
[Jan-2022] Symantec SCS Certification 250-550 Exam Practice Dumps
2022 250-550 Premium Files Test pdf - Free Dumps Collection
NEW QUESTION 32
What happens when an administrator blacklists a file?
- A. The file is assigned to the Blacklist task list
- B. The file is automatically quarantined
- C. The file is assigned to a chosen Blacklist policy
- D. The file is assigned to the default Blacklist policy
Answer: A
NEW QUESTION 33
An administrator must create a custom role in ICDm.
Which area of the management console is able to have access restricted or granted?
- A. Agent deployment
- B. Hybrid device management
- C. Policy Management
- D. Custom Dashboard Creation
Answer: A
NEW QUESTION 34
Why would an administrator choose the Server-optimized installation option when creating an installation package?
- A. To add the SES client's Optimize Memory setting to the default server installation.
- B. To reduce the SES client's using resources that are required for other server-specific processes.
- C. To limit the Intrusion Prevention policy to use server-only signatures.
- D. To add the Server-optimized Firewall policy
Answer: C
NEW QUESTION 35
An administrator is evaluating an organization's computers for an upcoming SES deployment. Which computer meets the pre-requisites for the SES client?
- A. A computer running Mac OS X 10.8 with 500 MB of disk space, 4 GB of RAM, and an Intel Core 2 Duo 64-bit processor
- B. A computer running Windows 10 with 400 MB of disk space, 2 GB of RAM, and a 2.4 GHz Intel Pentium 4 processor
- C. A computer running Mac OS X 10.14 with 400 MB of disk space, 4 GB of RAM, and an Intel Core 2 Duo 64-bit processor
- D. A computer running Windows 8 with 380 MB of disk space, 2 GB of RAM, and a 2.8 GHz Intel Pentium 4 processor
Answer: B
NEW QUESTION 36
An administrator suspects that several computers have become part of a botnet. What should the administrator do to detect botnet activity on the network?
- A. Add botnet related signatures to the IPS policy's Audit Signatures list
- B. Enable the IPS policy's Show notification on the device setting
- C. Enable the Command and Control Server Firewall
- D. Set the Antimalware policy's Monitoring Level to 4
Answer: C
NEW QUESTION 37
The ICDm has generated a blacklist task due to malicious traffic detection. Which SES component was utilized to make that detection?
- A. Firewall
- B. Reputation
- C. Antimalware
- D. IPS
Answer: C
NEW QUESTION 38
Which dashboard should an administrator access to view the current health of the environment?
- A. The SES Dashboard
- B. The Antimalware Dashboard
- C. The Device Integrity Dashboard
- D. The Security Control Dashboard
Answer: D
NEW QUESTION 39
Which device page should an administrator view to track the progress of an issued device command?
- A. Activity Update
- B. Command History
- C. Recent Activity
- D. Command Status
Answer: C
NEW QUESTION 40
An administrator selects the Discovered Items list in the ICDm to investigate a recent surge in suspicious file activity. What should an administrator do to display only high risk files?
- A. Apply a list control
- B. Apply a list filter
- C. Apply a search modifier
- D. Apply a search rule
Answer: D
NEW QUESTION 41
Which default role has the most limited permission in the Integrated Cyber Defense Manager?
- A. Restricted Administrator
- B. Limited Administrator
- C. Server Administrator
- D. Endpoint Console Domain Administrator
Answer: C
NEW QUESTION 42
Which type of organization is likely to be targeted with emerging threats?
- A. Small organization with externalized managed security
- B. Large organizations with dedicated security teams
- C. Small organization with little qualified staff
- D. Large organization with high turnover
Answer: C
NEW QUESTION 43
What characterizes an emerging threat in comparison to traditional threat?
- A. Emerging threats are undetectable by signature based engines.
- B. Emerging threats are more sophisticated than traditional threats.
- C. Emerging threats use new techniques and 0-day vulnerability to propagate.
- D. Emerging threats requires artificial intelligence to be detected.
Answer: C
NEW QUESTION 44
Which statement best describes Artificial Intelligence?
- A. A program that can predict when a task should be performed
- B. A program that is autonomous and needs training to perform a task
- C. A program that learns from experience and perform autonomous tasks
- D. A program that automates tasks with a static set of instructions
Answer: D
NEW QUESTION 45
Which term or expression is utilized when adversaries leverage existing tools in the environment?
- A. file-less attack
- B. script kiddies
- C. opportunistic attack
- D. living off the land
Answer: B
NEW QUESTION 46
What are two (2) benefits of a fully cloud managed endpoint protection solution? (Select two)
- A. Reduced 3rd party licensing cost
- B. Reduced network usage
- C. Increased visibility
- D. Increased content update frequency
- E. Reduced database usage
Answer: A,E
NEW QUESTION 47
An endpoint is offline, and the administrator issues a scan command. What happens to the endpoint when it restarts, if it lacks connectivity?
- A. The system scans after the content update is downloaded.
- B. The system downloads the content without scanning.
- C. The system starts without scanning.
- D. The system is scanning when started.
Answer: B
NEW QUESTION 48
Which rule types should be at the bottom of the list when an administrator adds device control rules?
- A. General "brand defined" rules
- B. Specific "device model" rules
- C. Specific "device type" rules
- D. General "catch all" rules
Answer: B
NEW QUESTION 49
In which phase of MITRE framework would attackers exploit faults in software to directly tamper with system memory?
- A. Discovery
- B. Execution
- C. Defense Evasion
- D. Exfiltration
Answer: C
NEW QUESTION 50
Which framework, open and available to any administrator, is utilized to categorize adversarial tactics and for each phase of a cyber attack?
- A. MITRE RESPONSE
- B. MITRE ATT&CK
- C. MITRE ATTACK MATRIX
- D. MITRE ADV&NCE
Answer: D
NEW QUESTION 51
Which statement best defines Machine Learning?
- A. A program that needs user input to perform a task.
- B. A program that learns from experience to optimize the output of a task.
- C. A program that teams from observing other programs.
- D. A program that require data to perform a task.
Answer: C
NEW QUESTION 52
Which report template includes a summary of risk distribution by devices, users, and groups?
- A. Comprehensive
- B. Device Integrity
- C. Threat Distribution
- D. Weekly
Answer: C
NEW QUESTION 53
Which Symantec component is required to enable two factor authentication with VIP on the Integrated Cyber Defense manager (ICDm)?
- A. A physical token or a software token
- B. A software token and a VIP server
- C. A software token and an active directory account
- D. A physical token or a secure USB key
Answer: B
NEW QUESTION 54
Which alert rule category includes events that are generated about the cloud console?
- A. Application Activity
- B. Security
- C. System
- D. Diagnostic
Answer: B
NEW QUESTION 55
Which Antimalware technology is used after all local resources have been exhausted?
- A. ITCS
- B. Reputation
- C. Sapient
- D. Emulator
Answer: A
NEW QUESTION 56
Which SES feature helps administrator apply policies based on specific endpoint profiles?
- A. Policy Bundles
- B. Policy Groups
- C. Device Profiles
- D. Device Groups
Answer: B
NEW QUESTION 57
......
Get ready to pass the 250-550 Exam right now using our Symantec SCS Certification Exam Package: https://certblaster.prep4away.com/Symantec-certification/braindumps.250-550.ete.file.html