Summer Certification Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = getmirror

Pass the Trend Micro Deep Security Deep-Security-Professional Questions and answers with ExamsMirror

Practice at least 50% of the questions to maximize your chances of passing.
Exam Deep-Security-Professional Premium Access

View all detail and faqs for the Deep-Security-Professional exam


741 Students Passed

97% Average Score

97% Same Questions
Viewing page 2 out of 3 pages
Viewing questions 11-20 out of questions
Questions # 11:

Which of the following statements is true regarding the Intrusion Prevention Protection Module?

Options:

A.

The Intrusion Prevention Protection Module blocks or allows traffic based on header information within data packets.

B.

The Intrusion Prevention Protection Module analyzes the payload within incoming and outgoing data packets to identify content that can signal an attack.

C.

The Intrusion Prevention Protection Module can identify changes applied to protected objects, such as the Hosts file, or the Windows Registry.

D.

The Intrusion Prevention Protection Module can prevent applications from executing, allowing an organization to block unallowed software.

Questions # 12:

Which of the following statements is true regarding Deep Security Relays?

Options:

A.

Both 32-bit and 64-bit Deep Security Agents can be promoted to a Deep Security Relay.

B.

Deep Security Agents promoted to Deep Security Relays no longer provide the security capabilities enabled by the Protection Modules.

C.

Deep Security Relays are able to process Deep Security Agent requests during updates.

D.

Deep Security Agents communicate with Deep Security Relays to obtain security updates.

Questions # 13:

Based on the details of event displayed in the exhibit, which of the following statements is false?

Question # 13

Options:

A.

You can instruct the Deep Security Agents and Appliances to block traffic from the source IP address for a period of time.

B.

You can create a firewall rule to permanently block traffic from the originating IP ad-dress.

C.

The scan may be generated from an IP address which may be known to you. If so, the source IP address can be added to the reconnaissance whitelist.

D.

The Intrusion Prevention Protection Modules must be enabled to detect reconnaissance scans.

Questions # 14:

Which of the following correctly identifies the order of the steps used by the Web Reputation Protection Module to determine if access to a web site should be allowed?

Options:

A.

Checks the cache. 2. Checks the Deny list. 3. Checks the Approved list. 4. If not found in any of the above, retrieves the credibility score from Rating Server. 5. Evaluates the credibility score against the Security Level to determine if access to the web site should be allowed.

B.

Checks the cache. 2. Checks the Approved list. 3. Checks the Deny list. 4. If not found in any of the above, retrieves the credibility score from the Rating Server. 5. Evaluates the credibility score against the Security Level to determine if access to the web site should be allowed.

C.

Checks the Deny list. 2. Checks the Approved list. 3. Checks the cache. 4. If not found in any of the above, retrieves the credibility score from Rating Server. 5. Evaluates the credibility score against the Security Level to determine if access to the web site should be allowed.

D.

Checks the Approved list. 2. Checks the Deny list. 3. Checks the cache. 4. If not found in any of the above, retrieves the credibility score from the Rating Server. 5. Evaluates the credibility score against the Security Level to determine if access to the web site should be allowed.

Questions # 15:

The maximum disk space limit for the Identified Files folder is reached. What is the expected Deep Security Agent behavior in this scenario?

Options:

A.

Any existing files are in the folder are compressed and forwarded to Deep Security Manager to free up disk space.

B.

Deep Security Agents will delete any files that have been in the folder for more than 60 days.

C.

Files will no longer be able to be quarantined. Any new files due to be quarantined will be deleted instead.

D.

Deep Security Agents will delete the oldest files in this folder until 20% of the allocated space is available.

Questions # 16:

Policies in Deep Security can include a Context value. Which of the following statements re-garding Context is correct?

Options:

A.

The Context provides Deep Security Agents with location awareness and are associated with Anti-Malware and Web Reputation Rules.

B.

The Context provides Deep Security Agents with location awareness and are associated with Firewall and Intrusion Prevention Rules.

C.

The Context provides Deep Security Agents with location awareness and are associated with Web Reputation Rules only.

D.

The Context provides Deep Security Agents with location awareness and are associated with Log Inspection and Integrity Monitoring Rules.

Questions # 17:

The Security Level for Web Reputation in a policy is set to High. A server assigned this policy attempts to access a Web site with a credibility score of 78.

What is the result?

Options:

A.

The Deep Security Agent allows access to the Web site, and logs the connection attempt as an Event.

B.

The Deep Security Agent allows access as the credibility score for the Web site is above the allowed threshold.

C.

The Deep Security Agent blocks access as the credibility score for the Web site is below the allowed threshold. An error page is displayed in the Web browser.

D.

The Deep Security Agent displays a warning message as the site is unrated.

Questions # 18:

Which of the following is NOT an operation that can be performed on Deep Security resources using the API?

Options:

A.

GET

B.

PUT

C.

VIEW

D.

POST

Questions # 19:

Your organization would like to implement a mechanism to alert administrators when files on a protected servers are modified or tampered with. Which Deep Security Protection Module should you enable to provide this functionality?

Options:

A.

The Integrity Monitoring Protection Module

B.

The File Inspection Protection Module

C.

Deep Security can not provide this type of functionality

D.

The Intrusion Prevention Protection Module

Questions # 20:

A collection of servers protected by Deep Security do not have Internet access. How can Smart Scan be used on these computers?

Options:

A.

Install a Smart Protection Server in the environment and set it as the source for File Reputation information.

B.

Smart Scan must contact the Smart Protection Network to function. Any servers without Internet access will be unable to use Smart Scan.

C.

Promote one of the Deep Security Agents on the air gapped computers to become a Relay.

D.

Smart Scan can be configured to use a local pattern file containing the same information as the Smart Protection Network.

Viewing page 2 out of 3 pages
Viewing questions 11-20 out of questions
TOP CODES

TOP CODES

Top selling exam codes in the certification world, popular, in demand and updated to help you pass on the first try.