
合格させるSymantec 250-614にはPassTest提供の試験問題集で2026年08月更新
完全版最新の250-614問題集、100%カバー率問題と解答があなたをリアル試験で合格させる
質問 # 36
Which attack goal is most commonly associated with compromising Active Directory?
- A. Improving policy management
- B. Reducing alert volume
- C. Increasing endpoint performance
- D. Achieving lateral movement and privilege escalation
正解:D
質問 # 37
What is the purpose of EDR threat investigation?
- A. Manage alert thresholds
- B. Apply content updates
- C. Assign device groups
- D. Reconstruct attack activity and scope
正解:D
質問 # 38
What happens when a policy version is updated?
- A. Endpoints stop reporting telemetry
- B. Device groups are reset
- C. Endpoints receive the new policy after synchronization
- D. Old policies are immediately deleted
正解:C
質問 # 39
Which MITRE ATT&CK framework step includes destroying data and rendering an endpoint inoperable?
- A. Kill Chain
- B. Exfiltration
- C. Rampage
- D. Impact
正解:D
質問 # 40
Which benefit is directly associated with SES Complete cloud-based management?
- A. Mandatory offline policy enforcement
- B. Elimination of endpoint agents
- C. Reduced need for endpoint telemetry
- D. Centralized visibility without on-premises management servers
正解:D
質問 # 41
What is the name of the cloud-based Management Console that is used to configure and manage an SES Complete implementation?
- A. The Integrated Cyber Defense Manager (ICDm)
- B. The Symantec Console (SC)
- C. The Integrated Security Protection Manager (ISPm)
- D. Symantec Endpoint Security Manager (SESM)
正解:A
質問 # 42
What is the purpose of Custom Application Behavior rules?
- A. Replace Adaptive Protection
- B. Manage alert severity
- C. Automatically deploy endpoint agents
- D. Define acceptable behaviors for specific applications
正解:D
質問 # 43
Why is understanding the threat landscape important for policy configuration?
- A. It determines licensing costs
- B. It helps align controls with current attack techniques
- C. It replaces security updates
- D. It automates user training
正解:B
質問 # 44
Why is context important during EDR investigations?
- A. It helps distinguish benign from malicious activity
- B. It reduces storage needs
- C. It automates remediation
- D. It limits alert visibility
正解:A
質問 # 45
A ransomware alert is detected on a single endpoint. What is the most immediate action to limit spread?
- A. Reassign the device group
- B. Isolate the endpoint
- C. Update content definitions
- D. Generate a compliance report
正解:B
質問 # 46
Which SES Complete feature provides protection against fileless attacks?
- A. Device group inheritance
- B. Machine Learning and behavior analysis
- C. Email enrollment
- D. Policy versioning
正解:B
質問 # 47
What is the key function of Adaptive Protection?
- A. Replace firewall rules
- B. Block only known malware
- C. Dynamically restrict unknown applications
- D. Manage content updates
正解:C
質問 # 48
How does Application Control contribute to attack surface reduction?
- A. By managing device groups
- B. By encrypting endpoint traffic
- C. By allowing only authorized applications to run
- D. By updating malware signatures
正解:C
質問 # 49
Why is the MITRE ATT&CK framework relevant to SES Complete?
- A. It controls endpoint enrollment
- B. It replaces antivirus signatures
- C. It defines cloud licensing tiers
- D. It provides a model for mapping attacker techniques
正解:D
質問 # 50
Which control is most effective against zero-day threats?
- A. Manual analysis
- B. Signature-based detection
- C. Machine Learning
- D. Policy versioning
正解:C
質問 # 51
......
最新250-614試験問題集有効で最新の問題集:https://www.passtest.jp/Symantec/250-614-shiken.html