Spring Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: buysanta

Exact2Pass Menu

Endpoint Security Complete - R2 Technical Specialist

Last Update 4 hours ago Total Questions : 150

The Endpoint Security Complete - R2 Technical Specialist content is now fully updated, with all current exam questions added 4 hours ago. Deciding to include 250-580 practice exam questions in your study plan goes far beyond basic test preparation.

You'll find that our 250-580 exam questions frequently feature detailed scenarios and practical problem-solving exercises that directly mirror industry challenges. Engaging with these 250-580 sample sets allows you to effectively manage your time and pace yourself, giving you the ability to finish any Endpoint Security Complete - R2 Technical Specialist practice test comfortably within the allotted time.

Question # 21

Why is it important for an Incident Responder to copy malicious files to the SEDR file store or create an image of the infected system during the Recovery phase?

A.

To create custom IPS signatures

B.

To test the effectiveness of the current assigned policy settings in the Symantec Endpoint Protection Manager (SEPM)

C.

To have a copy of the file for policy enforcement

D.

To document and preserve any pieces of evidence associated with the incident

Question # 22

Files are blocked by hash in the deny list policy. Which algorithm is supported, in addition to MD5?

A.

SHA2

B.

SHA256

C.

SHA256 "salted"

D.

MD5 "Salted"

Question # 23

An organization recently experienced an outbreak and is conducting a health check of the environment. What Protection Technology can the SEP team enable to control and monitor the behavior of applications?

A.

Host Integrity

B.

System Lockdown

C.

Application Control

D.

Behavior Monitoring (SONAR)

Question # 24

What does a ranged query return or exclude?

A.

Data matching the exact field names and their values

B.

Data matching a regular expression

C.

Data falling between two specified values of a given field

D.

Data based on specific values for a given field

Question # 25

An Application Control policy includes an Allowed list and a Blocked list. A user wants to use an application that is neither on the Allowed list nor on the Blocked list. What can the user do to gain access to the application?

A.

Email the App Control Admin

B.

Request an Override

C.

Install the application

D.

Wait for the Application Drift process to complete

Question # 26

What does an Endpoint Activity Recorder (EAR) full dump consist of?

A.

All of the recorded events that occurred on an endpoint relating to a single file

B.

All of the recorded events that occurred on an endpoint relating to a single process

C.

All of the recorded events that occurred on an endpoint

D.

All of the recorded events that are in the SEDR database

Question # 27

What is the maximum number of SEPMs a single Management Platform is able to connect to?

A.

50

B.

10

C.

5,000

D.

500

Question # 28

An Incident Responder has determined that an endpoint is compromised by a malicious threat. What SEDR feature would be utilized first to contain the threat?

A.

File Deletion

B.

Incident Manager

C.

Isolation

D.

Endpoint Activity Recorder

Question # 29

Which antimalware intensity level is defined by the following: "Blocks files that are most certainly bad or potentially bad files results in a comparable number of false positives and false negatives."

A.

Level 6

B.

Level 5

C.

Level 2

D.

Level 1

Question # 30

Which security control is complementary to IPS, providing a second layer of protection against network attacks?

A.

Host Integrity

B.

Network Protection

C.

Antimalware

D.

Firewall

Go to page: