
Reliable 250-605 Dumps Questions Available as Web-Based Practice Test Engine
Correct and Up-to-date Symantec 250-605 BrainDumps
NEW QUESTION # 65
What two actions can be performed from the SEDR Management Console to respond to an active threat?
(Choose two)
- A. Configure new SEP install packages
- B. Disconnect the endpoint from all external communications
- C. Reassign the user to a different SEP group
- D. Kill a malicious process on a target endpoint
Answer: B,D
NEW QUESTION # 66
Which two sections of SEPM are useful for real-time monitoring of endpoint security activity?
(Choose two)
- A. Home > Summary
- B. Reports > Quick Reports
- C. Monitors > Logs
- D. Admin > Servers
Answer: A,C
NEW QUESTION # 67
Which two functions are supported in the SEDR Management Console?
(Choose two)
- A. Schedule OS patch updates
- B. Policy deployment to SEP clients
- C. Search endpoint activity recorder logs
- D. Review and triage of threat incidents
Answer: C,D
NEW QUESTION # 68
What is a common use case for implementing System Lockdown in a production environment?
- A. Ensuring that only business-critical applications are executed
- B. Testing new virus definitions
- C. Temporarily blocking traffic to external email servers
- D. Accelerating LiveUpdate download speed
Answer: A
NEW QUESTION # 69
During a successful integration between SEDR and SEPM, which two data streams are shared to enhance EDR functionality?
(Choose two)
- A. Patch deployment schedules
- B. Telemetry data and event metadata
- C. Policy compliance violations
- D. Endpoint scan logs
Answer: B,D
NEW QUESTION # 70
Which two benefits are gained by deploying Group Update Providers in distributed networks?
(Choose two)
- A. Decreased SEPM CPU utilization
- B. Localized content distribution to reduce WAN traffic
- C. Improved scalability in branch offices without local SEPMs
- D. Automatic policy rollback during disconnection
Answer: B,C
NEW QUESTION # 71
When configuring the Intrusion Prevention Policy, which two options can be customized per signature?
(Choose two)
- A. Action taken (e.g., Block, Allow, Log only)
- B. Policy version rollback delay
- C. Definition file retention time
- D. Notification alert generation
Answer: A,D
NEW QUESTION # 72
What must be configured in SEDR to enable integration with Splunk for event analysis?
- A. SEP Content Replicator
- B. A syslog forwarding profile
- C. Network Packet Sniffer
- D. Custom DNS rules
Answer: B
NEW QUESTION # 73
Which port must be open on a GUP to allow other clients to request updates?
- A. 0
- B. 1
- C. 2
- D. 3
Answer: D
NEW QUESTION # 74
Which function do user-managed certificates serve in the SEDR environment?
- A. They ensure secure communication between SEDR and external systems
- B. They store log archives securely
- C. They replace the default SEP antivirus signature
- D. They activate administrator roles in SEPM
Answer: A
NEW QUESTION # 75
What must be done to ensure that SEP clients are protected by Intrusion Prevention rules?
- A. Assign an Application and Device Control policy
- B. Enable Stealth Mode in Firewall policy
- C. Configure the Host Integrity policy with antivirus exclusions
- D. Apply an Intrusion Prevention Policy to the client group
Answer: D
NEW QUESTION # 76
What is the correlation engine that allows for faster, confident responses to security incidents?
- A. Insight
- B. Skeptic
- C. SONAR
- D. Synapse
Answer: D
NEW QUESTION # 77
What method does the SEP client use to initiate communication with the SEPM by default?
- A. UDP-based broadcast
- B. Push communication from SEPM
- C. Manual synchronization through LiveUpdate
- D. Client-initiated polling over HTTPS
Answer: D
NEW QUESTION # 78
Which SEP policy controls the Memory Exploit Mitigation settings?
- A. Windows Settings > Exploit Mitigation
- B. Intrusion Prevention Policy
- C. Virus and Spyware Protection Policy
- D. Application and Device Control Policy
Answer: A
NEW QUESTION # 79
Which of the following components is responsible for enforcing policies on an endpoint in the SEP environment?
- A. SEPM (Symantec Endpoint Protection Manager)
- B. SEP Client
- C. Intrusion Prevention System
- D. LiveUpdate Administrator
Answer: B
NEW QUESTION # 80
What are two core benefits of SEP's layered security architecture?
(Choose two)
- A. Combines behavior-based and signature-based detection
- B. Enables SEP to function without a policy framework
- C. Improves zero-day threat detection using multiple detection methods
- D. Reduces the need for definition updates
Answer: A,C
NEW QUESTION # 81
What component of a custom firewall rule specifies whether traffic should be allowed, blocked, or logged?
- A. Rule inheritance
- B. Profile type
- C. Condition priority
- D. Action setting
Answer: D
NEW QUESTION # 82
When planning SEDR deployment sizing, what are two key characteristics to evaluate?
(Choose two)
- A. Average number of incidents generated daily
- B. Retention requirements for EDR data
- C. Endpoint operating system versions
- D. Number of policies in SEP firewall
Answer: A,B
NEW QUESTION # 83
Which tool within SEDR allows analysts to search for specific indicators of compromise (IoCs)?
- A. SEP Policy Scanner
- B. Search and Investigate
- C. Network Threat Analyzer
- D. Evidence Table
Answer: B
NEW QUESTION # 84
Which shared Symantec technology enables real-time threat detection and enrichment in SEDR?
- A. Symantec Brightmail Gateway
- B. SEP System Lockdown
- C. Symantec Global Intelligence Network (GIN)
- D. SEP Auto-Protect
Answer: C
NEW QUESTION # 85
......
100% Reliable Microsoft 250-605 Exam Dumps Test Pdf Exam Material: https://www.latestcram.com/250-605-exam-cram-questions.html
Current 250-605 dumps Preparation through Our Practice Test: https://drive.google.com/open?id=1WehgZwvdFkhSSbjMqowDAj1lrYt7d2yU
