Summer Certification Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = getmirror

Pass the Symantec Certified Specialist 250-441 Questions and answers with ExamsMirror

Practice at least 50% of the questions to maximize your chances of passing.
Exam 250-441 Premium Access

View all detail and faqs for the 250-441 exam


726 Students Passed

84% Average Score

98% Same Questions
Viewing page 3 out of 3 pages
Viewing questions 21-30 out of questions
Questions # 21:

Which level of privilege corresponds to each ATP account type?

Match the correct account type to the corresponding privileges.

Question # 21

Options:

Questions # 22:

An Incident Responder wants to investigate whether msscrt.pdf resides on any systems.

Which search query and type should the responder run?

Options:

A.

Database search filename “msscrt.pdf”

B.

Database search msscrt.pdf

C.

Endpoint search filename like msscrt.pdf

D.

Endpoint search filename =“msscrt.pdf”

Questions # 23:

Which National Institute of Standards and Technology (NIST) cybersecurity function is defined as “finding

incursions”?

Options:

A.

Protect

B.

Identify

C.

Respond

D.

Detect

Questions # 24:

How should an ATP Administrator configure Endpoint Detection and Response according to Symantec best practices for a SEP environment with more than one domain?

Options:

A.

Create a unique Symantec Endpoint Protection Manager (SEPM) domain for ATP

B.

Create an ATP manager for each Symantec Endpoint Protection Manager (SEPM) domain

C.

Create a Symantec Endpoint Protection Manager (SEPM) controller connection for each domain

D.

Create a Symantec Endpoint Protection Manager (SEPM) controller connection for the primary domain

Questions # 25:

Which section of the ATP console should an ATP Administrator use to create blacklists and whitelists?

Options:

A.

Reports

B.

Settings

C.

Action Manager

D.

Policies

Questions # 26:

An Incident Responder needs to remediate a group of endpoints but also wants to copy a potentially suspicious file to the ATP file store.

In which scenario should the Incident Responder copy a suspicious file to the ATP file store?

Options:

A.

The responder needs to analyze with Cynic

B.

The responder needs to isolate it from the network

C.

The responder needs to write firewall rules

D.

The responder needs to add the file to a whitelist

Questions # 27:

What is the main constraint an ATP Administrator should consider when choosing a network scanner model?

Options:

A.

Throughput

B.

Bandwidth

C.

Link speed

D.

Number of users

Questions # 28:

Which stage of an Advanced Persistent Threat (APT) attack do attackers send information back to the home base?

Options:

A.

Capture

B.

Incursion

C.

Discovery

D.

Exfiltration

Viewing page 3 out of 3 pages
Viewing questions 21-30 out of questions
TOP CODES

TOP CODES

Top selling exam codes in the certification world, popular, in demand and updated to help you pass on the first try.