Symantec Data Loss Prevention 16.x Administration Technical Specialist - 250-587 Exam Practice Test

Which two components can perform a file system scan of a workstation? (Choose two.)
Correct Answer: A,B
Which two actions are available for a "Network Prevent: Remove HTTP/HTTPS content" response rule when the content is unable to be removed? (Choose two.)
Correct Answer: B,C
Which tool must a DLP administrator run to certify the database prior to upgrading DLP?
Correct Answer: D
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
A DLP administrator is attempting to add a new Network Discover detection server from the Enforce management console. However, the only available options are Network Monitor and Endpoint servers.
What should the administrator do to make the Network Discover option available?
Correct Answer: D
Which two Network Discover/Cloud Storage targets apply Information Centric Encryption as policy response rules?
Correct Answer: B,D
When managing an Endpoint Discover scan, a DLP administrator notices some endpoint computers are NOT completing their scans.
When does the DLP agent stop scanning?
Correct Answer: B
A DLP administrator determines that the \SymantecDLP\Protect\Incidents folder on the Enforce server contains. BAD files dated today, while other. IDC files are flowing in and out of the \Incidents directory.
Only .IDC files larger than 1MB are turning to .BAD files.
What could be causing only incident data smaller than 1MB to persist while incidents larger than 1MB change to .BAD files?
Correct Answer: D
What is required on the Enforce server to communicate with the Symantec DLP database?
Correct Answer: C
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
0
0
0
0