Summer Certification Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = getmirror

Pass the Symantec Endpoint Security 250-580 Questions and answers with ExamsMirror

Practice at least 50% of the questions to maximize your chances of passing.
Exam 250-580 Premium Access

View all detail and faqs for the 250-580 exam


816 Students Passed

96% Average Score

98% Same Questions
Viewing page 3 out of 5 pages
Viewing questions 21-30 out of questions
Questions # 21:

Which EDR feature is used to search for real-time indicators of compromise?

Options:

A.

Domain search

B.

Endpoint search

C.

Cloud Database search

D.

Device Group search

Questions # 22:

An administrator changes the Virus and Spyware Protection policy for a specific group that disables Auto-Protect. The administrator assigns the policy and the client systems apply the corresponding policy serial number. Upon visual inspection of a physical client system, the policy serial number is correct. However, Auto-Protect is still enabled on the client system.

Which action should the administrator take to ensure that the desired setting is in place for the client?

Options:

A.

Restart the client system

B.

Run a command on the computer to Update Content

C.

Enable the padlock next to the setting in the policy

D.

Withdraw the Virus and Spyware Protection policy

Questions # 23:

SES includes an advanced policy versioning system. When an administrator edits and saves the properties of an existing policy, a new version of the policy is created. What is the status of all previous versions of the policy?

Options:

A.

They are marked dormant until reactivated

B.

They are deleted after 30 days

C.

They are active and can be assigned

D.

They are added to the policy archive list

Questions # 24:

Which antimalware intensity level is defined by the following: "Blocks files that are most certainly bad or potentially bad files results in a comparable number of false positives and false negatives."

Options:

A.

Level 6

B.

Level 5

C.

Level 2

D.

Level 1

Questions # 25:

What feature is used to get a comprehensive picture of infected endpoint activity?

Options:

A.

Entity View

B.

Process View

C.

Full Dump

D.

Endpoint Dump

Questions # 26:

A file has been identified as malicious.

Which feature of SEDR allows an administrator to manually block a specific file hash?

Options:

A.

Playbooks

B.

Quarantine

C.

Allow List

D.

Block List

Questions # 27:

Which of the following is a benefit of choosing a hybrid SES Complete architecture?

Options:

A.

The ability to use the cloud EDR functionality

B.

The ability to manage legacy clients running an embedded OS

C.

The ability to manage Active Directory group structure without Azure

D.

The ability to use Adaptive Protection features

Questions # 28:

What does a medium-priority incident indicate?

Options:

A.

The incident may have an impact on the business

B.

The incident can result in a business outage

C.

The incident does not affect critical business operation

D.

The incident can safely be ignored

Questions # 29:

What version number is assigned to a duplicated policy?

Options:

A.

The original policy's version number

B.

Zero

C.

The original policy's number plus one

D.

One

Questions # 30:

What EDR feature provides endpoint activity recorder data for a file hash?

Options:

A.

Process Dump

B.

Entity Dump

C.

Hash Dump

D.

Full Dump

Viewing page 3 out of 5 pages
Viewing questions 21-30 out of questions
TOP CODES

TOP CODES

Top selling exam codes in the certification world, popular, in demand and updated to help you pass on the first try.