Symantec Web Protection—Edge SWG R2 Technical Specialist Free Sample Questions

20 free sample questions198 in the full practice test

Try simulator

250-589 Sample Questions

  1. Question 1

    A financial services company is experiencing intermittent connectivity issues with a critical banking application that uses mutual TLS (mTLS) for client-server authentication. The issues began after deploying Edge SWG with full SSL interception. A policy trace reveals that the Edge SWG is attempting to intercept the traffic, causing the mTLS handshake to fail. Which configuration change is the most effective and secure method to resolve this issue?

    Answer and explanation

    Correct answer: C

    Mutual TLS (mTLS) requires both the client and server to present valid certificates. SSL interception breaks this process because the Edge SWG presents its own emulated certificate to the client. The correct solution is to bypass interception for this specific traffic. Using the Server Certificate Common Name in the SSL Interception Layer is a precise and secure way to create this bypass, ensuring only the intended application traffic is excluded from inspection. Installing the client's private key on the proxy is a significant security risk, and disabling protocol detection is too broad and may have unintended consequences.

  2. Question 2

    A network administrator is configuring IWA direct authentication on an Edge SWG appliance. Despite correctly configuring the realm and joining the domain, users are still being prompted for credentials. A packet capture shows that client requests to the Edge SWG lack the necessary Kerberos ticket. Which of the following is the most likely cause of this issue?

    Answer and explanation

    Correct answer: B

    For IWA to function transparently, the client browser must recognize the proxy as part of the Local Intranet zone. This setting allows the browser to automatically send the user's Kerberos ticket with the request. If the proxy's hostname or IP is not in this zone, the browser will treat it as an external site and will not send the authentication ticket, resulting in a credential prompt. While time sync issues and incorrect SPNs can cause IWA failures, the lack of a Kerberos ticket in the initial request points directly to a client-side zone configuration problem.

  3. Question 3

    Multiple answers

    An administrator needs to create a policy that isolates all web traffic destined for newly registered domains, as these are considered high-risk. Which TWO components are essential to build this policy in the Visual Policy Manager (VPM)? (Select TWO)

    Answer and explanation

    Correct answers: A, B

    To implement this policy, an administrator needs a Web Access Layer to define the traffic handling rule. The destination must be configured to match the 'Newly Registered Domains' category, which is provided by Symantec's categorization services. The action would then be set to trigger High Risk Isolation. A 'Threat Risk Level' object is for risk scores, not domain age, and an 'SSL Access Layer' is for controlling the initial SSL handshake, not for applying isolation based on content category.

  4. Question 4

    A multinational corporation uses Management Center to administer a fleet of Edge SWG appliances across different geographical regions. The security team needs to deploy a new, urgent VPM policy to block a zero-day threat, but only to the appliances in the European region. What is the most efficient method to achieve this in Management Center?

    Answer and explanation

    Correct answer: B

    Management Center is designed for centralized administration. The most efficient and scalable method is to organize appliances into logical groups (e.g., by region). A job can then be created to distribute the policy file specifically to the 'European' device group. This ensures targeted deployment without affecting other regions and provides a clear audit trail. Distributing to all devices is incorrect, and manual configuration defeats the purpose of centralized management.

  5. Question 5

    True or False: When Edge SWG is integrated with a Content Analysis appliance via ICAP, the Edge SWG is solely responsible for performing the actual malware scanning of files.

    Answer and explanation

    Correct answer: B

    This statement is false. In an ICAP integration, the Edge SWG acts as the ICAP client. It intercepts the traffic and, based on policy, forwards the content (e.g., a file download) to the Content Analysis appliance (the ICAP server). The Content Analysis appliance is the component that performs the actual malware scanning, sandboxing, and analysis, and then sends a response back to the Edge SWG indicating whether the content is clean or malicious.

  6. Question 6

    A hospital is deploying an Edge SWG in transparent mode to filter traffic for all devices on its network, including medical IoT devices that cannot be configured with explicit proxy settings. The primary goal is to prevent these devices from accessing known malicious command-and-control (C2) servers while allowing legitimate vendor update traffic. What is the most critical initial configuration step to ensure traffic is correctly intercepted?

    Answer and explanation

    Correct answer: C

    In a transparent deployment, client devices are unaware of the proxy. Therefore, traffic must be redirected to the Edge SWG at the network level. This is typically done using methods like Web Cache Communication Protocol (WCCP) or Policy Based Routing (PBR) on a router or Layer 3 switch that sits in the traffic path. This device is configured to identify web traffic and forward it to the proxy for inspection. Manually configuring routes on unmanageable IoT devices is not feasible, and installing SSL certificates is a step for decryption, not initial interception.

  7. Question 7

    During a security audit, it was discovered that the research department is using unsanctioned cloud storage applications. An administrator is tasked with creating a policy to block access to all 'Cloud Storage' category websites, EXCEPT for the company-approved application, 'corp-storage.com'. What is the best practice for structuring the rules in the VPM Web Access Layer to achieve this?

    Answer and explanation

    Correct answer: C

    VPM policies are evaluated from top to bottom, and the first matching rule determines the outcome. To create an exception, the more specific 'Allow' rule must be placed before the broader 'Deny' rule. A rule allowing access to 'corp-storage.com' should be first. Any request for that site will match this rule and be allowed, and policy processing for that layer stops. All other requests for sites in the 'Cloud Storage' category will not match the first rule, fall through to the second rule, and be denied. Placing the Deny rule first would block all cloud storage, including the allowed site.

  8. Question 8

    A system administrator is reviewing the health checks on an Edge SWG appliance and notices that the 'TCP-IP' health check is showing a 'critical' status. What does this status most likely indicate?

    Answer and explanation

    Correct answer: C

    The 'TCP-IP' health check specifically monitors the state of the networking stack, including the number of concurrent connections. A 'critical' status for this check typically means that the appliance is approaching or has reached its maximum configured limit for concurrent client connections. This indicates network pressure or a potential connection leak issue, but it is distinct from high CPU or memory usage, which are monitored by different health checks.

  9. Question 9

    What is the primary function of the sysinfo file when troubleshooting an issue with an Edge SWG appliance?

    Answer and explanation

    Correct answer: C

    The sysinfo file is a critical diagnostic tool that generates a detailed, point-in-time report of the Edge SWG's entire state. This includes hardware status, SGOS version, licensing, network configuration, running configuration, performance statistics, and logs. It is the primary file requested by Symantec support for offline analysis of an appliance's health and configuration to diagnose complex issues.

  10. Question 10

    A company wants to prevent employees from uploading sensitive documents to any website categorized as 'Personal Storage' or 'Social Networking'. Which Symantec Web Protection component and protocol are primarily used to inspect the content of these uploads for policy enforcement?

    Answer and explanation

    Correct answer: D

    To inspect the content of file uploads (HTTP POST requests), the Edge SWG must forward the data to a device capable of deep content inspection. The Content Analysis appliance serves this role. The standard protocol for this communication is the Internet Content Adaptation Protocol (ICAP). A policy on the Edge SWG would trigger an ICAP request to Content Analysis for matching uploads, which would then scan the content and return a verdict.

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 198 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon