Summer Certification Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = getmirror

Pass the Symantec Endpoint Security 250-580 Questions and answers with ExamsMirror

Practice at least 50% of the questions to maximize your chances of passing.
Exam 250-580 Premium Access

View all detail and faqs for the 250-580 exam


816 Students Passed

96% Average Score

98% Same Questions
Viewing page 2 out of 5 pages
Viewing questions 11-20 out of questions
Questions # 11:

An administrator notices that some entries list that the Risk was partially removed. The administrator needs to determine whether additional steps are necessary to remediate the threat.

Where in the Symantec Endpoint Protection Manager console can the administrator find additional information on the risk?

Options:

A.

Risk log

B.

Computer Status report

C.

Notifications

D.

Infected and At-Risk Computers report

Questions # 12:

Which security control performs a cloud lookup on files downloaded during the Initial Access phase?

Options:

A.

Exploit Protection

B.

Auto-Protect

C.

Intrusion Prevention

D.

Antimalware

Questions # 13:

Where in the Attack Chain does Threat Defense for Active Directory provide protection?

Options:

A.

Attack Surface Reduction

B.

Attack Prevention

C.

Detection and Response

D.

Breach Prevention

Questions # 14:

What is a feature of Cynic?

Options:

A.

Local Sandboxing

B.

Forwarding event data to Security Information and Event Management (SIEM)

C.

Cloud Sandboxing

D.

Customizable OS Images

Questions # 15:

A user is unknowingly about to connect to a malicious website and download a known threat within a .rar file. All Symantec Endpoint Protection technologies are installed on the client's system.

In which feature set order must the threat pass through to successfully infect the system?

Options:

A.

Download Insight, Firewall, IPS

B.

Firewall, IPS, Download Insight

C.

IPS, Firewall, Download Insight

D.

Download Insight, IPS, Firewall

Questions # 16:

An organization has several Symantec Endpoint Protection Management (SEPM) Servers without access to the internet. The SEPM can only run LiveUpdate within a specified "maintenance window" outside of business hours.

What content distribution method should the organization utilize?

Options:

A.

JDB file

B.

External LiveUpdate

C.

Internal LiveUpdate

D.

Group Update Provider

Questions # 17:

What EDR function minimizes the risk of an endpoint infecting other resources in the environment?

Options:

A.

Quarantine

B.

Block

C.

Deny List

D.

Firewall

Questions # 18:

What prevention technique does Threat Defense for Active Directory use to expose attackers?

Options:

A.

Process Monitoring

B.

Obfuscation

C.

Honeypot Traps

D.

Packet Tracing

Questions # 19:

The LiveUpdate Download Schedule is set to the default on the Symantec Endpoint Protection Manager (SEPM).

How many content revisions must the SEPM keep to ensure clients that check in to the SEPM every 10 days receive xdelta content packages instead of full content packages?

Options:

A.

10

B.

20

C.

30

D.

60

Questions # 20:

Why is it important for an Incident Responder to review Related Incidents and Events when analyzing an incident for an After Actions Report?

Options:

A.

It ensures that the Incident is resolved, and the threat does not continue to spread to other parts of the environment.

B.

It ensures that the Incident is resolved, and future threats are automatically remediated.

C.

It ensures that the Incident is resolved, and the responder is able to close the incident in the SEDR manager.

D.

It ensures that the Incident is resolved, and the responder can determine the best remediation method.

Viewing page 2 out of 5 pages
Viewing questions 11-20 out of questions
TOP CODES

TOP CODES

Top selling exam codes in the certification world, popular, in demand and updated to help you pass on the first try.