Broadcom Endpoint Security Complete - R2 Technical Specialist 250-580 Exam Questions

Page: 1 / 14
Total 150 questions
Question 1

Which rule types should be at the bottom of the list when an administrator adds device control rules?



Answer : C

When adding device control rules, General 'catch all' rules should be placed at the bottom of the rule list. This approach ensures that:

Specificity Precedes Generality: Specific rules (like those for device type or model) are applied first, allowing fine-grained control over device access.

Efficient Rule Processing: Placing general rules last prevents them from inadvertently overriding more specific rules, which could lead to unintended access restrictions or allowances.

This ordering helps maintain effective and targeted control over devices, while still providing a fallback catch-all rule to manage unspecified devices.


Question 2

What must be entered before downloading a file from ICDm?



Answer : C

Before downloading a file from the Integrated Cyber Defense Manager (ICDm), the hash of the file must be entered. The hash serves as a unique identifier for the file, ensuring that the correct file is downloaded and verifying its integrity. Here's why this is necessary:

File Verification: By entering the hash, users confirm they are accessing the correct file, which prevents accidental downloads of unrelated or potentially harmful files.

Security Measure: The hash requirement adds an additional layer of security, helping to prevent unauthorized downloads or distribution of sensitive files.

This practice ensures accurate and secure file management within ICDm.


Question 3

A company uses a remote administration tool that is detected as Hacktool.KeyLoggPro and quarantined by Symantec Endpoint Protection (SEP).

Which step can an administrator perform to continue using the remote administration tool without detection by SEP?



Answer : C

To allow the use of a remote administration tool detected as Hacktool.KeyLoggPro without interference from SEP, the administrator should create a Known Risk exception for the tool. This exception type allows specific files or applications to bypass detection, thereby avoiding quarantine or blocking actions.

Steps to Create a Known Risk Exception:

In the SEP management console, navigate to Policies > Exceptions.

Choose to create a Known Risk exception and specify the tool's executable file or file path to prevent SEP from identifying it as a threat.

Why Known Risk Exception is Appropriate:

This type of exception is designed for tools that SEP detects as potentially risky (like hacktools or keyloggers) but are authorized for legitimate use by the organization.

Creating this exception allows the tool to operate without being flagged or quarantined.

Reasons Other Options Are Less Effective:

Tamper Protect exceptions only prevent SEP from being tampered with by other applications.

Application to Monitor exceptions monitor applications without preventing quarantine actions.

SONAR exceptions are specific to behavior-based detections, not risk definitions.


Question 4

What information is required to calculate retention rate?



Answer : D

To calculate the retention rate in Symantec Endpoint Security (SES), the following information is required:

Number of Endpoints: Determines the total scope of data generation.

EAR Data per Endpoint per Day: This is the Endpoint Activity Recorder data size generated daily by each endpoint.

Number of Days to Retain: Defines the retention period for data storage, impacting the total data volume.

Number of Endpoint Dumps and Dump Size: These parameters contribute to overall storage needs for log data and event tracking.

This data allows administrators to accurately project storage requirements and ensure adequate capacity for data retention.


Question 5

Which two (2) scan range options are available to an administrator for locating unmanaged endpoints? (Select two)



Answer : B, C

For locating unmanaged endpoints, administrators in Symantec Endpoint Protection Manager (SEPM) can use the following scan range options:

IP Range within the Network: This option allows scanning of specific IP address ranges to locate devices that may not have SEP installed.

Subnet Range: Administrators can scan within specific subnets, providing a focused range to detect unmanaged endpoints in targeted sections of the network.

These options enable precise scans, helping administrators efficiently identify and manage unmanaged devices.


Question 6

An Application Control policy includes an Allowed list and a Blocked list. A user wants to use an application that is neither on the Allowed list nor on the Blocked list. What can the user do to gain access to the application?



Answer : B

In Symantec Endpoint Protection (SEP) Application Control policies, applications are managed through lists: an Allowed list (applications approved for use) and a Blocked list (applications restricted or prohibited). When a user encounters an application that is not explicitly on either the Allowed or Blocked list, it falls into a neutral category.

For accessing this application, the typical process includes:

Requesting an Override: The user can initiate a request to temporarily or permanently allow access to the application. This process usually involves contacting the administrator or following a specified override protocol to gain necessary permissions.

Administrator Review: Upon receiving the override request, the administrator evaluates the application to ensure it aligns with organizational security policies and compliance standards.

Override Approval: If deemed safe, the application may be added to the Allowed list, granting the user access.

This request mechanism ensures that unlisted appli


Question 7

Which two (2) security controls are utilized by an administrator to mitigate threats associated with the Discovery phase? (Select two)



Answer : A, B

In the Discovery phase of a cyber attack, attackers attempt to map the network, identify vulnerabilities, and gather information. Firewall and Intrusion Prevention System (IPS) are the most effective security controls to mitigate threats associated with this phase:

Firewall: The firewall restricts unauthorized network access, blocking suspicious or unexpected traffic that could be part of reconnaissance efforts.

IPS: Intrusion Prevention Systems detect and prevent suspicious traffic patterns that might indicate scanning or probing activity, which are common in the Discovery phase.

Together, these controls limit attackers' ability to explore the network and identify potential vulnerabilities.


Page:    1 / 14   
Total 150 questions