
Get Jul-2023 Download Latest & Valid Questions For Symantec 250-561 exam
Ensure Success With Updated Verified 250-561 Exam Dumps
NEW QUESTION # 38
An administrator is evaluating an organization's computers for an upcoming SES deployment. Which computer meets the pre-requisites for the SES client?
- A. A computer running Windows 10 with 400 MB of disk space, 2 GB of RAM, and a 2.4 GHz Intel Pentium 4 processor
- B. A computer running Mac OS X 10.14 with 400 MB of disk space, 4 GB of RAM, and an Intel Core 2 Duo 64-bit processor
- C. A computer running Windows 8 with 380 MB of disk space, 2 GB of RAM, and a 2.8 GHz Intel Pentium 4 processor
- D. A computer running Mac OS X 10.8 with 500 MB of disk space, 4 GB of RAM, and an Intel Core 2 Duo 64-bit processor
Answer: A
NEW QUESTION # 39
Files are blocked by hash in the blacklist policy.
Which algorithm is supported, in addition to MD5?
- A. SHA256
- B. MD5 "Salted"
- C. SHA256 "salted"
- D. SHA2
Answer: A
NEW QUESTION # 40
What should an administrator know regarding the differences between a Domain and a Tenant in ICDm?
- A. A tenant can contain multiple domains
- B. Each customer can have one domain and many tenant
- C. A domain can contain multiple tenants
- D. Each customer can have one tenant and many domains
Answer: A
NEW QUESTION # 41
In which phase of MITRE framework would attackers exploit faults in software to directly tamper with system memory?
- A. Exfiltration
- B. Defense Evasion
- C. Execution
- D. Discovery
Answer: B
NEW QUESTION # 42
A user downloads and opens a PDF file with Adobe Acrobat. Unknown to the user, a hidden script in the file begins downloading a RAT.
Which Anti-malware engine recognizes that this behavior is inconsistent with normal Acrobat functionality, blocks the behavior and kills Acrobat?
- A. Emulator
- B. IPS
- C. Sapient
- D. SONAR
Answer: C
NEW QUESTION # 43
What characterizes an emerging threat in comparison to traditional threat?
- A. Emerging threats requires artificial intelligence to be detected.
- B. Emerging threats are more sophisticated than traditional threats.
- C. Emerging threats are undetectable by signature based engines.
- D. Emerging threats use new techniques and 0-day vulnerability to propagate.
Answer: D
NEW QUESTION # 44
An administrator suspects that several computers have become part of a botnet. What should the administrator do to detect botnet activity on the network?
- A. Enable the IPS policy's Show notification on the device setting
- B. Add botnet related signatures to the IPS policy's Audit Signatures list
- C. Enable the Command and Control Server Firewall
- D. Set the Antimalware policy's Monitoring Level to 4
Answer: C
NEW QUESTION # 45
Which policy should an administrator edit to utilize the Symantec LiveUpdate server for pre-release content?
- A. The LiveUpdate Policy
- B. The System Schedule Policy
- C. The System Policy
- D. The Firewall Policy
Answer: A
NEW QUESTION # 46
Which rule types should be at the bottom of the list when an administrator adds device control rules?
- A. Specific "device model" rules
- B. General "brand defined" rules
- C. Specific "device type" rules
- D. General "catch all" rules
Answer: A
NEW QUESTION # 47
Which two (2) scan range options are available to an administrator for locating unmanaged endpoints? (Select two)
- A. Entire Network
- B. IP range within subnet
- C. IP range within network
- D. Subnet Range
- E. Entire Subnet
Answer: C,D
NEW QUESTION # 48
Which two (2) Discovery and Deploy features could an administrator use to enroll MAC endpoints? (Select two)
- A. A default Direct Installation package
- B. Invite User
- C. A custom Direct installation package
- D. A custom Installation package creator pact
- E. Push Enroll
Answer: C,D
NEW QUESTION # 49
An endpoint is offline, and the administrator issues a scan command. What happens to the endpoint when it restarts, if it lacks connectivity?
- A. The system starts without scanning.
- B. The system is scanning when started.
- C. The system scans after the content update is downloaded.
- D. The system downloads the content without scanning.
Answer: D
NEW QUESTION # 50
An endpoint fails to retrieve content updates.
Which URL should an administrator test in a browser to determine if the issue is network related?
- A. http://update.symantec.com/livetri.zip
- B. https://liveupdate.symantec,com/livetri.zi
- C. https://spocsymantec.com/livetri.zip
- D. https://update.symantec.com/livetri.zip
Answer: C
NEW QUESTION # 51
What option must an administrator choose when rolling back a policy assignment to a previous version?
- A. Override
- B. Customize
- C. Reverse
- D. Go Back
Answer: A
NEW QUESTION # 52
What are two (2) benefits of a fully cloud managed endpoint protection solution? (Select two)
- A. Increased visibility
- B. Increased content update frequency
- C. Reduced network usage
- D. Reduced database usage
- E. Reduced 3rd party licensing cost
Answer: D,E
NEW QUESTION # 53
An administrator learns of a potentially malicious file and wants to proactively prevent the file from ever being executed.
What should the administrator do?
- A. Increase the Antimalware policy Intensity to Level 5
- B. Add the filename and SHA-256 hash to a Blacklist policy
- C. Adjust the Antimalware policy age and prevalence settings
- D. Add the file SHA1 to a blacklist policy
Answer: C
NEW QUESTION # 54
Which statement best describes Artificial Intelligence?
- A. A program that can predict when a task should be performed
- B. A program that automates tasks with a static set of instructions
- C. A program that is autonomous and needs training to perform a task
- D. A program that learns from experience and perform autonomous tasks
Answer: B
NEW QUESTION # 55
Which Firewall Stealth setting prevents OS fingerprinting by sending erroneous OS information back to the attacker?
- A. Disable OS fingerprint profiling
- B. Disable OS fingerprint detection
- C. Enable OS fingerprint masqueradi
- D. Enable OS fingerprint protection
Answer: C
NEW QUESTION # 56
Which default role has the most limited permission in the Integrated Cyber Defense Manager?
- A. Endpoint Console Domain Administrator
- B. Restricted Administrator
- C. Limited Administrator
- D. Server Administrator
Answer: D
NEW QUESTION # 57
Which framework, open and available to any administrator, is utilized to categorize adversarial tactics and for each phase of a cyber attack?
- A. MITRE ATT&CK
- B. MITRE ADV&NCE
- C. MITRE RESPONSE
- D. MITRE ATTACK MATRIX
Answer: B
NEW QUESTION # 58
Which SES security control protects against threats that may occur in the Impact phase?
- A. Firewall
- B. Antimalware
- C. Device Control
- D. IPS
Answer: A
NEW QUESTION # 59
......
Exam Materials for You to Prepare & Pass 250-561 Exam: https://www.prepawaypdf.com/Symantec/250-561-practice-exam-dumps.html
Pass Your 250-561 Exam at the First Try with 100% Real Exam: https://drive.google.com/open?id=1tQISXCwfwzD8MkNoR7qvdg1Xyx3F4VGU