

Firewall

B.

IPS

C.

Antimalware

D.

Blacklist

E.

E . Device Control

Question # 18

Performance on a SEPM is less than expected and generates intermittent errors. How could the system administrators be notified of performance issues?

A.

Add a System event alert and specify how often the notifications need to be raised. Specify the e-mail address that needs to be notified and the action when the server health becomes poor.

B.

Add an Authentication alert and specify how often the notifications need to be raised. Specify the e-mail address that needs to be notified and the action when the server health becomes poor.

C.

Add a Client security alert and specify how often the notifications need to be raised. Specify the e-mail address that needs to be notified and the action when the server health becomes poor.

D.

Add a Server health alert and specify how often the notifications need to be raised. Specify the e-mail address that needs to be notified and the action when the server health becomes poor.

Question # 19

How would an administrator specify which remote consoles and servers have access to the management server?

A.

Edit the Server Properties and under the General tab, change the Server Communication Permission.

B.

Edit the Communication Settings for the Group under the Clients tab.

C.

Edit the External Communication Settings for the Group under the Clients tab.

D.

Edit the Site Properties and under the General tab, change the server priority.

Question # 20

What feature is used to get a comprehensive picture of infected endpoint activity?

A.

Entity View

B.

Process View

C.

Full Dump

D.

Endpoint Dump

Go to page: