Symantec 250-428 Administration of Symantec Endpoint Protection 14 Online Training
Symantec 250-428 Online Training
The questions for 250-428 were last updated at Jul 17,2025.
- Exam Code: 250-428
- Exam Name: Administration of Symantec Endpoint Protection 14
- Certification Provider: Symantec
- Latest update: Jul 17,2025
An administrator is troubleshooting a Symantec Endpoint Protection (SEP) replication.
Which component log should the administrator check to determine whether the communication between the two sites is working correctly?
- A . Tomcat
- B . Apache Web Server
- C . Group Update Provider (GUP)
- D . SQL Server
What is a function of Symantec Insight?
- A . Provides reputation ratings for binary executables
- B . Enhances the capability of Group Update Providers (GUP)
- C . Provides reputation ratings for structured data
- D . Increases the efficiency and effectiveness of LiveUpdate
Which two options are available when configuring DNS change detections for SONAR? (Select two.)
- A . Log
- B . Quarantine
- C . Block
- D . Active Response
- E . Trace
How are Insight results stored?
- A . Encrypted on the Symantec Endpoint Protection Client
- B . Unencrypted on the Symantec Endpoint Protection Manager
- C . Encrypted on the Symantec Endpoint Protection Manager
- D . Unencrypted on the Symantec Endpoint Protection Client
Which option is unavailable in the Symantec Endpoint Protection console to run a command on the group menu item?
- A . Disable SONAR
- B . Scan
- C . Disable Network Threat Protection
- D . Update content and scan
A Symantec Endpoint Protection administrator must block traffic from an attacking computer for a specific time period.
Where should the administrator adjust the time to block the attacking computer?
- A . In the group policy, under External Communication settings
- B . In the group policy, under Communication settings
- C . In the firewall policy, under Protection and Stealth
- D . In the firewall policy, under Built in Rules
Which option is a function of the Symantec Endpoint Protection client?
- A . Sends and receives application reputation ratings from LiveUpdate
- B . Uploads logs to the Shared Insight Cache
- C . Downloads virus content updates from Symantec Insight
- D . Provides a Lotus Notes email scanner
Which two instances could cause Symantec Endpoint Protection to be unable to remediate a file? (Select two.)
- A . Another scan is in progress.
- B . The detected file is in use.
- C . The file has good reputation.
- D . There are insufficient file permissions.
- E . The file is marked for deletion by Windows on restart.
A company has 10,000 Symantec Endpoint Protection (SEP) clients deployed using two Symantec Endpoint Protection Managers (SEPMs).
Which configuration is recommended to ensure that each SEPM is able to effectively handle the communications load with the SEP clients?
- A . Pull mode
- B . Push mode
- C . Server control mode
- D . Client control mode
An administrator is responsible for the Symantec Endpoint Protection architecture of a large, multinational company with three regionalized data centers. The administrator needs to collect data from clients; however, the collected data must stay in the local regional data center. Communication between the regional data centers is allowed 20 hours a day.
How should the administrator architect this organization?
- A . Set up 3 domains
- B . Set up 3 sites
- C . Set up 3 groups
- D . Set up 3 locations