Symantec Endpoint Protection 14.x Admin R2 Technical Specialist - 250-605 Exam Practice Test
Question 1
Which two scenarios are appropriate for using Rapid Release definitions?
(Choose two)
(Choose two)
Correct Answer: B,D
Question 2
How does SEP determine which network behaviors to block using the default Intrusion Prevention Policy?
Correct Answer: D
Question 3
What must be configured in SEPM to automatically send health or risk reports on a recurring basis?
Correct Answer: A
Question 4
What is the benefit of integrating SEDR with a SIEM such as Splunk?
Correct Answer: D
Question 5
What feature enables SEP to prevent users from downloading malware-infected files through email clients?
Correct Answer: D
Question 6
During a successful integration between SEDR and SEPM, which two data streams are shared to enhance EDR functionality?
(Choose two)
(Choose two)
Correct Answer: A,D
Question 7
How does the Command Status view help administrators evaluate client management actions?
Correct Answer: D
Question 8
How does SEPM distribute content to managed clients in the most efficient manner?
Correct Answer: D
Question 9
How does SEP apply Memory Exploit Mitigation to applications on a client system?
Correct Answer: C
Question 10
How can an analyst use the Evidence Table during an investigation in SEDR?
Correct Answer: C
Question 11
What is the primary function of System Lockdown in SEP?
Correct Answer: C
Question 12
Which policy component includes lists of approved applications that are allowed to run on client computers?
Correct Answer: D
Question 13
Which feature excludes files and folders from various scan types so that scans do not interfere with daily business operations?
Correct Answer: B
Question 14
What action can you perform directly from the SEPM Clients view to respond to a detected threat on a specific endpoint?
Correct Answer: D
Question 15
Which step aligns with the "Respond" phase in the NIST Cybersecurity Framework when using SEDR?
Correct Answer: B

