What is the default fallback option for the Endpoint Prevent Encrypt response rule?
A . Block
B . User Cancel
C . Encrypt
D . Notify
Answer: D
250-438 Administration of Symantec Data Loss Prevention 15 exam is a hot Symantec certification exam, Exam4Training offers you the latest free online 250-438 dumps to practice. You can get online training in the following questions, all these questions are verified by Symantec experts. If this exam changed, we will share new update questions.
What is the default fallback option for the Endpoint Prevent Encrypt response rule?
A . Block
B . User Cancel
C . Encrypt
D . Notify
Answer: D
Which server target uses the “Automated Incident Remediation Tracking” feature in Symantec DLP?
A . Exchange
B . File System
C . Lotus Notes
D . SharePoint
Answer: B
Explanation:
Reference: https://help.symantec.com/cs/DLP15.0/DLP/v83981880_v120691346/Troubleshootingautomated-incident-remediation-tracking?locale=EN_US
Which two detection technology options run on the DLP agent? (Choose two.)
A . Optical Character Recognition (OCR)
B . Described Content Matching (DCM)
C . Directory Group Matching (DGM)
D . Form Recognition
E . Indexed Document Matching (IDM)
Answer: BE
Which action should a DLP administrator take to secure communications between an on-premises Enforce server and detection servers hosted in the Cloud?
A . Use the built-in Symantec DLP certificate for the Enforce Server, and use the “sslkeytool” utility to create certificates for the detection servers.
B . Use the built-in Symantec DLP certificate for both the Enforce server and the hosted detection servers.
C . Set up a Virtual Private Network (VPN) for the Enforce server and the hosted detection servers.
D . Use the “sslkeytool” utility to create certificates for the Enforce server and the hosted detection servers.
Answer: A
Explanation:
Reference: https://www.symantec.com/connect/articles/sslkeytool-utility-and-server-certificates
A divisional executive requests a report of all incidents generated by a particular region, summarized by department.
What does the DLP administrator need to configure to generate this report?
A . Custom attributes
B . Status attributes
C . Sender attributes
D . User attributes
Answer: A
Which detection method depends on “training sets”?
A . Form Recognition
B . Vector Machine Learning (VML)
C . Index Document Matching (IDM)
D . Exact Data Matching (IDM)
Answer: B
Explanation:
Reference: http://eval.symantec.com/mktginfo/enterprise/white_papers/b-dlp_machine_learning.WP_enus.pdf
Which two Infrastructure-as-a-Service providers are supported for hosting Cloud Prevent for Office 365? (Choose two.)
A . Any customer-hosted private cloud
B . Amazon Web Services
C . AT&T
D . Verizon
E . Rackspace
Answer: BE
Explanation:
Reference: https://symwisedownload.symantec.com//resources/sites/SYMWISE/content/live/ DOCUMENTATION/8000/DOC8244/en_US/Symantec_DLP_15.0_Cloud_Prevent_O365.pdf? __gda__=1554430310_584ffada3918e15ced8b6483a2bfb6fb (14)
Which two components can perform a file system scan of a workstation? (Choose two.)
A . Endpoint Server
B . DLP Agent
C . Network Prevent for Web Server
D . Discover Server
E . Enforce Server
Answer: BD
A DLP administrator has added several approved endpoint devices as exceptions to an Endpoint Prevent policy that blocks the transfer of sensitive data.
However, data transfers to these devices are still being blocked.
What is the first action an administrator should take to enable data transfers to the approved endpoint devices?
A . Disable and re-enable the Endpoint Prevent policy to activate the changes
B . Double-check that the correct device ID or class has been entered for each device
C . Verify Application File Access Control (AFAC) is configured to monitor the specific application
D . Edit the exception rule to ensure that the “Match On” option is set to “Attachments”
Answer: D
A DLP administrator needs to stop the PacketCapture process on a detection server. Upon inspection of the Server Detail page, the administrator discovers that all processes are missing from the display.
What are the processes missing from the Server Detail page display?
A . The Display Process Control setting on the Advanced Settings page is disabled.
B . The Advanced Process Control setting on the System Settings page is deselected.
C . The detection server Display Control Process option is disabled on the Server Detail page.
D . The detection server PacketCapture process is displayed on the Server Overview page.
Answer: B
Explanation:
Reference: https://support.symantec.com/content/unifiedweb/en_US/article.TECH220250.html