Exam 2: Administration of Symantec Email Security.cloud (v1)

arrow
  • Select Tags
search iconSearch Question
flashcardsStudy Flashcards
  • Select Tags

A Symantec Endpoint Protection administrator is using System Lockdown in blacklist mode with a file fingerprint list. When testing a client, the administrator notices that at least one of the files is allowed to execute. What is the likely cause of the problem?

(Multiple Choice)
4.8/5
(34)

An administrator is responsible for the Symantec Endpoint Protection architecture of a large, multi-national company with three regionalized data centers. The administrator needs to collect data from clients; however, the collected data must stay in the local regional data center. Communication between the regional data centers is allowed 20 hours a day. How should the administrator architect this organization?

(Multiple Choice)
4.9/5
(34)

Where in the Symantec Endpoint Protection (SEP) management console will a SEP administrator find the option to allow all users to enable and disable the client firewall?

(Multiple Choice)
4.8/5
(37)

Which action does SONAR take before convicting a process?

(Multiple Choice)
4.8/5
(34)

An administrator is reviewing an Infected Clients Report and notices that a client repeatedly shows the same malware detection. Although the client remediates the files, the infection continues to display in the logs. Which two functions should be enabled to automate enhanced remediation of a detected threat and its related side effects? (Select two.)

(Multiple Choice)
4.8/5
(40)

What Symantec Endpoint Protection component facilitates distributing content clients that have a poor connection to the Symantec Endpoint Protection Manager (SEPM)?

(Multiple Choice)
4.7/5
(36)

Which content distribution method can distribute content to all client types and provides validation scheduling?

(Multiple Choice)
4.9/5
(41)

Which two criteria could be used to define Location Awareness for the Symantec Endpoint Protection (SEP) client? (Choose two.)

(Multiple Choice)
4.8/5
(32)

What two steps should an administrator take to troubleshoot firewall processing with the Symantec Endpoint Protection client? (Choose two.)

(Multiple Choice)
5.0/5
(40)

A Symantec Endpoint Protection (SEP) client uses a management server list with three management servers in the priority 1 list. Which mechanism does the SEP client use to select an alternate management server if the currently selected management server is unavailable?

(Multiple Choice)
4.9/5
(30)

What does SONAR use to reduce false positives?

(Multiple Choice)
4.8/5
(37)

An organization created a rule in the Application and Device Control policy to block peer-to-peer applications. What two other protection technologies can block and log such unauthorized application? (Choose two.)

(Multiple Choice)
4.9/5
(33)

An administrator changes the Virus and Spyware Protection policy for a specific group that disables Auto-Protect. The administrator assigns the policy and the client systems apply the corresponding policy serial number. Upon visual inspection of a physical client system, the policy serial number is correct. However, Auto-Protect is still enabled on the client system. Which action should the administrator take to ensure that the desired setting is in place on the client?

(Multiple Choice)
4.7/5
(32)
Showing 101 - 113 of 113
close modal

Filters

  • Essay(0)
  • Multiple Choice(0)
  • Short Answer(0)
  • True False(0)
  • Matching(0)