250-438 Exam Questions - Online Test


250-438 Premium VCE File

Learn More 100% Pass Guarantee - Dumps Verified - Instant Download
150 Lectures, 20 Hours

surepassexam.com

Act now and download your Symantec 250-438 test today! Do not waste time for the worthless Symantec 250-438 tutorials. Download Improved Symantec Administration of Symantec Data Loss Prevention 15 exam with real questions and answers and begin to learn Symantec 250-438 with a classic professional.

Online Symantec 250-438 free dumps demo Below:

NEW QUESTION 1
Which two technologies should an organization utilize for integration with the Network Prevent products? (choose two.)

  • A. Network Tap
  • B. Network Firewall
  • C. Proxy Server
  • D. Mail Transfer Agent
  • E. Encryption Appliance

Answer: CD

Explanation:
Reference: https://www.symantec.com/connect/articles/network-prevent

NEW QUESTION 2
Which two locations can Symantec DLP scan and perform Information Centric Encryption (ICE) actions on? (Choose two.)

  • A. Exchange
  • B. Jiveon
  • C. File store
  • D. SharePoint
  • E. Confluence

Answer: CD

Explanation:
Reference: https://www.symantec.com/content/dam/symantec/docs/data-sheets/information-centric-encryption-en.pdf

NEW QUESTION 3
What is the Symantec recommended order for stopping Symantec DLP services on a Windows Enforce server?

  • A. Vontu Notifier, Vontu Incident Persister, Vontu Update, Vontu Manager, Vontu Monitor Controller
  • B. Vontu Update, Vontu Notifier, Vontu Manager, Vontu Incident Persister, Vontu Monitor Controller
  • C. Vontu Incident Persister, Vontu Update, Vontu Notifier, Vontu Monitor Controller, Vontu Manager.
  • D. Vontu Monitor Controller, Vontu Incident Persister, Vontu Manager, Vontu Notifier, Vontu Update.

Answer: D

Explanation:
Reference: https://help.symantec.com/cs/dlp15.1/DLP/v23042736_v125428396/Stopping-an-Enforce-Server-on-Windows?locale=EN_US

NEW QUESTION 4
A DLP administrator needs to remove an agent its associated events from an Endpoint server.
Which Agent Task should the administrator perform to disable the agent’s visibility in the Enforce management console?

  • A. Delete action from the Agent Health dashboard
  • B. Delete action from the Agent List page
  • C. Disable action from Symantec Management Console
  • D. Change Endpoint Server action from the Agent Overview page

Answer: C

NEW QUESTION 5
DRAG DROP
The Symantec Data Loss risk reduction approach has six stages.
Drag and drop the six correct risk reduction stages in the proper order of Occurrence column.
Select and Place:
250-438 dumps exhibit

  • A. Mastered
  • B. Not Mastered

Answer: A

Explanation:
Reference: https://www.slideshare.net/iftikhariqbal/symantec-data-loss-prevention-technical-proposal-general

NEW QUESTION 6
A DLP administrator is attempting to add a new Network Discover detection server from the Enforce management console. However, the only available options are Network Monitor and Endpoint servers. What should the administrator do to make the Network Discover option available?

  • A. Restart the Symantec DLP Controller service
  • B. Apply a new software license file from the Enforce console
  • C. Install a new Network Discover detection server
  • D. Restart the Vontu Monitor Service

Answer: C

NEW QUESTION 7
An administrator is unable to log in to the Enforce management console as “sysadmin”. Symantec DLP is configured to use Active Directory authentication. The administrator is a member of two roles: “sysadmin” and “remediator.” How should the administrator log in to the Enforce console with the “sysadmin” role?

  • A. sysadminusername
  • B. sysadminusername@domain
  • C. domainusername
  • D. usernamesysadmin

Answer: C

NEW QUESTION 8
What detection server type requires a minimum of two physical network interface cards?

  • A. Network Prevent for Web
  • B. Network Prevent for Email
  • C. Network Monitor
  • D. Cloud Detection Service (CDS)

Answer: A

NEW QUESTION 9
A compliance officer needs to understand how the company is complying with its data security policies over time. Which report should be compliance officer generate to obtain the compliance information?

  • A. Policy report, filtered on date and summarized by policy
  • B. Policy Trend report, summarized by policy, then quarter
  • C. Policy report, filtered on quarter and summarized by policy
  • D. Policy Trend report, summarized by policy, then severity

Answer: A

NEW QUESTION 10
Why would an administrator set the Similarity Threshold to zero when testing and tuning a Vector Machine Learning (VML) profile?

  • A. To capture the matches to the Positive set
  • B. To capture the matches to the Negative set
  • C. To see the false negatives only
  • D. To see the entire range of potential matches

Answer: D

Explanation:
Reference: https://help.symantec.com/cs/dlp15.0/DLP/v45067125_v120691346/Adjusting-the-Similarity-Threshold?locale=EN_US

NEW QUESTION 11
Which two detection servers are available as virtual appliances? (Choose two.)

  • A. Network Monitor
  • B. Network Prevent for Web
  • C. Network Discover
  • D. Network Prevent for Email
  • E. Optical Character Recognition (OCR)

Answer: BD

Explanation:
Reference: https://help.symantec.com/cs/dlp15.0/DLP/v123002905_v120691346/About-DLP-Appliances?locale=EN_US

NEW QUESTION 12
Which two detection technology options ONLY run on a detection server? (Choose two.)

  • A. Form Recognition
  • B. Indexed Document Matching (IDM)
  • C. Described Content Matching (DCM)
  • D. Exact Data Matching (EDM)
  • E. Vector Machine Learning (VML)

Answer: BD

Explanation:
Reference: https://support.symantec.com/en_US/article.INFO5070.html

NEW QUESTION 13
Which action should a DLP administrator take to secure communications between an on-premises Enforce server and detection servers hosted in the Cloud?

  • A. Use the built-in Symantec DLP certificate for the Enforce Server, and use the “sslkeytool” utility to create certificates for the detection servers.
  • B. Use the built-in Symantec DLP certificate for both the Enforce server and the hosted detection servers.
  • C. Set up a Virtual Private Network (VPN) for the Enforce server and the hosted detection servers.
  • D. Use the “sslkeytool” utility to create certificates for the Enforce server and the hosted detection servers.

Answer: A

Explanation:
Reference: https://www.symantec.com/connect/articles/sslkeytool-utility-and-server-certificates

NEW QUESTION 14
A DLP administrator is testing Network Prevent for Web functionality. When the administrator posts a small test file to a cloud storage website, no new incidents are reported. What should the administrator do to allow incidents to be generated against this file?

  • A. Change the “Ignore requests Smaller Than” value to 1
  • B. Add the filename to the Inspect Content Type field
  • C. Change the “PacketCapture.DISCARD_HTTP_GET” value to “false”
  • D. Uncheck trial mode under the ICAP tab

Answer: A

Explanation:
Reference: https://help.symantec.com/cs/dlp15.0/DLP/id-SF0B0161467_v120691346/Configuring-Network-Prevent-for-Web-Server?locale=EN_US

NEW QUESTION 15
Refer to the exhibit. Which type of Endpoint response rule is shown?
250-438 dumps exhibit

  • A. Endpoint Prevent: User Notification
  • B. Endpoint Prevent: Block
  • C. Endpoint Prevent: Notify
  • D. Endpoint Prevent: User Cancel

Answer: B

Explanation:
Reference: https://help.symantec.com/cs/dlp15.0/DLP/v27595430_v120691346/Configuring-the-Endpoint-Prevent:-Block-action?locale=EN_US

NEW QUESTION 16
Which two DLP products support the new Optical Character Recognition (OCR) engine in Symantec DLP 15.0? (Choose two.)

  • A. Endpoint Prevent
  • B. Cloud Service for Email
  • C. Network Prevent for Email
  • D. Network Discover
  • E. Cloud Detection Service

Answer: BC

NEW QUESTION 17
Which two actions are available for a “Network Prevent: Remove HTTP/HTTPS content” response rule when the content is unable to be removed? (Choose two.)

  • A. Allow the content to be posted
  • B. Remove the content through FlexResponse
  • C. Block the content before posting
  • D. Encrypt the content before posting
  • E. Redirect the content to an alternative destination

Answer: AE

NEW QUESTION 18
A DLP administrator has added several approved endpoint devices as exceptions to an Endpoint Prevent policy that blocks the transfer of sensitive data. However, data transfers to these devices are still being blocked. What is the first action an administrator should take to enable data transfers to the approved endpoint devices?

  • A. Disable and re-enable the Endpoint Prevent policy to activate the changes
  • B. Double-check that the correct device ID or class has been entered for each device
  • C. Verify Application File Access Control (AFAC) is configured to monitor the specific application
  • D. Edit the exception rule to ensure that the “Match On” option is set to “Attachments”

Answer: D

NEW QUESTION 19
Which two factors are common sources of data leakage where the main actor is well-meaning insider? (Choose two.)

  • A. An absence of a trained incident response team
  • B. A disgruntled employee for a job with a competitor
  • C. Merger and Acquisition activities
  • D. Lack of training and awareness
  • E. Broken business processes

Answer: BD

NEW QUESTION 20
Which option is an accurate use case for Information Centric Encryption (ICE)?

  • A. The ICE utility encrypts files matching DLP policy being copied from network share through use of encryption keys.
  • B. The ICE utility encrypts files matching DLP policy being copied to removable storage through use of encryption keys.
  • C. The ICE utility encrypts files matching DLP policy being copied to removable storage on an endpoint use of certificates.
  • D. The ICE utility encrypts files matching DLP policy being copied from network share through use of certificates

Answer: B

Explanation:
Reference: https://help.symantec.com/cs/ICE1.0/ICE/v126756321_v120576779/Using-ICE-with-Symantec-Data-Loss-Preventionabout_dlp?locale=EN_US

NEW QUESTION 21
What is the correct configuration for “BoxMonitor.Channels” that will allow the server to start as a Network Monitor server?

  • A. Packet Capture, Span Port
  • B. Packet Capture, Network Tap
  • C. Packet Capture, Copy Rule
  • D. Packet capture, Network Monitor

Answer: C

Explanation:
Reference: https://support.symantec.com/en_US/article.TECH218980.html

NEW QUESTION 22
A divisional executive requests a report of all incidents generated by a particular region, summarized by department. What does the DLP administrator need to configure to generate this report?

  • A. Custom attributes
  • B. Status attributes
  • C. Sender attributes
  • D. User attributes

Answer: A

NEW QUESTION 23
A company needs to secure the content of all Mergers and Acquisitions Agreements However, the standard text included in all company literature needs to be excluded. How should the company ensure that this standard text is excluded from detection?

  • A. Create a Whitelisted.txt file after creating the Vector Machine Learning (VML) profile.
  • B. Create a Whitelisted.txt file after creating the Exact Data Matching (EDM) profile
  • C. Create a Whitelisted.txt file before creating the Indexed Document Matching (IDM) profile
  • D. Create a Whitelisted.txt file before creating the Exact Data Matching (EDM) profile

Answer: C

Explanation:
Reference: https://help.symantec.com/cs/dlp15.0/DLP/v27161240_v120691346/White-listing-file-contents-to-exclude-from-partial-matching?locale=EN_US

NEW QUESTION 24
What is the default fallback option for the Endpoint Prevent Encrypt response rule?

  • A. Block
  • B. User Cancel
  • C. Encrypt
  • D. Notify

Answer: D

NEW QUESTION 25
......

P.S. Easily pass 250-438 Exam with 70 Q&As Surepassexam Dumps & pdf Version, Welcome to Download the Newest Surepassexam 250-438 Dumps: https://www.surepassexam.com/250-438-exam-dumps.html (70 New Questions)