Symantec Administration of Symantec Advanced Threat Protection 3.0 - 250-441 Exam Practice Test

Which detection method identifies a file as malware after SEP has queried the file's reputation?
Correct Answer: D
An Incident Responder needs to remediate a group of endpoints but also wants to copy a potentially suspicious file to the ATP file store.
In which scenario should the Incident Responder copy a suspicious file to the ATP file store?
Correct Answer: D
Which threat is an example of an Advanced Persistent Threat (APT)?
Correct Answer: C
Which level of privilege corresponds to each ATP account type?
Match the correct account type to the corresponding privileges.
Correct Answer:

Refer to the exhibit. An Incident Responder wants to see what was detected on a specific day by the IPS engine.
Which item must the responder choose from the drop-down menu?
Correct Answer: C
An ATP administrator is setting up correlation with Email Security cloud.
What is the minimum Email Security cloud account privilege required?
Correct Answer: B
What occurs when an endpoint fails its Host Integrity check and is unable to remediate?
Correct Answer: B
During a recent virus outlook, an Incident found that the incident Response team was successful in identifying malicious that were communicating with the infected endpoint.
Which two (2) options should be incident Responder select to prevent endpoints from communicating with malicious domains?
Correct Answer: A,D
An Incident Responder discovers an incident where all systems are infected with a file that has the same name and different hash. As a result, the organism view has multiple entries for the malicious file.
What is causing this issue?
Correct Answer: A
An ATP Administrator set up ATP: Network in TAP mode and has placed URLs on the blacklist.
What will happen when a user attempts to access one of the blacklisted URLs?
Correct Answer: C
0
0
0
0