250-561練習試験テスト最新問題2023年12月 [Q20-Q39]

Share

250-561練習試験テスト最新問題2023年12月

250-561試験を一発合格保証問題集!

質問 # 20
In which phase of MITRE framework would attackers exploit faults in software to directly tamper with system memory?

  • A. Execution
  • B. Discovery
  • C. Exfiltration
  • D. Defense Evasion

正解:D


質問 # 21
Which SES advanced feature detects malware by consulting a training model composed of known good and known bad fries?

  • A. Artificial Intelligence
  • B. Advanced Machine Learning
  • C. Reputation
  • D. Signatures

正解:B


質問 # 22
Which two (2) options is an administrator able to use to prevent a file from being fasely detected (Select two)

  • A. Add the file to a Whitelist policy
  • B. Rename the file
  • C. Register the file with Symantec's False Positive database
  • D. Reduce the Intensive Protection setting of the Antimalware policy
  • E. Assign the file a SHA-256 cryptographic hash

正解:A、C


質問 # 23
What is the primary issue pertaining to managing roaming users while utilizing an on-premise solution?

  • A. The endpoint fails to receive content update
  • B. The endpoint is absent of the management console
  • C. The endpoint is more exposed to threats
  • D. The endpoint is missing timely policy update

正解:A


質問 # 24
Which framework, open and available to any administrator, is utilized to categorize adversarial tactics and for each phase of a cyber attack?

  • A. MITRE RESPONSE
  • B. MITRE ADV&NCE
  • C. MITRE ATTACK MATRIX
  • D. MITRE ATT&CK

正解:B


質問 # 25
Which file should an administrator create, resulting Group Policy Object (GPO)?

  • A. Symantec__Agent_package_x64.zip
  • B. Symantec__Agent_package_x64.msi
  • C. Symantec__Agent_package_x64.exe
  • D. Symantec__Agent_package__32-bit.msi

正解:D


質問 # 26
Which type of security threat is used by attackers to exploit vulnerable applications?

  • A. Privilege Escalation
  • B. Lateral Movement
  • C. Command and Control
  • D. Credential Access

正解:A


質問 # 27
What option must an administrator choose when rolling back a policy assignment to a previous version?

  • A. Reverse
  • B. Go Back
  • C. Customize
  • D. Override

正解:D


質問 # 28
Which Anti-malware technology should an administrator utilize to expose the malicious nature of a file created with a custom packet?

  • A. Reputation
  • B. SONAR
  • C. Emulator
  • D. Sandbox

正解:D


質問 # 29
Which two (2) skill areas are critical to the success of incident Response Teams (Select two)

  • A. Threat Analysis
  • B. Incident Management
  • C. Cyber Intelligence
  • D. Incident Response
  • E. Project Management

正解:C、D


質問 # 30
An administrator suspects that several computers have become part of a botnet. What should the administrator do to detect botnet activity on the network?

  • A. Add botnet related signatures to the IPS policy's Audit Signatures list
  • B. Set the Antimalware policy's Monitoring Level to 4
  • C. Enable the IPS policy's Show notification on the device setting
  • D. Enable the Command and Control Server Firewall

正解:D


質問 # 31
What must an administrator check prior to enrolling an on-prem SEPM infrastructure into the cloud?

  • A. Clients are running SEP 14.0.1 or late
  • B. Clients are running SEP 14.2 or later
  • C. Clients are running SEP 12-6 or later
  • D. Clients are running SEP 14.1.0 or later

正解:A


質問 # 32
A user downloads and opens a PDF file with Adobe Acrobat. Unknown to the user, a hidden script in the file begins downloading a RAT.
Which Anti-malware engine recognizes that this behavior is inconsistent with normal Acrobat functionality, blocks the behavior and kills Acrobat?

  • A. IPS
  • B. SONAR
  • C. Sapient
  • D. Emulator

正解:C


質問 # 33
Which type of organization is likely to be targeted with emerging threats?

  • A. Large organizations with dedicated security teams
  • B. Small organization with little qualified staff
  • C. Large organization with high turnover
  • D. Small organization with externalized managed security

正解:B


質問 # 34
An endpoint fails to retrieve content updates.
Which URL should an administrator test in a browser to determine if the issue is network related?

  • A. https://liveupdate.symantec,com/livetri.zi
  • B. https://spocsymantec.com/livetri.zip
  • C. http://update.symantec.com/livetri.zip
  • D. https://update.symantec.com/livetri.zip

正解:B


質問 # 35
What is the frequency of feature updates with SES and the Integrated Cyber Defense Manager (ICDm)

  • A. Weekly
  • B. Bi-monthly
  • C. Quarterly
  • D. Monthly

正解:A


質問 # 36
Which report template includes a summary of risk distribution by devices, users, and groups?

  • A. Weekly
  • B. Device Integrity
  • C. Threat Distribution
  • D. Comprehensive

正解:C


質問 # 37
Which Symantec component is required to enable two factor authentication with VIP on the Integrated Cyber Defense manager (ICDm)?

  • A. A software token and an active directory account
  • B. A physical token or a secure USB key
  • C. A software token and a VIP server
  • D. A physical token or a software token

正解:C


質問 # 38
What are the Exploit Mitigation security control's mitigation techniques designed to prevent?

  • A. Packed file execution
  • B. Misbehaving applications
  • C. File-less attacks
  • D. Rootkit downloads

正解:D


質問 # 39
......


この試験は65の複数選択の質問で構成されており、候補者はそれを完了するのに90分かかります。試験の合格スコアは70%であり、試験は英語、ドイツ語、日本語、中国語を含むいくつかの言語で利用できます。

 

Symantec SCS無料認定試験材料はPassTestが提供された72問題:https://www.passtest.jp/Symantec/250-561-shiken.html

250-561問題集完全版問題試験学習ガイド:https://drive.google.com/open?id=1y4yCKfldepWCTeAxGfIPYMT9ZZ0sbh_U