New 2023 Realistic 250-561 Dumps Test Engine Exam Questions in here [Q31-Q49]

Share

New 2023 Realistic 250-561 Dumps Test Engine Exam Questions in here

Updated Official licence for 250-561 Certified by 250-561 Dumps PDF

NEW QUESTION 31
An endpoint fails to retrieve content updates.
Which URL should an administrator test in a browser to determine if the issue is network related?

  • A. http://update.symantec.com/livetri.zip
  • B. https://spocsymantec.com/livetri.zip
  • C. https://update.symantec.com/livetri.zip
  • D. https://liveupdate.symantec,com/livetri.zi

Answer: B

 

NEW QUESTION 32
What version number is assigned to a duplicated policy?

  • A. Zero
  • B. The original policy's number plus one
  • C. The original policy's version numb
  • D. One

Answer: B

 

NEW QUESTION 33
Which option should an administrator utilize to temporarily or permanently block a file?

  • A. Hide
  • B. Delete
  • C. Encrypt
  • D. Blacklist

Answer: D

 

NEW QUESTION 34
Which URL is responsible for notifying the SES agent that a policy change occurred in the cloud console?

  • A. spoc.norton.com
  • B. stnd-ipsg.crsi-symantec.com
  • C. ent-shasta.rrs-symantec.com
  • D. ocsp.digicert.com

Answer: D

 

NEW QUESTION 35
Which Anti-malware technology should an administrator utilize to expose the malicious nature of a file created with a custom packet?

  • A. Emulator
  • B. Reputation
  • C. Sandbox
  • D. SONAR

Answer: C

 

NEW QUESTION 36
Which IPS Signature type is Primarily used to identify specific unwanted traffic?

  • A. Audit
  • B. Malcode
  • C. Attack
  • D. Probe

Answer: C

 

NEW QUESTION 37
Which rule types should be at the bottom of the list when an administrator adds device control rules?

  • A. Specific "device type" rules
  • B. General "brand defined" rules
  • C. General "catch all" rules
  • D. Specific "device model" rules

Answer: D

 

NEW QUESTION 38
Which framework, open and available to any administrator, is utilized to categorize adversarial tactics and for each phase of a cyber attack?

  • A. MITRE ADV&NCE
  • B. MITRE RESPONSE
  • C. MITRE ATT&CK
  • D. MITRE ATTACK MATRIX

Answer: A

 

NEW QUESTION 39
What is the primary issue pertaining to managing roaming users while utilizing an on-premise solution?

  • A. The endpoint is absent of the management console
  • B. The endpoint is more exposed to threats
  • C. The endpoint fails to receive content update
  • D. The endpoint is missing timely policy update

Answer: C

 

NEW QUESTION 40
Which two (2) steps should an administrator take to guard against re-occurring threats? (Select two)

  • A. Quarantine affected endpoints
  • B. Verify that all endpoints receive scheduled Live-Update content
  • C. Add endpoints to a high security group and assign a restrictive Antimalware policy to the group
  • D. Use Power Eraser to clean endpoint Windows registries
  • E. Confirm that daily active and weekly full scans take place on all endpoints

Answer: A,D

 

NEW QUESTION 41
After editing and saving a policy, an administrator is prompted with the option to apply the edited policy to any assigned device groups.
What happens to the new version of the policy if the administrator declines the option to apply it?

  • A. The new version of the policy is added to the "in progress" list
  • B. The new version of the policy is deleted
  • C. An unassigned version of the policy is created
  • D. The policy display is returned to edit mode

Answer: D

 

NEW QUESTION 42
Which type of security threat is used by attackers to exploit vulnerable applications?

  • A. Lateral Movement
  • B. Credential Access
  • C. Command and Control
  • D. Privilege Escalation

Answer: D

 

NEW QUESTION 43
Which two (2) options is an administrator able to use to prevent a file from being fasely detected (Select two)

  • A. Reduce the Intensive Protection setting of the Antimalware policy
  • B. Assign the file a SHA-256 cryptographic hash
  • C. Rename the file
  • D. Register the file with Symantec's False Positive database
  • E. Add the file to a Whitelist policy

Answer: D,E

 

NEW QUESTION 44
Which statement best defines Machine Learning?

  • A. A program that learns from experience to optimize the output of a task.
  • B. A program that require data to perform a task.
  • C. A program that needs user input to perform a task.
  • D. A program that teams from observing other programs.

Answer: D

 

NEW QUESTION 45
Which SES security control protects against threats that may occur in the Impact phase?

  • A. Device Control
  • B. IPS
  • C. Antimalware
  • D. Firewall

Answer: D

 

NEW QUESTION 46
The ICDm has generated a blacklist task due to malicious traffic detection. Which SES component was utilized to make that detection?

  • A. IPS
  • B. Antimalware
  • C. Reputation
  • D. Firewall

Answer: B

 

NEW QUESTION 47
Which report template out format should an administrator utilize to generate graphical reports?

  • A. XML
  • B. PFD
  • C. XML
  • D. HTML

Answer: D

 

NEW QUESTION 48
Which report template type should an administrator utilize to create a daily summary of network threats detected?

  • A. Access Violation Report
  • B. Network Risk Report
  • C. Intrusion Prevention Report
  • D. Blocked Threats Report

Answer: A

 

NEW QUESTION 49
......


Symantec 250-561 Exam Syllabus Topics:

TopicDetails
Topic 1
  • Describe the configuration and use of the Endpoint Activity Recorder
  • Describe the ways in which ICDm can be used to remediate threats
Topic 2
  • Describe the process for policy migration from SEPM to the ICDm console
  • Understand how ICDm is used to identify threats in the environment
Topic 3
  • Describe the requirements for Threat Defense for Active Directory Installation and Configuration
  • Describe how SES Complete's mobile technologies protection against malicious apps
Topic 4
  • Describe how the SES Complete Heatmap can be used to prevent unwanted application behaviors
  • Describe the requirements to enable Network Integrity in the ICDm management console
Topic 5
  • Describe how Threat Defense for Active Directory is used to identify threats
  • Describe how SES Complete can be used in preventing an attacker from accessing the environment
Topic 6
  • Describe how Threat Defense for Active Directory protects against misconfigurations and vulnerabilites in an environment
  • Describe how SES Complete works to block data exfiltration
Topic 7
  • Describe the various methods for enrolling SES endpoint agents
  • Introduction to Symantec Endpoint Security Complete
Topic 8
  • Describe the incident lifecycle and steps required to identify a threat
  • Describe the benefits of SES Complete Cloud-based management
Topic 9
  • Understand how Sites and Replication are impacted in a Hybrid environment
  • Understand the Threat landscape and the MITRE ATT&CK Framework
Topic 10
  • Describe how SES Complete blocks Command & Control communication
  • Describe how SES Complete prevents threat execution
Topic 11
  • Describe how to use EDR to retrieve and submit files for analysis
  • Describe how EDR can be used to quarantine endpoint devices
Topic 12
  • Describe how EDR assists in identifying suspicious and malicious activity
  • Describe how EDR can be used to block and quarantine suspicious files
Topic 13
  • Describe how SES Complete's mobile technologies protection against malicious networks
  • Understand how policies are used to protect endpoint devices

 

Grab latest Symantec 250-561 Dumps as PDF Updated: https://www.lead1pass.com/Symantec/250-561-practice-exam-dumps.html

Newly Released 250-561 Dumps for Symantec SCS Certified: https://drive.google.com/open?id=1D5m20lhQioBtGrQsYEMPDDUQfwHFXzjc