Summer Sale Special - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: mxmas70

Home > Symantec > Data Loss Prevention > 250-587

250-587 Symantec Data Loss Prevention 16.x Administration Technical Specialist Question and Answers

Question # 4

A customer needs to integrate information from DLP incidents into external Governance, Risk and Compliance dashboards.

Which feature should a third party component integrate with to provide dynamic reporting, create custom incident remediation processes, or support business processes?

A.

Export incidents using the CSV format

B.

Incident Reporting and Update API

C.

Incident Data Views

D.

A Web incident extraction report

Full Access
Question # 5

Which service encrypts the message when using a Modify SMTP Message response rule?

A.

Network Monitor server

B.

SMTP Prevent

C.

Enforce server

D.

Encryption Gateway

Full Access
Question # 6

A compliance officer needs to understand how the company is complying with its data security policies over time.

Which report should be compliance officer generate to obtain the compliance information?

A.

Policy report, filtered on date and summarized by policy

B.

Policy Trend report, summarized by policy, then quarter

C.

Policy report, filtered on quarter and summarized by policy

D.

Policy Trend report, summarized by policy, then severity

Full Access
Question # 7

When Symantec DLP and Symantec CloudSOC are integrated, what must you configure in Enforce to tell CloudSOC which traffic or content to send to the Cloud Detection Service for analysis?

A.

DLP policies with CloudSOC-specific detection rules and response rules

B.

Cloud Detection Service traffic settings on the Servers and Detectors Overview page

C.

Traffic settings in the Agent Configuration for endpoint computers running the WSS Agent

D.

One or more Application Detection Configurations that include Gatelet and Securlet settings

Full Access
Question # 8

Which two (2) detection technology options run ONLY on detection servers and NOT on endpoint agents? (Choose two.)

A.

Indexed Document Matching (IDM)

B.

Vector Machine Learning (VML)

C.

Described Content Matching (DCM)

D.

Exact Data Matching (EDM)

E.

Form Recognition

Full Access
Question # 9

Which type of detector integrates with Symantec CloudSOC?

A.

Cloud Detection Service for REST

B.

Cloud Detection Service for ICAP

C.

Cloud Detection Service for SMTP

D.

Cloud Prevent detector

Full Access
Question # 10

What are two reasons an administrator should utilize a manual configuration to determine the endpoint location? (Choose two.)

A.

To specify Wi-Fi SSID names

B.

To specify an IP address or range

C.

To specify the endpoint server

D.

To specify domain names

E.

To specify network card status (ON/OFF)

Full Access
Question # 11

A DLP administrator created a new agent configuration for an Endpoint server. However, the endpoint agents fail to receive the new configuration.

What is one possible reason that the agent fails to receive the new configuration?

A.

The default agent configuration must be disabled before the new configuration can be assigned.

B.

The Endpoint server needs to be recycled so that the new agent configuration can take effect.

C.

The new agent configuration was saved but not applied to any endpoint groups.

D.

The new agent configuration was copied and modified from the default agent configuration.

Full Access
Question # 12

Which two automated response rules will be active in policies that include Exact Data Matching (EDM) detection rule? (Choose two.)

A.

Endpoint Discover: Quarantine File

B.

All: Send Email Notification

C.

Endpoint Prevent: User Cancel

D.

Endpoint Prevent: Block

E.

Network Protect: Quarantine File

Full Access
Question # 13

Which two locations can Symantec DLP scan and perform Information Centric Encryption (ICE) actions on? (Choose two.)

A.

Exchange

B.

Jiveon

C.

File store

D.

SharePoint

E.

Confluence

Full Access
Question # 14

Which two detection technology options run on the DLP agent? (Choose two.)

A.

Optical Character Recognition (OCR)

B.

Described Content Matching (DCM)

C.

Directory Group Matching (DGM)

D.

Form Recognition

E.

Indexed Document Matching (IDM)

Full Access
Question # 15

How should a DLP administrator exclude a custom endpoint application named “custom_app.exe” from being monitoring by Application File Access Control?

A.

Add “custom_app.exe” to the “Application Whitelist” on all Endpoint servers.

B.

Add “custom_app.exe” Application Monitoring Configuration and de-select all its channel options.

C.

Add “custom_app_.exe” as a filename exception to the Endpoint Prevent policy.

D.

Add “custom_app.exe” to the “Program Exclusion List” in the agent configuration settings.

Full Access
Question # 16

Which two (2) detection servers are available as virtual appliances? (Choose two.)

A.

Network Prevent for Email

B.

Network Monitor

C.

Network Discover

D.

Network Prevent for Web

E.

Optical Character Recognition (OCR)

Full Access
Question # 17

What is the recommended ratio of Enforce servers to Oracle database servers when deploying Symantec DLP?

A.

1:1

B.

1:2

C.

2:1

D.

3:1

Full Access
Question # 18

Which two (2) detection technology options run on the DLP agent? (Choose two.)

A.

Indexed Document Matching (IDM)

B.

Directory Group Matching (DGM)

C.

Described Content Matching (DCM)

D.

Optical Character Recognition (OCR)

E.

Form Recognition

Full Access
Question # 19

A DLP administrator determines that the \SymantecDLP\Protect\Incidents folder on the Enforce server contains. BAD files dated today, while other. IDC files are flowing in and out of the \Incidents directory. Only .IDC files larger than 1MB are turning to .BAD files.

What could be causing only incident data smaller than 1MB to persist while incidents larger than 1MB change to .BAD files?

A.

A corrupted policy was deployed.

B.

The Enforce server’s hard drive is out of space.

C.

A detection server has excessive filereader restarts.

D.

Tablespace is almost full.

Full Access
Question # 20

A DLP administrator has added several approved endpoint devices as exceptions to an Endpoint Prevent policy that blocks the transfer of sensitive data. However, data transfers to these devices are still being blocked.

What is the first action an administrator should take to enable data transfers to the approved endpoint devices?

A.

Disable and re-enable the Endpoint Prevent policy to activate the changes

B.

Double-check that the correct device ID or class has been entered for each device

C.

Verify Application File Access Control (AFAC) is configured to monitor the specific application

D.

Edit the exception rule to ensure that the “Match On” option is set to “Attachments”

Full Access
Question # 21

A DLP administrator has performed a test deployment of the DLP 15.0 Endpoint agent and now wants to uninstall the agent. However, the administrator no longer remembers the uninstall password.

What should the administrator do to work around the password problem?

A.

Apply a new global agent uninstall password in the Enforce management console.

B.

Manually delete all the Endpoint agent files from the test computer and install a new agent package.

C.

Replace the PGPsdk.dll file on the agent’s assigned Endpoint server with a copy from a different Endpoint server

D.

Use the UninstallPwdGenerator to create an UninstallPasswordKey.

Full Access
Question # 22

Which two (2) DLP products support Optical Character Recognition (OCR)? (Choose two.)

A.

Network Discover

B.

Endpoint Prevent

C.

Network Prevent for Email

D.

Endpoint Discover

E.

Information Centric Analytics

Full Access
Question # 23

What is one difference between Exact Data Matching (EDM) and Exact Match Data Identifiers (EMDI)?

A.

EDM requires an index and EMDI does not.

B.

EDM rules can be evaluated by the DLP Agent and EMDI rules cannot.

C.

EDM is its own detection rule type and EMDI is a Data Identifier validation check.

D.

EDM is better at detecting non-standard delimiters (in ID numbers) than EMDI.

Full Access
Question # 24

Which statement accurately describes where Optical Character Recognition (OCR) On-Premises DLP Core components must be installed?

A.

The OCR engine must be installed directly on the Enforce server.

B.

The OCR engine must be installed on one or more detection servers.

C.

The OCR server software must by installed on one or more dedicated (non-detection) Windows servers.

D.

The OCR server software must be installed on one or more dedicated (non-detection) Linux servers.

Full Access
Question # 25

What is the first step an administrator should take to improve the performance of Network Monitor when network traffic exceeds 1 Gbps?

A.

Increase system memory (RAM) for existing Network Prevent servers.

B.

Add more Network Prevent servers to the Symantec DLP environment.

C.

Filter out all network traffic that is unreadable to Network Monitor.

D.

Install network taps and connect them to existing Network Monitor servers.

Full Access
Question # 26

What is required on the Enforce server to communicate with the Symantec DLP database?

A.

Port 8082 should be opened

B.

CryptoMasterKey.properties file

C.

Symbolic links to .dbf files

D.

SQL*plus Client

Full Access
Question # 27

Why is it important for an administrator to utilize the grid scan feature?

A.

To distribute the scan workload across multiple network discover servers

B.

To distribute the scan workload across the cloud servers

C.

To distribute the scan workload across multiple endpoint servers

D.

To distribute the scan workload across multiple detection servers

Full Access
Question # 28

Which action is available for use in both Smart Response and Automated Response rules?

A.

Log to a Syslog Server

B.

Limit incident data retention

C.

Modify SMTP message

D.

Block email message

Full Access
Question # 29

A company needs to secure the content of all mergers and Acquisitions Agreements/ However, the standard text included in all company literature needs to be excluded.

How should the company ensure that this standard text is excluded from detection?

A.

Create a Whitelisted.txt file after creating the Vector Machine Learning (VML) profile.

B.

Create a Whitelisted.txt file after creating the Exact Data Matching (EDM) profile

C.

Create a Whitelisted.txt file before creating the Indexed Document Matching (IDM) profile

D.

Create a Whitelisted.txt file before creating the Exact Data Matching (EDM) profile

Full Access
Question # 30

Which Network Prevent action has taken place when a Network incident snapshot indicates the message has been “Modified”?

A.

Modify content from the body of an email

B.

Add one or more SMTP headers to an email

C.

Obfuscate text in the body of an email

D.

Remove attachments from an email

Full Access
Question # 31

Which type of response rule does Cloud Service for Email use to block confidential emails?

A.

Network Prevent: Block HTTP/HTTPS

B.

Network Prevent: Block SMTP Message

C.

Cloud Applications and API Appliance: Block Data-in-Motion

D.

Cloud Applications and API Appliance: Redact Data-in-Motion

Full Access
Question # 32

A divisional executive requests a report of all incidents generated by a particular region, summarized by department.

What does the DLP administrator need to configure to generate this report?

A.

Custom attributes

B.

Status attributes

C.

Sender attributes

D.

User attributes

Full Access