
準備できる250-605問題解答は無料更新されて100%試験合格保証 [2026]
問題集リアルなSymantec 250-605試験問題 [更新されたのは2026年]
質問 # 100
What is the role of a "Site" in the Symantec Endpoint Protection Manager (SEPM) architecture?
- A. It manages firewall rules for separate client networks
- B. It allows for isolation of clients based on IP address
- C. It represents a logical container for SEPMs sharing a single database
- D. It defines physical office locations for deploying SEP
正解:C
質問 # 101
Which feature is a subset of Application and Device Control that can be used by itself or in conjunction with Application and Device Control?
- A. Custom AD Control
- B. Allow Lists
- C. Application Monitoring
- D. System Lockdown
正解:D
質問 # 102
Which two types of Security Exceptions can be created in SEPM?
(Choose two)
- A. SONAR Exception
- B. DNS Exception
- C. Application Exception
- D. Memory Exception
正解:A、C
質問 # 103
What is a common use case for implementing System Lockdown in a production environment?
- A. Temporarily blocking traffic to external email servers
- B. Accelerating LiveUpdate download speed
- C. Ensuring that only business-critical applications are executed
- D. Testing new virus definitions
正解:C
質問 # 104
Which port must be open on a GUP to allow other clients to request updates?
- A. 0
- B. 1
- C. 2
- D. 3
正解:D
質問 # 105
When enabling System Lockdown, which file is essential to define the set of allowed applications?
- A. File Fingerprint List
- B. Host Integrity Check File
- C. Exclusion Policy File
- D. Security Certificate File
正解:A
質問 # 106
What must be configured in SEPM to ensure effective threat detection by SEDR?
- A. Forward logs and telemetry data to the SEDR appliance
- B. Enable Auto-Protect Scan only
- C. Assign a default domain administrator role
- D. Disable client integrity checking
正解:A
質問 # 107
Which feature in SEPM allows administrators to generate graphical summaries of threat activity, policy compliance, and system status?
- A. Command Status
- B. Summary Dashboard
- C. Reports Page
- D. System Logs
正解:C
質問 # 108
Which two elements must be specified when creating a custom firewall rule in SEPM?
(Choose two)
- A. The definition revision history
- B. Network protocol and port(s)
- C. Location awareness priority
- D. Action to take (e.g., allow or block)
正解:B、D
質問 # 109
What method does the SEP client use to initiate communication with the SEPM by default?
- A. UDP-based broadcast
- B. Push communication from SEPM
- C. Manual synchronization through LiveUpdate
- D. Client-initiated polling over HTTPS
正解:D
質問 # 110
How can an analyst use the Evidence Table during an investigation in SEDR?
- A. To view event logs generated by the SEPM
- B. To list only infected endpoints
- C. To organize and correlate all detected evidence related to a threat
- D. To delete false positives directly from the database
正解:C
質問 # 111
How does the SEP Emulator contribute to threat detection?
- A. By running daily full system scans
- B. By simulating file execution in a safe environment to detect obfuscated malware
- C. By verifying system drivers before installation
- D. By blocking all unknown applications
正解:B
質問 # 112
Which SEPM page offers a high-level overview of system health, policy compliance, and recent threat activity?
- A. Notifications
- B. Summary
- C. Reports
- D. Logs
正解:B
質問 # 113
Which two exploit techniques are commonly detected and mitigated by SEP's Memory Exploit Mitigation?
(Choose two)
- A. Shellcode injection
- B. Heap spraying
- C. DNS tunneling
- D. Email phishing
正解:A、B
質問 # 114
What action can you perform directly from the SEPM Clients view to respond to a detected threat on a specific endpoint?
- A. Initiate an administrator-defined scan
- B. Roll back to a previous policy version
- C. Reset the user's password
- D. Format the local disk of the endpoint
正解:A
質問 # 115
Which two actions can System Lockdown perform when an unauthorized application is detected?
(Choose two)
- A. Quarantine the application automatically
- B. Log the event in SEPM and enforce the policy
- C. Notify the user and block execution
- D. Add the application to the whitelist automatically
正解:B、C
質問 # 116
Which two scanning methods are part of SEP's Auto-Protect capabilities?
(Choose two)
- A. Weekly scheduled heuristic scans
- B. Scanning files during creation or modification
- C. Real-time scanning of encrypted email content
- D. On-access scanning of files at runtime
正解:B、D
質問 # 117
How does the Command Status view help administrators evaluate client management actions?
- A. It tracks the success or failure of actions like scans and policy updates
- B. It provides LiveUpdate schedules for client groups
- C. It lists all administrator-defined groups and OUs
- D. It shows clients currently in passive mode
正解:A
質問 # 118
Which two criteria can be used to define a location in SEP?
(Choose two)
- A. MAC Address Pattern
- B. Operating System Type
- C. Connected Gateway IP Address
- D. DNS Suffix
正解:C、D
質問 # 119
......
250-605試験問題集、250-605練習テスト問題:https://www.passtest.jp/Symantec/250-605-shiken.html