Weekend Sale Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: netbudy65

250-428 Administration of Symantec Endpoint Protection 14 Questions and Answers

Questions 4

What SEPM report should an administrator utilize to view the files that Download Insight detected on your computers, after configuring Download Insight?

Options:

A.

Risk Distribution

B.

SONAR Detection Results

C.

Risk Detections Count

D.

Download Risk Distribution

Buy Now
Questions 5

A system running Symantec Endpoint Protection is assigned to a group with client user interface control settings set to mixed mode with Auto-Protect options set to Client. The user on the system is unable to turn off Auto-Protect.

What is the likely cause of this problem?

Options:

A.

Tamper protection is enabled.

B.

System Lockdown is enabled.

C.

Application and Device Control is configured.

D.

The padlock on the enable Auto-Protect option is locked.

Buy Now
Questions 6

Which setting can an administrator configure in the LiveUpdate policy?

Options:

A.

Linux Settings

B.

Frequency to download content

C.

Specific content revision to download from a Group Update Provider (GUP)

D.

Specific content policies to download

Buy Now
Questions 7

Which policy should an administrator modify to enable Virtual Image Exception (VIE) functionality?

Options:

A.

Host Integrity Policy

B.

Exceptions Policy

C.

Virus and Spyware Protection Policy

D.

Application and Device Control Policy

Buy Now
Questions 8

A company deploys Symantec Endpoint Protection (SEP) to50 virtual machines running on a single ESXi host.

Which configuration change can the administrator make to minimize sudden IOPS impact on the ESXi server while each SEP endpoint communicates with the Symantec Endpoint Protection Manager?

Options:

A.

Reduce number of content revisions to keep

B.

Increase download randomization window

C.

Reduce the heartbeat interval

D.

Increase Download Insight sensitivity level

Buy Now
Questions 9

An administrator is reviewing an Infected Clients Report and notices that a client repeatedly shows the same malware detection. Although the client remediates the files, the infection continues to display in the logs.

Which two functions should be enabled to automate enhanced remediation of a detected threat and its related side effects? (Select two.)

Options:

A.

Stop Service Automatically

B.

Stop and Reload AutoProtect

C.

Terminate Processes Automatically

D.

Risk Tracer

E.

Early Launch Anti-Malware Driver

Buy Now
Questions 10

What are two supported Symantec Endpoint Protection Manager authentication types? (Select two.)

Options:

A.

Microsoft Active Directory

B.

MS-CHAP

C.

RSA SecurID

D.

Biometrics

E.

Network Access Control

Buy Now
Questions 11

What is a function of Symantec Insight?

Options:

A.

Provides reputation ratings for binary executables

B.

Enhances the capability of Group Update Providers (GUP)

C.

Provides reputation ratings for structured data

D.

Increases the efficiency and effectiveness of LiveUpdate

Buy Now
Questions 12

Which option is unavailable in the Symantec Endpoint Protection console to run a command on the group menu item?

Options:

A.

Disable SONAR

B.

Scan

C.

Disable Network Threat Protection

D.

Update content and scan

Buy Now
Questions 13

Which client log shows that a client is downloading content from its designated source?

Options:

A.

Log.LiveUpdate

B.

System Log

C.

Risk Log

D.

SesmLu.log

Buy Now
Questions 14

In addition to performance improvements, which two benefits does Insight provide? (Select two.)

Options:

A.

Reputation scoring for documents

B.

Zero-day threat detection

C.

Protection against malicious java scripts

D.

False positive mitigation

E.

Blocking of malicious websites

Buy Now
Questions 15

Which protection engine should an administrator enable in order to drop malicious vulnerability scans against a client system?

Options:

A.

SONAR

B.

Intrusion Prevention

C.

Application and Device Control

D.

Tamper Protection

Buy Now
Questions 16

A company needs to configure an Application and Device Control policy to block read/write access to all USB removable media on its Symantec Endpoint Protection (SEP) systems.

Which tool should an administrator use to format the GUID and device IDs as required by SEP?

Options:

A.

CheckSum.exe

B.

DevViewer.exe

C.

TaskMgr.exe

D.

DeviceTree.exe

Buy Now
Questions 17

An administrator is re-adding an existing Replication Partner to the local Symantec Endpoint Protection Manager site.

Which two parameters are required to re-establish this replication partnership? (Select two.)

Options:

A.

Remote site Encryption Password

B.

Remote server IP Address and port

C.

Remote SQL database account credentials

D.

Remote server Administrator credentials

E.

Remote site Domain ID

Buy Now
Questions 18

Users report abnormal behavior on systems where Symantec Endpoint Protection is installed.

Which tool can an administrator run on the problematic systems to identify the likely cause of the abnormal behavior?

Options:

A.

smc.exe -stop

B.

SymHelp.exe

C.

PowerShell.exe

D.

CleanWipe.exe

Buy Now
Questions 19

A company deploys Symantec Endpoint Protection client to its sales staff who travel across the country.

Which deployment method should the company use to notify its sales staff to install the client?

Options:

A.

Unmanaged Detector

B.

Client Deployment Wizard

C.

Pull mode

D.

Push mode

Buy Now
Questions 20

A Symantec Endpoint Protection administrator needs to prevent users from modifying files in a specific program folder that is on all client machines.

What does the administrator need to configure?

Options:

A.

a file and folder exception in the Exception policy

B.

an application rule set in the Application and Device Control policy

C.

a file fingerprint list and System Lockdown

D.

the Tamper Protection settings for the client folder

Buy Now
Exam Code: 250-428
Exam Name: Administration of Symantec Endpoint Protection 14
Last Update: May 18, 2024
Questions: 135

PDF + Testing Engine

$130

Testing Engine

$95

PDF (Q&A)

$80