Winter Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: geek65

250-441 Administration of Symantec Advanced Threat Protection 3.0 Questions and Answers

Questions 4

Which endpoint detection method allows for information about triggered processes to be displayed in ATP?

Options:

A.

SONAR

B.

Insight

C.

System Lockdown

D.

Antivirus

Buy Now
Questions 5

Which prerequisite is necessary to extend the ATP: Network solution service in order to correlate email

detections?

Options:

A.

Email Security.cloud

B.

Web security.cloud

C.

Skeptic

D.

Symantec Messaging Gateway

Buy Now
Questions 6

Which threat is an example of an Advanced Persistent Threat (APT)?

Options:

A.

Loyphish

B.

Aurora

C.

ZeroAccess

D.

Michelangelo

Buy Now
Questions 7

What are the prerequisite products needed when deploying ATP: Endpoint, Network, and Email?

Options:

A.

SEP and Symantec Messaging Gateway

B.

SEP, Symantec Email Security.cloud, and Security Information and Event Management (SIEM)

C.

SEP and Symantec Email Security.cloud

D.

SEP, Symantec Messaging Gateway, and Symantec Email Security.cloud

Buy Now
Questions 8

An organization recently deployed ATP and integrated it with the existing SEP environment. During an outbreak, the Incident Response team used ATP to isolate several infected endpoints. However, one of the endpoints could NOT be isolated.

Which SEP protection technology is required in order to use the Isolate and Rejoin features in ATP?

Options:

A.

Intrusion Prevention

B.

Firewall

C.

SONAR

D.

Application and Device Control

Buy Now
Questions 9

Which two widgets can an Incident Responder use to isolate breached endpoints from the Incident details

page? (Choose two.)

Options:

A.

Affected Endpoints

B.

Dashboard

C.

Incident Graph

D.

Events View

E.

Actions Bar

Buy Now
Questions 10

An Incident Responder discovers an incident where all systems are infected with a file that has the same name and different hash. As a result, the organism view has multiple entries for the malicious file.

What is causing this issue?

Options:

A.

This is a polymorphic threat

B.

This is a DDoS attack

C.

The file has multiple hashes

D.

The file is trying to phone home

Buy Now
Questions 11

Which SEP technology does an Incident Responder need to enable in order to enforce blacklisting on an

endpoint?

Options:

A.

System Lockdown

B.

Intrusion Prevention System

C.

Firewall

D.

SONAR

Buy Now
Questions 12

How should an ATP Administrator configure Endpoint Detection and Response according to Symantec best practices for a SEP environment with more than one domain?

Options:

A.

Create a unique Symantec Endpoint Protection Manager (SEPM) domain for ATP

B.

Create an ATP manager for each Symantec Endpoint Protection Manager (SEPM) domain

C.

Create a Symantec Endpoint Protection Manager (SEPM) controller connection for each domain

D.

Create a Symantec Endpoint Protection Manager (SEPM) controller connection for the primary domain

Buy Now
Questions 13

Why is it important for an Incident Responder to analyze an incident during the Recovery phase?

Options:

A.

To determine the best plan of action for cleaning up the infection

B.

To isolate infected computers on the network and remediate the threat

C.

To gather threat artifacts and review the malicious code in a sandbox environment

D.

To access the current security plan, adjust where needed, and provide reference materials in the event of a similar incident

Buy Now
Questions 14

What impact does changing from Inline Block to SPAN/TAP mode have on blacklisting in ATP?

Options:

A.

ATP will continue to block previously blacklisted addresses but NOT new ones.

B.

ATP does NOT block access to blacklisted addresses unless block mode is enabled.

C.

ATP will clear the existing blacklists.

D.

ATP does NOT block access to blacklisted addresses unless TAP mode is enabled.

Buy Now
Exam Code: 250-441
Exam Name: Administration of Symantec Advanced Threat Protection 3.0
Last Update: Nov 21, 2024
Questions: 96
250-441 pdf

250-441 PDF

$28  $80
250-441 Engine

250-441 Testing Engine

$33.25  $95
250-441 PDF + Engine

250-441 PDF + Testing Engine

$45.5  $130