Get Jul-2023 Download Latest & Valid Questions For Symantec 250-561 exam [Q38-Q59]

Share

Get Jul-2023 Download Latest & Valid Questions For Symantec 250-561 exam

Ensure Success With Updated Verified 250-561 Exam Dumps

NEW QUESTION # 38
An administrator is evaluating an organization's computers for an upcoming SES deployment. Which computer meets the pre-requisites for the SES client?

  • A. A computer running Windows 10 with 400 MB of disk space, 2 GB of RAM, and a 2.4 GHz Intel Pentium 4 processor
  • B. A computer running Mac OS X 10.14 with 400 MB of disk space, 4 GB of RAM, and an Intel Core 2 Duo 64-bit processor
  • C. A computer running Windows 8 with 380 MB of disk space, 2 GB of RAM, and a 2.8 GHz Intel Pentium 4 processor
  • D. A computer running Mac OS X 10.8 with 500 MB of disk space, 4 GB of RAM, and an Intel Core 2 Duo 64-bit processor

Answer: A


NEW QUESTION # 39
Files are blocked by hash in the blacklist policy.
Which algorithm is supported, in addition to MD5?

  • A. SHA256
  • B. MD5 "Salted"
  • C. SHA256 "salted"
  • D. SHA2

Answer: A


NEW QUESTION # 40
What should an administrator know regarding the differences between a Domain and a Tenant in ICDm?

  • A. A tenant can contain multiple domains
  • B. Each customer can have one domain and many tenant
  • C. A domain can contain multiple tenants
  • D. Each customer can have one tenant and many domains

Answer: A


NEW QUESTION # 41
In which phase of MITRE framework would attackers exploit faults in software to directly tamper with system memory?

  • A. Exfiltration
  • B. Defense Evasion
  • C. Execution
  • D. Discovery

Answer: B


NEW QUESTION # 42
A user downloads and opens a PDF file with Adobe Acrobat. Unknown to the user, a hidden script in the file begins downloading a RAT.
Which Anti-malware engine recognizes that this behavior is inconsistent with normal Acrobat functionality, blocks the behavior and kills Acrobat?

  • A. Emulator
  • B. IPS
  • C. Sapient
  • D. SONAR

Answer: C


NEW QUESTION # 43
What characterizes an emerging threat in comparison to traditional threat?

  • A. Emerging threats requires artificial intelligence to be detected.
  • B. Emerging threats are more sophisticated than traditional threats.
  • C. Emerging threats are undetectable by signature based engines.
  • D. Emerging threats use new techniques and 0-day vulnerability to propagate.

Answer: D


NEW QUESTION # 44
An administrator suspects that several computers have become part of a botnet. What should the administrator do to detect botnet activity on the network?

  • A. Enable the IPS policy's Show notification on the device setting
  • B. Add botnet related signatures to the IPS policy's Audit Signatures list
  • C. Enable the Command and Control Server Firewall
  • D. Set the Antimalware policy's Monitoring Level to 4

Answer: C


NEW QUESTION # 45
Which policy should an administrator edit to utilize the Symantec LiveUpdate server for pre-release content?

  • A. The LiveUpdate Policy
  • B. The System Schedule Policy
  • C. The System Policy
  • D. The Firewall Policy

Answer: A


NEW QUESTION # 46
Which rule types should be at the bottom of the list when an administrator adds device control rules?

  • A. Specific "device model" rules
  • B. General "brand defined" rules
  • C. Specific "device type" rules
  • D. General "catch all" rules

Answer: A


NEW QUESTION # 47
Which two (2) scan range options are available to an administrator for locating unmanaged endpoints? (Select two)

  • A. Entire Network
  • B. IP range within subnet
  • C. IP range within network
  • D. Subnet Range
  • E. Entire Subnet

Answer: C,D


NEW QUESTION # 48
Which two (2) Discovery and Deploy features could an administrator use to enroll MAC endpoints? (Select two)

  • A. A default Direct Installation package
  • B. Invite User
  • C. A custom Direct installation package
  • D. A custom Installation package creator pact
  • E. Push Enroll

Answer: C,D


NEW QUESTION # 49
An endpoint is offline, and the administrator issues a scan command. What happens to the endpoint when it restarts, if it lacks connectivity?

  • A. The system starts without scanning.
  • B. The system is scanning when started.
  • C. The system scans after the content update is downloaded.
  • D. The system downloads the content without scanning.

Answer: D


NEW QUESTION # 50
An endpoint fails to retrieve content updates.
Which URL should an administrator test in a browser to determine if the issue is network related?

  • A. http://update.symantec.com/livetri.zip
  • B. https://liveupdate.symantec,com/livetri.zi
  • C. https://spocsymantec.com/livetri.zip
  • D. https://update.symantec.com/livetri.zip

Answer: C


NEW QUESTION # 51
What option must an administrator choose when rolling back a policy assignment to a previous version?

  • A. Override
  • B. Customize
  • C. Reverse
  • D. Go Back

Answer: A


NEW QUESTION # 52
What are two (2) benefits of a fully cloud managed endpoint protection solution? (Select two)

  • A. Increased visibility
  • B. Increased content update frequency
  • C. Reduced network usage
  • D. Reduced database usage
  • E. Reduced 3rd party licensing cost

Answer: D,E


NEW QUESTION # 53
An administrator learns of a potentially malicious file and wants to proactively prevent the file from ever being executed.
What should the administrator do?

  • A. Increase the Antimalware policy Intensity to Level 5
  • B. Add the filename and SHA-256 hash to a Blacklist policy
  • C. Adjust the Antimalware policy age and prevalence settings
  • D. Add the file SHA1 to a blacklist policy

Answer: C


NEW QUESTION # 54
Which statement best describes Artificial Intelligence?

  • A. A program that can predict when a task should be performed
  • B. A program that automates tasks with a static set of instructions
  • C. A program that is autonomous and needs training to perform a task
  • D. A program that learns from experience and perform autonomous tasks

Answer: B


NEW QUESTION # 55
Which Firewall Stealth setting prevents OS fingerprinting by sending erroneous OS information back to the attacker?

  • A. Disable OS fingerprint profiling
  • B. Disable OS fingerprint detection
  • C. Enable OS fingerprint masqueradi
  • D. Enable OS fingerprint protection

Answer: C


NEW QUESTION # 56
Which default role has the most limited permission in the Integrated Cyber Defense Manager?

  • A. Endpoint Console Domain Administrator
  • B. Restricted Administrator
  • C. Limited Administrator
  • D. Server Administrator

Answer: D


NEW QUESTION # 57
Which framework, open and available to any administrator, is utilized to categorize adversarial tactics and for each phase of a cyber attack?

  • A. MITRE ATT&CK
  • B. MITRE ADV&NCE
  • C. MITRE RESPONSE
  • D. MITRE ATTACK MATRIX

Answer: B


NEW QUESTION # 58
Which SES security control protects against threats that may occur in the Impact phase?

  • A. Firewall
  • B. Antimalware
  • C. Device Control
  • D. IPS

Answer: A


NEW QUESTION # 59
......

Exam Materials for You to Prepare & Pass 250-561 Exam: https://www.prepawaypdf.com/Symantec/250-561-practice-exam-dumps.html

Pass Your 250-561 Exam at the First Try with 100% Real Exam: https://drive.google.com/open?id=1tQISXCwfwzD8MkNoR7qvdg1Xyx3F4VGU