Leads4pass > Symantec > Symantec Certified Specialist > 250-441 > 250-441 Online Practice Questions and Answers

250-441 Online Practice Questions and Answers

Questions 4

What are two policy requirements for using the Isolate and Rejoin features in ATP? (Choose two.)

A. Add a Quarantine firewall policy for non-compliant and non-remediated computers.

B. Add a Quarantine LiveUpdate policy for non-compliant and non-remediated computers.

C. Add and assign an Application and Device Control policy in the Symantec Endpoint Protection Manager (SEPM).

D. Add and assign a Host Integrity policy in the Symantec Endpoint Protection Manager (SEPM).

E. Add a Quarantine Antivirus and Antispyware policy for non-compliant and non-remediated computers.

Buy Now
Questions 5

Which best practice does Symantec recommend with the Endpoint Detection and Response feature?

A. Create a unique Cynic account to provide to ATP

B. Create a unique Symantec Messaging Gateway account to provide to ATP

C. Create a unique Symantec Endpoint Protection Manager (SEPM) administrator account to provide to ATP

D. Create a unique Email Security.cloud portal account to provide to ATP

Buy Now
Questions 6

Where can an Incident Responder view Cynic results in ATP?

A. Events

B. Dashboard

C. File Details

D. Incident Details

Buy Now
Questions 7

An Incident Responder notices traffic going from an endpoint to an IRC channel. The endpoint is listed in an incident. ATP is configured in TAP mode.

What should the Incident Responder do to stop the traffic to the IRC channel?

A. Isolate the endpoint with a Quarantine Firewall policy

B. Blacklist the IRC channel IP

C. Blacklist the endpoint IP

D. Isolate the endpoint with an application control policy

Buy Now
Questions 8

Which two widgets can an Incident Responder use to isolate breached endpoints from the Incident details page? (Choose two.)

A. Affected Endpoints

B. Dashboard

C. Incident Graph

D. Events View

E. Actions Bar

Buy Now
Questions 9

Which stage of an Advanced Persistent Threat (APT) attack do attackers map an organization's defenses from the inside?

A. Discovery

B. Capture

C. Exfiltration

D. Incursion

Buy Now
Questions 10

Which default port does ATP use to communicate with the Symantec Endpoint Protection Manager (SEPM) web services?

A. 8446

B. 8081

C. 8014

D. 1433

Buy Now
Questions 11

What are the prerequisite products needed when deploying ATP: Endpoint, Network, and Email?

A. SEP and Symantec Messaging Gateway

B. SEP, Symantec Email Security.cloud, and Security Information and Event Management (SIEM)

C. SEP and Symantec Email Security.cloud

D. SEP, Symantec Messaging Gateway, and Symantec Email Security.cloud

Buy Now
Questions 12

Which threat is an example of an Advanced Persistent Threat (APT)?

A. ILOVEYOU

B. Conficker

C. MyDoom

D. GhostNet

Buy Now
Questions 13

Which level of privilege corresponds to each ATP account type? Match the correct account type to the corresponding privileges.

Select and Place:

Buy Now
Exam Code: 250-441
Exam Name: Administration of Symantec Advanced Threat Protection 3.0
Last Update: Dec 18, 2024
Questions: 95
10%OFF Coupon Code: SAVE10

PDF (Q&A)

$49.99

VCE

$55.99

PDF + VCE

$65.99