Symantec Data Loss Prevention 16.x Administration Technical Specialist v1.0

Page:    1 / 5   
Exam contains 66 questions

A DLP administrator needs to remove an agent and its associated events from an Endpoint server.
Which Agent Task should the administrator perform to disable the agent’s visibility in the Enforce management console?

  • A. Delete action from the Agent List page
  • B. Disable action from Symantec Management Console
  • C. Change Endpoint Server action from the Agent Overview page
  • D. Delete action from the Agent Health dashboard


Answer : B

A divisional executive requests a report of all incidents generated by a particular region, summarized by department.
What does the DLP administrator need to configure to generate this report?

  • A. User attributes
  • B. Sender attributes
  • C. Status attributes
  • D. Custom attributes


Answer : A

Which two (2) detection technology options run ONLY on detection servers and NOT on endpoint agents? (Choose two.)

  • A. Indexed Document Matching (IDM)
  • B. Vector Machine Learning (VML)
  • C. Described Content Matching (DCM)
  • D. Exact Data Matching (EDM)
  • E. Form Recognition


Answer : BE

Which server target uses the “Automated Incident Remediation Tracking” feature in Symantec DLP?

  • A. File System High-Speed Discovery
  • B. File System (standard)
  • C. SharePoint
  • D. Exchange


Answer : C

A DLP administrator needs to stop the PacketCapture process on a detection server. Upon inspection of the Server Detail page, the administrator discovers that all processes are missing from the display.
What are the processes missing from the Server Detail page display?

  • A. The detection server Display Control Process option is disabled on the Server Detail page.
  • B. The Display Process Control setting on the Advanced Settings page is disabled.
  • C. The detection server PacketCapture process is displayed on the Server Overview page.
  • D. The Advanced Process Control setting on the System Settings page is deselected.


Answer : B

Which Network Prevent action has taken place when a Network incident snapshot indicates the message has been “Modified”?

  • A. Modify content from the body of an email
  • B. Add one or more SMTP headers to an email
  • C. Obfuscate text in the body of an email
  • D. Remove attachments from an email


Answer : B

What is the first step an administrator should take to improve the performance of Network Monitor when network traffic exceeds 1 Gbps?

  • A. Increase system memory (RAM) for existing Network Prevent Servers.
  • B. Add more Network Prevent Servers to the Symantec DLP environment.
  • C. Filter out all network traffic that is “unreadable” to Network Monitor.
  • D. Install network taps and connect them to existing Network Monitor Servers.


Answer : C

DRAG DROP -
Choose all that apply.



Answer :

Which option correctly describes the two-tier installation type for Symantec DLP?

  • A. Install the Oracle database on one host, and install the Enforce server and a detection server on a second host.
  • B. Install the Oracle database and Enforce server on the same host, and install detection servers on separate hosts.
  • C. Install the Oracle database and a detection server on the same host, and install the Enforce server on a second host.
  • D. Install the Oracle database on a local physical host, and install the Enforce server and detection servers on virtual hosts in the Cloud.


Answer : B

What should an incident responder select in the Enforce management console to remediate multiple incidents simultaneously?

  • A. Smart Response on the Incident Snapshot page
  • B. Automated Response on an Incident List report
  • C. Smart Response on an Incident List report
  • D. Automated Response on the Incident Snapshot page


Answer : C

DRAG DROP -
Choose all that apply.



Answer :

What is the recommended ratio for Enforce servers to Oracle database servers, when deploying Symantec DPL?

  • A. 1:1
  • B. 1:2
  • C. 2:1
  • D. 3:1


Answer : A

What is the correct configuration for “BoxMonitor.Channels” that will allow the server to start as a Network Monitor server?

  • A. Packet Capture, Span Port
  • B. Packet Capture, Network Monitor
  • C. Packet Capture, Network Tap
  • D. Packet Capture, Copy Rule


Answer : B

Which of the following is a good use case for Structured Data Identifiers (SDIs)?

  • A. Detecting the copy of health care data (in tabular format) to USB from endpoint computers
  • B. Detecting confidential financial data contained in XLSX or CSV email attachments
  • C. Detecting partial sections of merger and acquisition documents in Network Discover scans
  • D. Detecting single instances of Personally Identifiable Information (PII) in Endpoint Discover scans


Answer : D

Which statement accurately describes where Optical Character Recognition (OCR) On-Premises DLP Core components must be installed?

  • A. The OCR engine must be installed directly on the Enforce server.
  • B. The OCR engine must be installed on one or more detection servers.
  • C. The OCR server software must by installed on one or more dedicated (non-detection) Windows servers.
  • D. The OCR server software must be installed on one or more dedicated (non-detection) Linux servers.


Answer : C

Page:    1 / 5   
Exam contains 66 questions

Talk to us!


Have any questions or issues ? Please dont hesitate to contact us

Certlibrary.com is owned by MBS Tech Limited: Room 1905 Nam Wo Hong Building, 148 Wing Lok Street, Sheung Wan, Hong Kong. Company registration number: 2310926
Certlibrary doesn't offer Real Microsoft Exam Questions. Certlibrary Materials do not contain actual questions and answers from Cisco's Certification Exams.
CFA Institute does not endorse, promote or warrant the accuracy or quality of Certlibrary. CFA® and Chartered Financial Analyst® are registered trademarks owned by CFA Institute.
Terms & Conditions | Privacy Policy | Amazon Exams | Cisco Exams | CompTIA Exams | Databricks Exams | Fortinet Exams | Google Exams | Microsoft Exams | VMware Exams