Symantec 250-587 Symantec Data Loss Prevention 16.x Administration Technical Specialist Exam Practice Test
Symantec Data Loss Prevention 16.x Administration Technical Specialist Questions and Answers
Why would an administrator set the Similarity Threshold to zero when testing and tuning a Vector Machine Learning (VML) profile?
Which two technologies should an organization utilize for integration with the Network Prevent products? (choose two.)
A DLP administrator has added several approved endpoint devices as exceptions to an Endpoint Prevent policy that blocks the transfer of sensitive data. However, data transfers to these devices are still being blocked.
What is the first action an administrator should take to enable data transfers to the approved endpoint devices?
Where in the Enforce management console can a DLP administrator change the “UI.NO_SCAN.int” setting to disable the “Inspecting data” pop-up?
What should an incident responder select in the Enforce management console to remediate multiple incidents simultaneously?
Which two locations can Symantec DLP scan and perform Information Centric Encryption (ICE) actions on? (Choose two.)
Refer to the exhibit.
What activity should occur during the baseline phase, according to the risk reduction model?
Which network Prevent action takes place when the network Incident list shows the message is “Modified”?
An administrator is unable to log in to the Enforce management console as “sysadmin”. Symantec DLP is configured to use Active Directory authentication. The administrator is a member of two roles: “sysadmin” and “remediator.”
How should the administrator log in to the Enforce console with the “sysadmin” role?
A company needs to secure the content of all mergers and Acquisitions Agreements/ However, the standard text included in all company literature needs to be excluded.
How should the company ensure that this standard text is excluded from detection?
A DLP administrator created a new agent configuration for an Endpoint server. However, the endpoint agents fail to receive the new configuration.
What is one possible reason that the agent fails to receive the new configuration?
Which Network Prevent action has taken place when a Network incident snapshot indicates the message has been “Modified”?
Which two components can perform a file system scan of a workstation? (Choose two.)
Refer to the exhibit. Which type of Endpoint response rule is shown?
Which two detection technology options ONLY run on a detection server? (Choose two.)
How should a DLP administrator change a policy so that it retains the original file when an endpoint incident has detected a “cope to USB device” operation?
Which of the following is a good use case for Structured Data Identifiers (SDIs)?
Which two DLP products support the new Optical Character Recognition (OCR) engine in Symantec DLP 15.0? (Choose two.)
What is the correct order for data in motion when a customer has integrated their CloudSOC and DLP solutions?
A DLP administrator needs to stop the PacketCapture process on a detection server. Upon inspection of the Server Detail page, the administrator discovers that all processes are missing from the display.
What are the processes missing from the Server Detail page display?
How should a DLP administrator exclude a custom endpoint application named “custom_app.exe” from being monitored by Application File Access Control?
Under the “System Overview” in the Enforce management console, the status of a Network Monitor detection server is shown as “Running Selected.” The Network Monitor server’s event logs indicate that the packet capture and filereader processes are crashing.
What is a possible cause for the Network Monitor server being in this state?
Which two Infrastructure-as-a-Service providers are supported for hosting Cloud Prevent for Office 365? (Choose two.)
Which action is available for use in both Smart Response and Automated Response rules?
What is the correct installation sequence for the components shown here, according to the Symantec Installation Guide?
Place the options in the correct installation sequence.
Which option correctly describes the two-tier installation type for Symantec DLP?
A DLP administrator has performed a test deployment of the DLP 15.0 Endpoint agent and now wants to uninstall the agent. However, the administrator no longer remembers the uninstall password.
What should the administrator do to work around the password problem?
In the context of Network Discover scanning of Exchange servers, what is the Exchange Autodiscover service?
A DLP administrator needs to remove an agent its associated events from an Endpoint server.
Which Agent Task should the administrator perform to disable the agent’s visibility in the Enforce management console?
What detection method utilizes Data Identifiers?
What detection server is used for Network Discover, Network Protect, and Cloud Storage?
A DLP administrator is attempting to add a new Network Discover detection server from the Enforce management console. However, the only available options are Network Monitor and Endpoint servers.
What should the administrator do to make the Network Discover option available?
