Symantec 250-587 - Symantec Data Loss Prevention 16.x Administration Technical Specialist Exam

Question #11 (Topic: Exam A)
Which two (2) technologies should an organization utilize for integration with the Network Prevent products? (Choose two.)
A. Mail Transfer Agent B. Network Tap C. Proxy Server D. Network Firewall E. Encryption Appliance
Answer: AC
Question #12 (Topic: Exam A)
A DLP administrator has added several approved endpoint devices as exceptions to an Endpoint Prevent policy that blocks the transfer of sensitive data. However, data transfers to these devices are still being blocked.
What is the first action an administrator should take to enable data transfers to the approved endpoint devices?
A. Disable and re-enable the Endpoint Prevent policy to activate the changes B. Double-check that the correct device ID or class has been entered for each device C. Edit the exception rule to ensure that the “Match On” option is set to “Attachments” D. Verify Application File Access Control (AFAC) is configured to monitor the specific application
Answer: B
Question #13 (Topic: Exam A)
Which of the following would have to be a custom attribute (and not an out-of -the-box system attribute) in incident snapshots?
A. Network Prevent Action B. Endpoint Location C. Employee Phone Number D. See Before
Answer: C
Question #14 (Topic: Exam A)
How do Cloud Detection Service and the Enforce server communicate with each other?
A. Enforce initiates communication with Cloud Detection Service, which is expecting connections on port 8100. B. Cloud Detection Service initiates communication with Enforce, which is expecting connections on port 443. C. Enforce initiates communication with Cloud Detection Service, which is expecting connections on port 443. D. Cloud Detection Service initiates communication with Enforce, which is expecting connections on port 8100.
Answer: C
Question #15 (Topic: Exam A)
What is one difference between Exact Data Matching (EDM) and Exact Match Data Identifiers (EMDI)?
A. EDM requires an index and EMDI does not. B. EDM rules can be evaluated by the DLP Agent and EMDI rules cannot. C. EDM is its own detection rule type and EMDI is a Data Identifier validation check. D. EDM is better at detecting non-standard delimiters (in ID numbers) than EMDI.
Answer: C
Download Exam
Page: 3 / 14
Total 66 questions