Want to know Ucertify 250-438 Exam practice test features? Want to lear more about Symantec Administration of Symantec Data Loss Prevention 15 certification experience? Study 100% Guarantee Symantec 250-438 answers to Leading 250-438 questions at Ucertify. Gat a success with an absolute guarantee to pass Symantec 250-438 (Administration of Symantec Data Loss Prevention 15) test on your first attempt.
Symantec 250-438 Free Dumps Questions Online, Read and Test Now.
NEW QUESTION 1
Which two actions are available for a “Network Prevent: Remove HTTP/HTTPS content” response rule when the content is unable to be removed? (Choose two.)
- A. Allow the content to be posted
- B. Remove the content through FlexResponse
- C. Block the content before posting
- D. Encrypt the content before posting
- E. Redirect the content to an alternative destination
Answer: AE
NEW QUESTION 2
Refer to the exhibit.
What activity should occur during the baseline phase, according to the risk reduction model?
- A. Define and build the incident response team
- B. Monitor incidents and tune the policy to reduce false positives
- C. Establish business metrics and begin sending reports to business unit stakeholders
- D. Test policies to ensure that blocking actions minimize business process disruptions
Answer: C
NEW QUESTION 3
Which two Infrastructure-as-a-Service providers are supported for hosting Cloud Prevent for Office 365? (Choose two.)
- A. Any customer-hosted private cloud
- B. Amazon Web Services
- C. AT&T
- D. Verizon
- E. Rackspace
Answer: BE
NEW QUESTION 4
Which server target uses the “Automated Incident Remediation Tracking” feature in Symantec DLP?
- A. Exchange
- B. File System
- C. Lotus Notes
- D. SharePoint
Answer: B
Explanation:
Reference: https://help.symantec.com/cs/DLP15.0/DLP/v83981880_v120691346/Troubleshooting-automated-incident-remediation-tracking?locale=EN_US
NEW QUESTION 5
What is the default fallback option for the Endpoint Prevent Encrypt response rule?
- A. Block
- B. User Cancel
- C. Encrypt
- D. Notify
Answer: D
NEW QUESTION 6
Which two locations can Symantec DLP scan and perform Information Centric Encryption (ICE) actions on? (Choose two.)
- A. Exchange
- B. Jiveon
- C. File store
- D. SharePoint
- E. Confluence
Answer: CD
Explanation:
Reference: https://www.symantec.com/content/dam/symantec/docs/data-sheets/information-centric-encryption-en.pdf
NEW QUESTION 7
What detection technology supports partial contents matching?
- A. Indexed Document Matching (IDM)
- B. Described Content Matching (DCM)
- C. Exact Data Matching (EDM)
- D. Optical Character Recognition (OCR)
Answer: A
Explanation:
Reference: https://help.symantec.com/cs/dlp15.1/DLP/v115965297_v125428396/Mac-agent-detection-technologies?locale=EN_US
NEW QUESTION 8
Which two detection technology options ONLY run on a detection server? (Choose two.)
- A. Form Recognition
- B. Indexed Document Matching (IDM)
- C. Described Content Matching (DCM)
- D. Exact Data Matching (EDM)
- E. Vector Machine Learning (VML)
Answer: BD
Explanation:
Reference: https://support.symantec.com/en_US/article.INFO5070.html
NEW QUESTION 9
A DLP administrator determines that the SymantecDLPProtectIncidents folder on the Enforce server contains. BAD files dated today, while other. IDC files are flowing in and out of the Incidents directory. Only .IDC files larger than 1MB are turning to .BAD files.
What could be causing only incident data smaller than 1MB to persist while incidents larger than 1MB change to .BAD files?
- A. A corrupted policy was deployed.
- B. The Enforce server’s hard drive is out of space.
- C. A detection server has excessive filereader restarts.
- D. Tablespace is almost full.
Answer: D
NEW QUESTION 10
An organization wants to restrict employees to copy files only a specific set of USB thumb drives owned by the organization.
Which detection method should the organization use to meet this requirement?
- A. Exact Data Matching (EDM)
- B. Indexed Document Matching (IDM)
- C. Described Content Matching (DCM)
- D. Vector Machine Learning (VML)
Answer: D
NEW QUESTION 11
Refer to the exhibit. Which type of Endpoint response rule is shown?
- A. Endpoint Prevent: User Notification
- B. Endpoint Prevent: Block
- C. Endpoint Prevent: Notify
- D. Endpoint Prevent: User Cancel
Answer: B
Explanation:
Reference: https://help.symantec.com/cs/dlp15.0/DLP/v27595430_v120691346/Configuring-the-Endpoint-Prevent:-Block-action?locale=EN_US
NEW QUESTION 12
Which Network Prevent action takes place when the Network Incident list shows the message is “Modified”?
- A. Remove attachments from an email
- B. Obfuscate text in the body of an email
- C. Add one or more SMTP headers to an email
- D. Modify content from the body of an email
Answer: C
NEW QUESTION 13
An administrator is unable to log in to the Enforce management console as “sysadmin”. Symantec DLP is configured to use Active Directory authentication. The administrator is a member of two roles: “sysadmin” and “remediator.” How should the administrator log in to the Enforce console with the “sysadmin” role?
- A. sysadminusername
- B. sysadminusername@domain
- C. domainusername
- D. usernamesysadmin
Answer: C
NEW QUESTION 14
A DLP administrator needs to stop the PacketCapture process on a detection server. Upon inspection of the Server Detail page, the administrator discovers that all processes are missing from the display. What are the processes missing from the Server Detail page display?
- A. The Display Process Control setting on the Advanced Settings page is disabled.
- B. The Advanced Process Control setting on the System Settings page is deselected.
- C. The detection server Display Control Process option is disabled on the Server Detail page.
- D. The detection server PacketCapture process is displayed on the Server Overview page.
Answer: B
Explanation:
Reference: https://support.symantec.com/content/unifiedweb/en_US/article.TECH220250.html
NEW QUESTION 15
A DLP administrator is preparing to install Symantec DLP and has been asked to use an Oracle database provided by the Database Administration team. Which SQL *Plus command should the administrator utilize to determine if the database is using a supported version of Oracle?
- A. select database version from <database name>;
- B. select * from db$version;
- C. select * from v$version;
- D. select db$ver from <database name>;
Answer: C
Explanation:
Reference: https://www.symantec.com/connect/forums/new-install-oracle-returns-error
NEW QUESTION 16
DRAG DROP
The Symantec Data Loss risk reduction approach has six stages.
Drag and drop the six correct risk reduction stages in the proper order of Occurrence column.
Select and Place:
- A. Mastered
- B. Not Mastered
Answer: A
Explanation:
Reference: https://www.slideshare.net/iftikhariqbal/symantec-data-loss-prevention-technical-proposal-general
NEW QUESTION 17
Which service encrypts the message when using a Modify SMTP Message response rule?
- A. Network Monitor server
- B. SMTP Prevent
- C. Enforce server
- D. Encryption Gateway
Answer: D
Explanation:
Reference: https://www.symantec.com/connect/articles/network-prevent
NEW QUESTION 18
A DLP administrator is attempting to add a new Network Discover detection server from the Enforce management console. However, the only available options are Network Monitor and Endpoint servers. What should the administrator do to make the Network Discover option available?
- A. Restart the Symantec DLP Controller service
- B. Apply a new software license file from the Enforce console
- C. Install a new Network Discover detection server
- D. Restart the Vontu Monitor Service
Answer: C
NEW QUESTION 19
What is the correct configuration for “BoxMonitor.Channels” that will allow the server to start as a Network Monitor server?
- A. Packet Capture, Span Port
- B. Packet Capture, Network Tap
- C. Packet Capture, Copy Rule
- D. Packet capture, Network Monitor
Answer: C
Explanation:
Reference: https://support.symantec.com/en_US/article.TECH218980.html
NEW QUESTION 20
Which two components can perform a file system scan of a workstation? (Choose two.)
- A. Endpoint Server
- B. DLP Agent
- C. Network Prevent for Web Server
- D. Discover Server
- E. Enforce Server
Answer: BD
NEW QUESTION 21
What detection server is used for Network Discover, Network Protect, and Cloud Storage?
- A. Network Protect Storage Discover
- B. Network Discover/Cloud Storage Discover
- C. Network Prevent/Cloud Detection Service
- D. Network Protect/Cloud Detection Service
Answer: B
Explanation:
Reference: https://help.symantec.com/cs/dlp15.0/DLP/v16110606_v120691346/Modifying-the-Network-Discover-Cloud-Storage-Discover-Server-configuration?locale=EN_US
NEW QUESTION 22
Which action should a DLP administrator take to secure communications between an on-premises Enforce server and detection servers hosted in the Cloud?
- A. Use the built-in Symantec DLP certificate for the Enforce Server, and use the “sslkeytool” utility to create certificates for the detection servers.
- B. Use the built-in Symantec DLP certificate for both the Enforce server and the hosted detection servers.
- C. Set up a Virtual Private Network (VPN) for the Enforce server and the hosted detection servers.
- D. Use the “sslkeytool” utility to create certificates for the Enforce server and the hosted detection servers.
Answer: A
Explanation:
Reference: https://www.symantec.com/connect/articles/sslkeytool-utility-and-server-certificates
NEW QUESTION 23
A DLP administrator has performed a test deployment of the DLP 15.0 Endpoint agent and now wants to uninstall the agent. However, the administrator no longer remembers the uninstall password. What should the administrator do to work around the password problem?
- A. Apply a new global agent uninstall password in the Enforce management console.
- B. Manually delete all the Endpoint agent files from the test computer and install a new agent package.
- C. Replace the PGPsdk.dll file on the agent’s assigned Endpoint server with a copy from a different Endpoint server
- D. Use the UninstallPwdGenerator to create an UninstallPasswordKey.
Answer: D
NEW QUESTION 24
......
100% Valid and Newest Version 250-438 Questions & Answers shared by Dumps-hub.com, Get Full Dumps HERE: https://www.dumps-hub.com/250-438-dumps.html (New 70 Q&As)
