Weekend Special 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: Board70

250-441 Exam Dumps - Symantec Certified Specialist Questions and Answers

Question # 4

How can an Incident Responder generate events for a site that was identified as malicious but has NOT

triggered any events or incidents in ATP?

Options:

A.

Assign a High-Security Antivirus and Antispyware policy in the Symantec Endpoint Protection Manager

(SEPM).

B.

Run an indicators of compromise (IOC) search in ATP manager.

C.

Create a firewall rule in the Symantec Endpoint Protection Manager (SEPM) or perimeter firewall that

blocks traffic to the domain.

D.

Add the site to a blacklist in ATP manager.

Buy Now
Question # 5

A medium-sized organization with 10,000 users at Site A and 20,000 users at Site B wants to use ATP:

Network to scan internet traffic at both sites.

Which physical appliances should the organization use to act as a network scanner at each site while using the fewest appliances and assuming typical network usage?

Options:

A.

Site A 8840 x4 – Site B 8880 x2

B.

Site A 8880 x2 – Site B 8840 x1

C.

Site A 8880 x1 – Site B 8840 x6

D.

Site A 8880 x1 – Site B 8880 x2

Buy Now
Question # 6

Which policies are required for the quarantine feature of ATP to work?

Options:

A.

Firewall Policy and Host Integrity Policy

B.

Quarantine Policy and Firewall Policy

C.

Host Integrity Policy and Quarantine Policy

D.

Quarantine and Intrusion Prevention Policy

Buy Now
Question # 7

Which section of the ATP console should an ATP Administrator use to create blacklists and whitelists?

Options:

A.

Reports

B.

Settings

C.

Action Manager

D.

Policies

Buy Now
Question # 8

What are two policy requirements for using the Isolate and Rejoin features in ATP? (Choose two.)

Options:

A.

Add a Quarantine firewall policy for non-compliant and non-remediated computers.

B.

Add a Quarantine LiveUpdate policy for non-compliant and non-remediated computers.

C.

Add and assign an Application and Device Control policy in the Symantec Endpoint Protection Manager

(SEPM).

D.

Add and assign a Host Integrity policy in the Symantec Endpoint Protection Manager (SEPM).

E.

Add a Quarantine Antivirus and Antispyware policy for non-compliant and non-remediated computers.

Buy Now
Question # 9

An Incident Responder notices traffic going from an endpoint to an IRC channel. The endpoint is listed in an

incident. ATP is configured in TAP mode.

What should the Incident Responder do to stop the traffic to the IRC channel?

Options:

A.

Isolate the endpoint with a Quarantine Firewall policy

B.

Blacklist the IRC channel IP

C.

Blacklist the endpoint IP

D.

Isolate the endpoint with an application control policy

Buy Now
Question # 10

An Incident Responder has noticed that for the last month, the same endpoints have been involved with malicious traffic every few days. The network team also identified a large amount of bandwidth being used over P2P protocol.

Which two steps should the Incident Responder take to restrict the endpoints while maintaining normal use of the systems? (Choose two.)

Options:

A.

Report the users to their manager for unauthorized usage of company resources

B.

Blacklist the domains and IP associated with the malicious traffic

C.

Isolate the endpoints

D.

Blacklist the endpoints

E.

Find and blacklist the P2P client application

Buy Now
Question # 11

How should an ATP Administrator configure Endpoint Detection and Response according to Symantec best practices for a SEP environment with more than one domain?

Options:

A.

Create a unique Symantec Endpoint Protection Manager (SEPM) domain for ATP

B.

Create an ATP manager for each Symantec Endpoint Protection Manager (SEPM) domain

C.

Create a Symantec Endpoint Protection Manager (SEPM) controller connection for each domain

D.

Create a Symantec Endpoint Protection Manager (SEPM) controller connection for the primary domain

Buy Now
Question # 12

What is the earliest stage at which a SQL injection occurs during an Advanced Persistent Threat (APT) attack?

Options:

A.

Exfiltration

B.

Incursion

C.

Capture

D.

Discovery

Buy Now
Question # 13

What does a Quarantine Firewall policy enable an ATP Administrator to do?

Options:

A.

Isolate a computer while it is manually being remediated

B.

Submit files to a Central Quarantine server

C.

Filter all traffic leaving the network

D.

Intercept all traffic entering the network

Buy Now
Exam Code: 250-441
Exam Name: Administration of Symantec Advanced Threat Protection 3.0
Last Update: Feb 22, 2025
Questions: 90
250-441 pdf

250-441 PDF

$25.5  $84.99
250-441 Engine

250-441 Testing Engine

$28.5  $94.99
250-441 PDF + Engine

250-441 PDF + Testing Engine

$40.5  $134.99