A financial services company with 15,000 endpoints is designing a new Symantec Endpoint Security Complete (SESC) deployment. The company has a central data center and 50 branch offices with varying bandwidth. The primary goal is to minimize WAN traffic for definition updates while ensuring high availability for policy management. The design proposes two load-balanced Symantec Endpoint Protection Managers (SEPMs) in the data center and Group Update Providers (GUPs) in each branch. How should the SEPMs be configured for replication to meet these requirements?
Answer and explanation
Correct answer: A
For high availability and reduced WAN traffic, the best practice is to configure the SEPMs as replication partners for logs and policies only. Client packages and definitions are large and should be downloaded from the central LiveUpdate source to each SEPM independently, and then distributed to clients via GUPs. Replicating packages would consume significant bandwidth between the SEPMs without adding value in this GUP-based design.
Question 2
Multiple answers
During the assessment phase for an SES Complete implementation at a hospital, an administrator discovers that several critical medical imaging devices run on an unsupported legacy Windows XP Embedded OS. These devices cannot be upgraded but must be protected. Which SES Complete features should be prioritized in the solution design for these specific devices? (Select TWO)
Answer and explanation
Correct answers: A, B
System Lockdown (Application Hardening) is ideal for fixed-function devices like medical equipment. It can create a whitelist of known good applications and block any unauthorized executables from running, effectively preventing malware execution on the unsupported OS.
Since the OS cannot be patched, it is vulnerable to network-based exploits. The Network IPS can block known attack signatures at the network layer, providing a critical compensating control to protect the vulnerable OS from being compromised.
Question 3
An administrator is troubleshooting an issue where SES Complete clients in a specific remote office are not receiving policy updates from the central SEPM. All other offices are functioning correctly. The remote office clients can successfully ping the SEPM server by its IP address. What is the most likely cause of this issue?
Answer and explanation
Correct answer: A
The ability to ping the server confirms basic network connectivity (ICMP), but it does not guarantee that the application-level communication ports (e.g., TCP 8014 or 443) are open. A firewall rule blocking these specific ports for traffic from the remote office's subnet is the most common and logical cause for this type of isolated communication failure.
Question 4
True or False: When configuring a System Lockdown policy in 'blacklist' mode, the policy will block only the applications explicitly listed, and all other unlisted applications will be allowed to run.
Answer and explanation
Correct answer: A
This statement is true. System Lockdown has two modes: whitelist and blacklist. In blacklist mode, it functions as a traditional application blocking tool, preventing only the specified applications (by file hash or path) from executing, while permitting all others.
Question 5
A university is implementing SES Complete across its campus, which includes administrative offices, student labs, and faculty research departments. The security team wants to apply a baseline security policy to all computers but allow specific departments, like computer science, to have more lenient script control settings for academic purposes, without duplicating the entire baseline policy. What is the most efficient method to achieve this in SEPM?
Answer and explanation
Correct answer: A
This is the correct and most efficient design. By creating a child group that inherits from the parent, all baseline settings are automatically applied. Creating a specific, non-shared policy for a single feature (like Application and Device Control) for the child group allows administrators to override just that part of the policy while inheriting all other settings, avoiding policy duplication and simplifying management.
Question 6
An administrator needs to deploy the SES Complete agent to 500 new workstations that have just been imaged and are not yet in Active Directory. The administrator wants to automate the process and ensure the clients are placed in the correct 'New Deployments' group in SEPM upon installation. Which deployment method is best suited for this scenario?
Answer and explanation
Correct answer: C
This is the most efficient and scalable method. Exporting a managed package embeds the communication settings (Sylink.xml) and the target group information directly into the installer. This package can then be easily scripted or included in an imaging process for automated, large-scale deployment, ensuring all clients report to the correct group automatically.
Question 7
What is the primary function of the Integrated Cyber Defense Manager (ICDm) in a hybrid SES Complete environment?
Answer and explanation
Correct answer: B
The core purpose of ICDm is to act as a cloud-based bridge. It enrolls on-premises SEPM domains, allowing administrators to manage both their on-premises and cloud-native endpoints from a single, unified console, and integrates data from other Symantec products like Email Security.cloud.
Question 8
A company has configured SES Complete with a Data Loss Prevention (DLP) policy to block the transfer of files containing credit card numbers to USB drives. A user reports that they are still able to copy a sensitive file to a USB drive without it being blocked. A review of the SES client on the user's machine shows that all policies are up-to-date and the client is communicating with the SEPM. What is the most probable reason for the policy failure?
Answer and explanation
Correct answer: A
Endpoint DLP policies work by scanning file content for defined patterns (like credit card numbers). If a file is placed inside an encrypted container (e.g., a password-protected ZIP file) or is otherwise encrypted before the copy operation, the agent cannot inspect the content. The DLP engine sees an encrypted blob of data, not the sensitive content within, and therefore does not trigger the blocking rule. This is a common method for bypassing content-aware DLP.
Question 9
Case Study: Global Retail Inc.
Company Background: Global Retail Inc. is a multinational corporation with 500 retail stores, three large distribution centers, and a corporate headquarters. Each retail store has 5-10 Point-of-Sale (POS) terminals running Windows 10 IoT Enterprise, a local server, and 2-3 staff workstations. Distribution centers operate 24/7 and use a mix of Windows Server 2019 and specialized logistics systems. Corporate headquarters houses 2,000 employees with standard Windows 11 desktops and laptops.
Current Situation: The company is migrating from a competitor's legacy AV product to Symantec Endpoint Security Complete. The legacy AV has caused performance issues on the POS terminals, leading to transaction delays. The distribution centers have experienced downtime due to false positives quarantining critical logistics application files. Corporate users frequently travel and need consistent protection both on and off the corporate network.
Requirements:
A centralized management solution with role-based access for regional IT teams.
Minimal performance impact on POS terminals and distribution center servers.
Strong protection against fileless malware and ransomware for corporate users.
An efficient content update strategy to minimize bandwidth consumption over the retail stores' business internet connections.
Ensure traveling corporate users receive the latest policies and protection updates promptly.
Problem: You are the implementation specialist tasked with designing the SES Complete architecture and policy structure to meet all of Global Retail's requirements. Which design choice best addresses the unique needs of the POS terminals and distribution centers regarding performance and false positives?
Answer and explanation
Correct answer: A
This is the optimal solution. System Lockdown in whitelist mode is perfect for fixed-function systems like POS terminals, as it provides maximum security with minimal performance overhead by only allowing known good applications to run. For the distribution centers, creating specific, targeted exceptions for the known-good logistics applications prevents false positives without broadly weakening security. This layered approach correctly addresses the specific needs of each environment.
Question 10
When designing a Group Update Provider (GUP) strategy for an organization with many low-bandwidth remote sites, which GUP configuration setting is most critical to prevent a single GUP from becoming overloaded with requests from clients at other sites?
Answer and explanation
Correct answer: B
This is the most effective method for strict control. By creating separate SEPM groups for each physical site and assigning a unique LiveUpdate policy that lists only the local GUP(s) for that site, you ensure that clients can only use their designated GUP. This prevents clients from one site from traversing the WAN to get updates from a GUP at another site, thereby controlling traffic and GUP load.