Broadcom Symantec Endpoint Security Complete Admin R1.4 Technical Specialist - 250-604 Exam Practice Test
Which two functions does the SES Complete Heatmap provide to administrators? (Choose two)
Correct Answer: B,D
Vote an answer
What benefit does ICDm provide when managing remote endpoints?
Correct Answer: D
Vote an answer
Scenario:
A suspicious alert has appeared across multiple endpoints, originating from a shared file server. As part of the EDR response workflow, you need to confirm whether all devices interacted with the same suspicious file.
Which ICDm feature is best suited to identify and correlate this activity?
A suspicious alert has appeared across multiple endpoints, originating from a shared file server. As part of the EDR response workflow, you need to confirm whether all devices interacted with the same suspicious file.
Which ICDm feature is best suited to identify and correlate this activity?
Correct Answer: C
Vote an answer
Which SES Policy protects against port scan detections?
Correct Answer: A
Vote an answer
Which report format is supported in Symantec Endpoint Security?
Correct Answer: B
Vote an answer
Scenario:
An enterprise security team notices that several users have recently accessed resources they typically do not use. TDAD has raised alerts regarding credential misuse and suspicious lateral movement patterns.
Which two actions should the team take using SES Complete? (Choose two)
An enterprise security team notices that several users have recently accessed resources they typically do not use. TDAD has raised alerts regarding credential misuse and suspicious lateral movement patterns.
Which two actions should the team take using SES Complete? (Choose two)
Correct Answer: B,C
Vote an answer
How does EDR aid in investigating the lateral movement of threats across endpoints in a network?
Correct Answer: B
Vote an answer
Which policy feature can assist in tracking changes over time and debugging misconfigurations?
Correct Answer: B
Vote an answer
When analyzing suspicious files using EDR, how are files typically submitted for deeper inspection?
Correct Answer: A
Vote an answer
Which features contribute to blocking data exfiltration in SES Complete? (Choose two)
Correct Answer: A,C
Vote an answer
What benefit does behavioral tuning offer in the context of App Control and reducing the endpoint attack surface?
Correct Answer: A
Vote an answer
How can EDR assist security administrators in distinguishing between suspicious and confirmed malicious activity?
Correct Answer: B
Vote an answer
Which monitoring techniques are used by Threat Defense for Active Directory to identify potentially malicious behaviors in AD environments? (Choose two)
Correct Answer: A,D
Vote an answer
What does SES Complete do to block Command & Control (C2) communication attempts?
Correct Answer: A
Vote an answer
How does the Endpoint Activity Recorder assist with threat investigation in EDR?
Correct Answer: C
Vote an answer