Endpoint Security Complete - R2 Technical Specialist Free Sample Questions

20 free sample questions226 in the full practice test

Try simulator

250-580 Sample Questions

  1. Question 1

    A security architect is designing a Symantec Endpoint Security (SES) Complete policy for a group of developers who frequently use unsigned, custom-compiled executables for testing. The CISO has mandated that Application Control must be enabled in blacklist mode for all workstations, but developer productivity should not be impeded. Which policy configuration provides the most secure and efficient solution to meet these conflicting requirements?

    Answer and explanation

    Correct answer: D

    This is the most secure and scalable solution. Using a trusted publisher certificate allows developers to sign their own compiled code, which Application Control will then trust. This avoids the insecurity of path-based exceptions (where malware could be placed), the potential over-permission of allowing any process from an IDE, and the administrative nightmare of constantly updating file hashes every time the code is recompiled.

  2. Question 2

    A SOC analyst is investigating an incident in the ICDm console that originated from a suspicious PowerShell command. The Endpoint Activity Recorder (EAR) data shows the PowerShell process spawned from winword.exe, which was launched by a user opening an email attachment. To understand the full scope of the attack, what is the most effective next step within the EDR console?

    Answer and explanation

    Correct answer: C

    While isolation and memory dumps are valid response actions, the immediate next step for investigation is to understand the scope. The Process Lineage view provides a graphical representation of the entire attack chain, from the initial email attachment to the PowerShell execution and any subsequent actions. This is the most efficient way to quickly grasp the full context before deciding on specific remediation or containment actions.

  3. Question 3

    Multiple answers

    A global corporation is deploying SES Complete using a hybrid model. They have an existing on-premises SEPM managing 10,000 clients and need to enroll it with the ICDm cloud console. The security policy requires that all communication between the SEPM and the cloud must pass through a dedicated, explicit proxy server that requires authentication. Which two actions are required to ensure successful enrollment? (Select TWO).

    Answer and explanation

    Correct answers: B, D

    The Symantec Endpoint Protection Manager itself must be configured to use the proxy for its outbound communications to the cloud console. This is the primary location for setting up this connection.

    For certain SEPM services and the enrollment process itself, SEPM relies on the Windows HTTP Services (WinHTTP). Configuring the proxy at this level ensures that all necessary components can reach the cloud services, supplementing the settings within the SEPM console.

  4. Question 4

    During a security audit, an administrator discovers that the content definitions for a group of isolated servers in a secure network segment are severely outdated. These servers have no internet access. The administrator has access to a Symantec Endpoint Protection Manager (SEPM) with up-to-date content. What is the most efficient method to update the clients in the secure segment?

    Answer and explanation

    Correct answer: C

    This is the standard, supported method for managing air-gapped environments. The LUA server acts as an intermediary, downloading content from Symantec and placing it on an internal web or file share (distribution center). The GUP in the secure segment is then configured to pull from this internal location and distribute the updates to its peers. This is far more scalable and manageable than manual .jdb updates or setting up a full replication partner.

  5. Question 5

    True or False: When an SES Complete policy's Host Integrity check fails for a client, the client is automatically moved to the Quarantine group, regardless of the firewall policy configuration.

    Answer and explanation

    Correct answer: B

    False. A Host Integrity failure does not automatically move a client to a different group. Instead, it typically triggers a firewall rule that applies a more restrictive 'Quarantine' firewall policy to the non-compliant client, limiting its network access until it meets the integrity requirements. The client remains in its original management group.

  6. Question 6

    A hospital is using SES Complete to protect workstations that are frequently moved between wards. They are experiencing performance issues with a critical medical imaging application that writes large temporary files to C:\Temp\ImagingData\. A previous administrator created a folder exception for this path in the Antivirus and Spyware Protection policy. Despite this, SONAR continues to generate detections on the application's processes when they access this directory. Why are the SONAR detections still occurring?

    Answer and explanation

    Correct answer: C

    This is a critical distinction. SONAR monitors process behavior in real-time (API calls, memory access, etc.), not just files at rest. Standard file/folder exceptions are designed for file-based scanning engines. To prevent SONAR from flagging a legitimate application's behavior, a separate SONAR-specific exception (e.g., by application path or hash) must be created in the Exceptions policy.

  7. Question 7

    An administrator is reviewing the sylink.log file on a client that is failing to communicate with its SEPM. The log contains repeated entries of HTTP 407 Proxy Authentication Required. The client is configured with the correct proxy settings in its communication policy. What is the most likely cause of this error?

    Answer and explanation

    Correct answer: B

    The Symantec agent (sylink) runs under the local SYSTEM account. If the proxy server requires user-based authentication (e.g., domain credentials), the SYSTEM account will not have them, leading to an authentication failure (HTTP 407). The proxy credentials specified in the policy are often user-context specific and not available to the SYSTEM account. The solution is often to use a proxy that allows authentication based on machine account or IP address, or to configure proxy bypass for SEPM traffic.

  8. Question 8

    A security analyst needs to create a custom EDR query to hunt for evidence of a specific MITRE ATT&CK technique: T1059.001, PowerShell. The goal is to find any PowerShell command that contains the string IEX (New-Object Net.WebClient).DownloadString. Which search query syntax should be used in the ICDm console's threat hunting interface?

    Answer and explanation

    Correct answer: B

    The ICDm threat hunting query language uses a Lucene-like syntax. The correct format specifies the field (process.name), a colon, and the value (powershell.exe). The AND operator links conditions. For the command line, wildcards (*) are used to match the contained substrings effectively. The other options use incorrect operators (=, CONTAINS) or syntax for this specific interface.

  9. Question 9

    An administrator wants to prevent users from copying sensitive data to any USB storage devices, but must allow specific, company-issued encrypted USB drives to function normally. They also need to allow HID devices like keyboards and mice. What is the most precise way to configure this in the Device Control policy?

    Answer and explanation

    Correct answer: C

    This is the correct, layered approach. First, you block the entire class of devices you want to control ('USB Mass Storage Devices'), which is more efficient than blocking the generic 'USB' class. Then, you add specific, granular exclusions for the hardware you want to permit. Using the unique Device ID (or Hardware ID) for each company-issued encrypted drive ensures only those specific devices are allowed, fulfilling the security requirement precisely.

  10. Question 10

    What is the primary function of the sesinstaller.log file during the installation of the Symantec Agent on a Windows endpoint?

    Answer and explanation

    Correct answer: C

    The sesinstaller.log is the primary troubleshooting tool for failed agent installations. It captures each action performed by the installer, from system checks and file copying to registry modifications and service creation. Any errors that cause the installation to fail or roll back will be recorded in this file, making it essential for diagnostics.

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 226 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon