显示标签为“250-511”的博文。显示所有博文
显示标签为“250-511”的博文。显示所有博文

2014年2月26日星期三

Dernières Symantec 250-511 examen pratique questions et réponses

Il y a beaucoup de gans ambitieux dansn l'Industrie IT. Pour monter à une autre hauteur dans la carrière, et être plus proche du pic de l'Industrie IT. On peut choisir le test Symantec 250-511 à se preuver. Mais le taux du succès et bien bas. Participer le test Symantec 250-511 est un choix intelligent. Dans l'Industrie IT de plus en plus intense, on doit trouver une façon à s'améliorer. Vous pouvez chercher plusieurs façons à vous aider pour réussir le test.

Les experts de Pass4Test ont fait sortir un nouveau guide d'étude de Certification Symantec 250-511, avec ce guide d'étude, réussir ce test a devenu une chose pas difficile. Pass4Test vous permet à réussir 100% le test Symantec 250-511 à la première fois. Les questions et réponses vont apparaître dans le test réel. Pass4Test peut vous donner une Q&A plus complète une fois que vous choisissez nous. D'ailleurs, la mise à jour gratuite pendant un an est aussi disponible pour vous.

Il y a nombreux façons à vous aider à réussir le test Symantec 250-511. Le bon choix est l'assurance du succès. Pass4Test peut vous offrir le bon outil de formation, lequel est une documentation de qualité. La Q&A de test Symantec 250-511 est recherchée par les experts selon le résumé du test réel. Donc l'outil de formation est de qualité et aussi autorisé, votre succès du test Symantec 250-511 peut bien assuré. Nous allons mettre le jour successivement juste pour répondre les demandes de tous candidats.

Différentes façons peuvent atteindre le même but, ça dépend laquelle que vous prenez. Beaucoup de gens choisissent le test Symantec 250-511 pour améliorer la vie et la carrière. Mais tous les gens ont déjà participé le test Symantec 250-511, ils savent qu'il est difficile à réussir le test. Il y a quelques dépensent le temps et l'argent, mais ratent finalement.

Selon les anciens test Symantec 250-511, la Q&A offerte par Pass4Test est bien liée avec le test réel.

Pass4Test est un site web de vous offrir particulièrement les infos plus chaudes à propos de test Certification Symantec 250-511. Pour vous assurer à nous choisir, vous pouvez télécharger les Q&As partielles gratuites. Pass4Test vous promet un succès 100% du test Symantec 250-511.

Le Pass4Test est un site qui peut offrir les facilités aux candidats et aider les candidats à réaliser leurs rêve. Si vous êtes souci de votre test Certification, Pass4Test peut vous rendre heureux. La haute précision et la grande couverture de la Q&A de Pass4Test vous aidera pendant la préparation de test. Vous n'aurez aucune raison de regretter parce que Pass4Test réalisera votre rêve.

Code d'Examen: 250-511
Nom d'Examen: Symantec (Administration of Symantec(TM) Data Loss Prevention 11)
Questions et réponses: 176 Q&As

250-511 Démo gratuit à télécharger: http://www.pass4test.fr/250-511.html

NO.1 An administrator is running a Discover Scanner target scan and the scanner is unable to communicate
back to the Discover Server. Where will the files be stored?
A. Discover Server incoming folder
B. scanner's outgoing folder
C. scanner's incoming folder
D. Enforce incident persister
Answer: B

Symantec   250-511   250-511

NO.2 Which two remediation actions are available for Network Protect? (Select two.)
A. Copy
B. Move
C. Block
D. Rename
E. Quarantine
Answer: A,E

Symantec   250-511   250-511   certification 250-511   250-511

NO.3 To manually troubleshoot DLP Agent issues, the database and log viewer tools must be executed in
which location?
A. in the same location as the dcs.ead file location
B. in the same location as the cg.ead file location
C. in the same location as the ks.ead file location
D. in the same location as the is.ead file location
Answer: C

Symantec   certification 250-511   250-511   250-511

NO.4 Which product provides support for the Citrix XenApp virtualization platform?
A. Endpoint Prevent
B. Network Discover
C. Network Protect
D. Network Prevent
Answer: A

Symantec   250-511   250-511   250-511   certification 250-511

NO.5 A role is configured for XML export and a user executes the export XML incident action. What must be
done before history information is included in the export?
A. A remediator must take an action on the incident.
B. History must be enabled as a tab or panel in the incident snapshot layout.
C. Incident history must be enabled in the user's role.
D. The manager.properties must be configured for XML export.
Answer: C

Symantec examen   250-511   certification 250-511   250-511   certification 250-511

NO.6 Where should the Network Discover detection server be placed in a corporate network architecture?
A. inside the DMZ
B. on the same virtual LAN as the proxy server
C. inside the corporate network
D. on the same switch as the Oracle database server
Answer: C

certification Symantec   250-511 examen   250-511 examen

NO.7 Which two functions of the communications architecture ensure that the system will automatically
recover if a network connectivity failure occurs between the detection servers and the Enforce Server?
(Select two.)
A. Oracle database backup
B. detection server autonomous monitoring
C. Enforce Server offline alert notification
D. detection server incident queuing
E. detection server alert archiving
Answer: B,D

certification Symantec   250-511 examen   250-511   250-511 examen

NO.8 The database is full and the Incident Persister is unable to process incidents. Which two file types
could be present in Vontu/protect/incidents? (Select two.)
A. .idx
B. .edc
C. .idc
D. .inc
E. .bad
Answer: C,E

certification Symantec   250-511 examen   250-511

NO.9 What are two benefits of the Symantec Data Loss Prevention 11 security architecture? (Select two.)
A. Communication is initiated by the detection servers inside the firewall.
B. SSL communication is used for user access to the Enforce Platform.
C. Endpoint Agent to Endpoint Server communication uses the Triple Data Encryption Standard (Triple
DES).
D. Confidential information captured by system components is stored using Advanced Encryption
Standards (AES) symmetric keys.
E. All indexed data uploaded into the Enforce Platform is protected with a two-way hash.
Answer: B,D

certification Symantec   certification 250-511   250-511   250-511 examen   250-511 examen

NO.10 After installing several new DLP Agents, the Data Loss Prevention administrator discovers that none of
the endpoint agents are appearing on the Agent Overview page. After refreshing the page several times,
and determining that the equipment is powered on and connected to the network, the Agent Overview
page still fails to display the new agents. What is a possible cause for this issue?
A. The DLP Agents need to be added manually through the Symantec Management Platform.
B. The DLP Agents were installed with the incorrect Endpoint server IP address.
C. The assigned Endpoint server needs to be recycled in order to detect the new DLP Agents.
D. The Endpoint Location is set to "Manually" instead of "Automatically" in the Enforce user interface.
Answer: B

Symantec examen   250-511   250-511 examen

NO.11 A company needs to scan all of its file shares on a weekly basis to make sure sensitive data is being
stored correctly. The total volume of data on the file servers is greater than 1 TB. Which approach will
allow the company to quickly scan all of this data on a weekly basis?
A. run an initial complete scan of all the file shares, then modify the scan target to add date filters and
exclude any files created or modified before the initial scan was run
B. run an initial complete scan of all the file shares, then modify the scan target to an incremental scan
type
C. create a separate scan target for each file share and exclude files accessed before the start of each
scan
D. run an initial complete scan of all file shares, create a summary report of all incidents created by the
scan, then run weekly scans and compare incidents from weekly scans to incidents from the complete
scan
Answer: B

Symantec   certification 250-511   250-511   certification 250-511   250-511 examen   250-511

NO.12 A user is unable to log in as sysadmin. The Data Loss Prevention system is configured to use Active
Directory authentication. The user is a member of two roles, sysadmin and remediator. How should the
user log in to the user interface in the sysadmin role?
A. sysadmin\username@domain
B. sysadmin\username
C. domain\username
D. sysadmin\username\domain
Answer: B

Symantec   250-511   250-511

NO.13 A Data Loss Prevention administrator notices that several errors occurred during a Network Discover
scan. Which report can the administrator use to determine exactly which errors occurred and when?
A. Discover Incident report sorted by target name and scan
B. Full Activity report for that particular scan
C. Server Event report from Server Overview
D. Full Statistics report for that particular scan
Answer: B

certification Symantec   certification 250-511   250-511 examen   250-511 examen   250-511

NO.14 A divisional executive requests a report of all incidents generated by a particular region, summarized
by department. What must be populated to generate this report?
A. remediation attributes
B. sender correlations
C. status groups
D. custom attributes
Answer: D

Symantec   250-511 examen   certification 250-511   250-511   certification 250-511

NO.15 What is a feature of keyword proximity matching?
A. It will match on whole keywords only.
B. It has a maximum distance between keywords of 99.
C. It only matches on message body.
D. It evaluates each keyword pair independently.
Answer: D

certification Symantec   250-511   250-511   250-511 examen

NO.16 Which Network Discover option is used to determine whether confidential data exists without having to
scan the entire target?
A. Byte Throttling
B. File Throttling
C. Match Thresholds
D. Inventory Mode Scanning
Answer: D

Symantec   250-511 examen   250-511

NO.17 How can an administrator validate that once a policy is updated and saved it has been enabled on a
specific detection server?
A. check the status of the policy on the policy list page
B. check to see whether the policy was loaded under System > Servers > Alerts
C. check the policy and validate the date and time it was last updated
D. check to see whether the policy was loaded under System > Servers > Events
Answer: D

certification Symantec   250-511   250-511   250-511 examen

NO.18 Which two policy management actions can result in a reduced number of incidents for a given traffic
flow? (Select two.)
A. adding additional component matching to the rule
B. adding data owner exceptions
C. deploying to additional detection servers
D. increasing condition match count
E. adding additional severities
Answer: B,D

Symantec   250-511   250-511   250-511

NO.19 Which DLP Agent task is unique to the Symantec Management Platform and is unavailable through
the Enforce console?
A. Change Endpoint server
B. Restart agent
C. Pull agent logs
D. Set log level
Answer: D

Symantec examen   250-511   250-511   250-511   250-511

NO.20 What must a policy manager do when working with Exact Data Matching (EDM) indexes?
A. re-index large data sources on a daily or weekly basis
B. index the original data source on the detection server
C. deploy the index only to specific detection servers
D. create a new data profile if data source schema changes
Answer: D

Symantec   250-511 examen   250-511 examen   certification 250-511   250-511 examen

Pass4Test provide non seulement le produit de qualité, mais aussi le bon service. Si malheureusement vous ne pouvez pas réussir le test, votre argent sera tout rendu. Le service de la mise à jour gratuite est aussi pour vous bien que vous passiez le test Certification.

2013年9月21日星期六

Dernières Symantec 250-511 examen pratique questions et réponses

Certification Symantec 250-511 est un des tests plus importants dans le système de Certification Symantec. Les experts de Pass4Test profitent leurs expériences et connaissances professionnelles à rechercher les guides d'étude à aider les candidats du test Symantec 250-511 à réussir le test. Les Q&As offertes par Pass4Test vous assurent 100% à passer le test. D'ailleurs, la mise à jour pendant un an est gratuite.

Vous pouvez télécharger tout d'abord le démo gratuit pour prendre un essai. Vous serez confiant davantage sur Pass4Test après l'essai de démo. Vous allez réussir le test Symantec 250-511 sans aucune doute si vous choisissez le Pass4Test.

Pass4Test vous permet à réussir le test Certification sans beaucoup d'argents et de temps dépensés. La Q&A Symantec 250-511 est recherchée par Pass4Test selon les résumés de test réel auparavant, laquelle est bien liée avec le test réel.

Pass4Test est un bon site d'offrir la facilité aux candidats de test Symantec 250-511. Selon les anciens test, l'outil de formation Symantec 250-511 est bien proche de test réel.

Code d'Examen: 250-511
Nom d'Examen: Symantec (Administration of Symantec(TM) Data Loss Prevention 11)
Questions et réponses: 176 Q&As

250-511 Démo gratuit à télécharger: http://www.pass4test.fr/250-511.html

NO.1 Which two remediation actions are available for Network Protect? (Select two.)
A. Copy
B. Move
C. Block
D. Rename
E. Quarantine
Answer: A,E

certification Symantec   certification 250-511   certification 250-511

NO.2 A company needs to scan all of its file shares on a weekly basis to make sure sensitive data is being
stored correctly. The total volume of data on the file servers is greater than 1 TB. Which approach will
allow the company to quickly scan all of this data on a weekly basis?
A. run an initial complete scan of all the file shares, then modify the scan target to add date filters and
exclude any files created or modified before the initial scan was run
B. run an initial complete scan of all the file shares, then modify the scan target to an incremental scan
type
C. create a separate scan target for each file share and exclude files accessed before the start of each
scan
D. run an initial complete scan of all file shares, create a summary report of all incidents created by the
scan, then run weekly scans and compare incidents from weekly scans to incidents from the complete
scan
Answer: B

Symantec examen   250-511 examen   250-511 examen

NO.3 A role is configured for XML export and a user executes the export XML incident action. What must be
done before history information is included in the export?
A. A remediator must take an action on the incident.
B. History must be enabled as a tab or panel in the incident snapshot layout.
C. Incident history must be enabled in the user's role.
D. The manager.properties must be configured for XML export.
Answer: C

certification Symantec   250-511 examen   certification 250-511   250-511

NO.4 To manually troubleshoot DLP Agent issues, the database and log viewer tools must be executed in
which location?
A. in the same location as the dcs.ead file location
B. in the same location as the cg.ead file location
C. in the same location as the ks.ead file location
D. in the same location as the is.ead file location
Answer: C

Symantec   250-511   250-511 examen

NO.5 The database is full and the Incident Persister is unable to process incidents. Which two file types
could be present in Vontu/protect/incidents? (Select two.)
A. .idx
B. .edc
C. .idc
D. .inc
E. .bad
Answer: C,E

Symantec examen   certification 250-511   250-511 examen

NO.6 Which Network Discover option is used to determine whether confidential data exists without having to
scan the entire target?
A. Byte Throttling
B. File Throttling
C. Match Thresholds
D. Inventory Mode Scanning
Answer: D

Symantec examen   250-511   250-511 examen

NO.7 Which two functions of the communications architecture ensure that the system will automatically
recover if a network connectivity failure occurs between the detection servers and the Enforce Server?
(Select two.)
A. Oracle database backup
B. detection server autonomous monitoring
C. Enforce Server offline alert notification
D. detection server incident queuing
E. detection server alert archiving
Answer: B,D

certification Symantec   certification 250-511   certification 250-511

NO.8 After installing several new DLP Agents, the Data Loss Prevention administrator discovers that none of
the endpoint agents are appearing on the Agent Overview page. After refreshing the page several times,
and determining that the equipment is powered on and connected to the network, the Agent Overview
page still fails to display the new agents. What is a possible cause for this issue?
A. The DLP Agents need to be added manually through the Symantec Management Platform.
B. The DLP Agents were installed with the incorrect Endpoint server IP address.
C. The assigned Endpoint server needs to be recycled in order to detect the new DLP Agents.
D. The Endpoint Location is set to "Manually" instead of "Automatically" in the Enforce user interface.
Answer: B

certification Symantec   250-511 examen   250-511   250-511 examen

NO.9 A user is unable to log in as sysadmin. The Data Loss Prevention system is configured to use Active
Directory authentication. The user is a member of two roles, sysadmin and remediator. How should the
user log in to the user interface in the sysadmin role?
A. sysadmin\username@domain
B. sysadmin\username
C. domain\username
D. sysadmin\username\domain
Answer: B

Symantec examen   250-511   250-511   250-511 examen   certification 250-511   250-511 examen

NO.10 Where should the Network Discover detection server be placed in a corporate network architecture?
A. inside the DMZ
B. on the same virtual LAN as the proxy server
C. inside the corporate network
D. on the same switch as the Oracle database server
Answer: C

Symantec   certification 250-511   250-511 examen   250-511   250-511 examen

NO.11 A Data Loss Prevention administrator notices that several errors occurred during a Network Discover
scan. Which report can the administrator use to determine exactly which errors occurred and when?
A. Discover Incident report sorted by target name and scan
B. Full Activity report for that particular scan
C. Server Event report from Server Overview
D. Full Statistics report for that particular scan
Answer: B

Symantec examen   250-511   certification 250-511

NO.12 Which two policy management actions can result in a reduced number of incidents for a given traffic
flow? (Select two.)
A. adding additional component matching to the rule
B. adding data owner exceptions
C. deploying to additional detection servers
D. increasing condition match count
E. adding additional severities
Answer: B,D

Symantec examen   250-511   250-511 examen

NO.13 A divisional executive requests a report of all incidents generated by a particular region, summarized
by department. What must be populated to generate this report?
A. remediation attributes
B. sender correlations
C. status groups
D. custom attributes
Answer: D

Symantec   250-511   250-511

NO.14 What are two benefits of the Symantec Data Loss Prevention 11 security architecture? (Select two.)
A. Communication is initiated by the detection servers inside the firewall.
B. SSL communication is used for user access to the Enforce Platform.
C. Endpoint Agent to Endpoint Server communication uses the Triple Data Encryption Standard (Triple
DES).
D. Confidential information captured by system components is stored using Advanced Encryption
Standards (AES) symmetric keys.
E. All indexed data uploaded into the Enforce Platform is protected with a two-way hash.
Answer: B,D

Symantec   certification 250-511   250-511 examen   250-511 examen   250-511

NO.15 An administrator is running a Discover Scanner target scan and the scanner is unable to communicate
back to the Discover Server. Where will the files be stored?
A. Discover Server incoming folder
B. scanner's outgoing folder
C. scanner's incoming folder
D. Enforce incident persister
Answer: B

Symantec examen   250-511   250-511   certification 250-511

NO.16 What must a policy manager do when working with Exact Data Matching (EDM) indexes?
A. re-index large data sources on a daily or weekly basis
B. index the original data source on the detection server
C. deploy the index only to specific detection servers
D. create a new data profile if data source schema changes
Answer: D

Symantec   250-511   certification 250-511   certification 250-511

NO.17 What is a feature of keyword proximity matching?
A. It will match on whole keywords only.
B. It has a maximum distance between keywords of 99.
C. It only matches on message body.
D. It evaluates each keyword pair independently.
Answer: D

Symantec examen   250-511   250-511 examen   250-511 examen

NO.18 Which product provides support for the Citrix XenApp virtualization platform?
A. Endpoint Prevent
B. Network Discover
C. Network Protect
D. Network Prevent
Answer: A

Symantec   250-511   250-511 examen   250-511

NO.19 Which DLP Agent task is unique to the Symantec Management Platform and is unavailable through
the Enforce console?
A. Change Endpoint server
B. Restart agent
C. Pull agent logs
D. Set log level
Answer: D

Symantec   250-511   250-511   250-511   250-511   250-511

NO.20 How can an administrator validate that once a policy is updated and saved it has been enabled on a
specific detection server?
A. check the status of the policy on the policy list page
B. check to see whether the policy was loaded under System > Servers > Alerts
C. check the policy and validate the date and time it was last updated
D. check to see whether the policy was loaded under System > Servers > Events
Answer: D

certification Symantec   250-511   certification 250-511   250-511

Pass4Test est un site web de vous offrir particulièrement les infos plus chaudes à propos de test Certification Symantec 250-511. Pour vous assurer à nous choisir, vous pouvez télécharger les Q&As partielles gratuites. Pass4Test vous promet un succès 100% du test Symantec 250-511.

2013年8月5日星期一

Le plus récent matériel de formation Symantec 250-402 ST0-118 ST0-134 ST0-119 250-511

Dans cette société de plus en plus intense, nous vous proposons à choisir une façon de se former plus efficace : moins de temps et d'argent dépensé. Pass4Test peut vous offrir une bonne solution avec une plus grande space à développer.


Le test Symantec 250-402 ST0-118 ST0-134 ST0-119 250-511 est très important dans l'Industrie IT, tous les professionnels le connaîssent ce fait. D'ailleur, c'est difficile à réussir ce test, toutefois le test Symantec 250-402 ST0-118 ST0-134 ST0-119 250-511 est une bonne façon à examiner les connaissances professionnelles. Un gens avec le Certificat Symantec 250-402 ST0-118 ST0-134 ST0-119 250-511 sera apprécié par beaucoup d'entreprises. Pass4Test est un fournisseur très important parce que beaucoup de candidats qui ont déjà réussi le test preuvent que le produit de Pass4Test est effectif. Vous pouvez réussir 100% le test Symantec 250-402 ST0-118 ST0-134 ST0-119 250-511 avec l'aide de Pass4Test.


Si vous choisissez notre l'outil formation, Pass4Test peut vous assurer le succès 100% du test Symantec 250-402 ST0-118 ST0-134 ST0-119 250-511. Votre argent sera tout rendu si vous échouez le test.


Code d'Examen: 250-402

Nom d'Examen: Symantec (Administration of Altiris Client Management Suite 7.1)

Questions et réponses: 133 Q&As

Code d'Examen: ST0-118

Nom d'Examen: Symantec (Symantec Enterprise Vault 10.0 for Exchange Technical Assessment)

Questions et réponses: 318 Q&As

Code d'Examen: ST0-134

Nom d'Examen: Symantec (Symantec EndPoint Protection 12.1 Technical Assessment)

Questions et réponses: 165 Q&As

Code d'Examen: ST0-119

Nom d'Examen: Symantec (Altiris (TM) Client Management Suite 7.1 Technical Assessmen)

Questions et réponses: 101 Q&As

Code d'Examen: 250-511

Nom d'Examen: Symantec (Administration of Symantec(TM) Data Loss Prevention 11)

Questions et réponses: 176 Q&As

Dans l'Industrie IT, le certificat IT peut vous permet d'une space plus grande de se promouvoir. Généralement, la promotion de l'entreprise repose sur ce que vous avec la certification. Le Certificat Symantec 250-402 ST0-118 ST0-134 ST0-119 250-511 est bien autorisé. Avec le certificat Symantec 250-402 ST0-118 ST0-134 ST0-119 250-511, vous aurez une meilleure carrière dans le future. Vous pouvez télécharger tout d'abord la partie gratuite de Q&A Symantec 250-402 ST0-118 ST0-134 ST0-119 250-511.


ST0-134 Démo gratuit à télécharger: http://www.pass4test.fr/ST0-134.html


NO.1 How many Symantec Endpoint Protection Managers can be connected to an embedded database?
A. 1
B. 2
C. 5
D. 10
Answer: A

Symantec   ST0-134   ST0-134   ST0-134

NO.2 Which Symantec Endpoint Protection 12.1 defense mechanism provides protection against worms
like W32.Silly.FDC, which propagate from system to system through the use of autorun.inf files?
A. Application Control
B. SONAR
C. Client Firewall
D. Exceptions
Answer: A

Symantec   ST0-134   ST0-134   ST0-134 examen

NO.3 Which Symantec Endpoint Protection 12.1 component provides services to improve the
performance of virtual client scanning?
A. Shared Insight Cache server
B. LiveUpdate Administrator server
C. Symantec Protection Center
D. Group Update Provider
Answer: A

Symantec   certification ST0-134   certification ST0-134   certification ST0-134   ST0-134 examen

NO.4 An administrator creates a new domain in the Symantec Endpoint Protection Manager console. How
can the administrator copy policies from the old domain to the new domain?
A. Export the policy from the old domain and import it into the new domain.
B. Copy the policy in the old domain and paste the policy into the new domain.
C. Copy the old domain's policy XML file into the folder for the new domain.
D. Back up the old domain's database and restore it into the new domain.
Answer: A

Symantec   certification ST0-134   certification ST0-134   ST0-134 examen   ST0-134 examen

NO.5 Which Symantec Endpoint Protection 12.1 component uses reputation to evaluate a file?
A. Shared Insight Cache server
B. Symantec Endpoint Protection client
C. Symantec Endpoint Protection Manager
D. LiveUpdate Administrator server
Answer: B

Symantec   ST0-134 examen   ST0-134   ST0-134

NO.6 Which component is required in order to run Symantec Endpoint Protection 12.1 protection
technologies?
A. Symantec Endpoint Protection Manager
B. Symantec Endpoint Protection client
C. LiveUpdate Administrator server
D. Symantec Protection Center
Answer: B

Symantec examen   certification ST0-134   ST0-134   certification ST0-134   ST0-134   certification ST0-134
13.Which Symantec Endpoint Protection 12.1 component provides single-sign-on to the Symantec
Endpoint Protection Manager and other products, along with cross-product reporting?
A. Symantec Reporting server
B. Symantec Security Information Manager
C. IT Analytics
D. Symantec Protection Center
Answer: D

Symantec examen   certification ST0-134   certification ST0-134

NO.7 An administrator is logged in to the Symantec Endpoint Protection Manager (SEPM) console for a
system named SEPM01. The groups and policies that were previously in the SEPM01 console are
unavailable and have been replaced with unfamiliar groups and policies. What was a possible reason
for this change?
A. The administrator was modified from using Computer mode to User mode.
B. The administrator was logged in to the incorrect domain for SEPM01.
C. The administrator was changed from a limited administrator to a system administrator.
D. The administrator was using the Web console instead of the Java console.
Answer: B

Symantec   ST0-134   ST0-134   ST0-134   ST0-134

NO.8 How can an administrator manage multiple, independent companies from one database while
maintaining independent groups, computers, and policies?
A. Set up limited administrators with appropriate rights.
B. Set up separate domains.
C. Set up additional sites using a single database.
D. Set up separate locations and turn off inheritance.
Answer: B

Symantec examen   ST0-134 examen   ST0-134   certification ST0-134

NO.9 According to Symantec, what is a botnet?
A. systems infected with the same virus strain
B. groups of systems performing remote tasks without the users' knowledge
C. groups of computers configured to steal credit card records
D. compromised systems opening communication to an IRC channel
Answer: B

Symantec examen   ST0-134 examen   ST0-134   certification ST0-134

NO.10 A financial company has a security policy that prevents banking system workstations from
connecting to the internet. Which Symantec Endpoint Protection 12.1 protection technology will be
prevented from working on the company's workstations?
A. Insight
B. Application and Device Control
C. Network Threat Protection
D. LiveUpdate
Answer: A

Symantec   ST0-134 examen   ST0-134   certification ST0-134

NO.11 Drive-by downloads are a common vector of infections. Some of these attacks use encryption to
bypass traditional defense mechanisms. Which Symantec Endpoint Protection 12.1 protection
technology blocks such obfuscated attacks?
A. SONAR
B. Bloodhound heuristic virus detection
C. Client Firewall
D. Browser Intrusion Prevention
Answer: D

Symantec   ST0-134   ST0-134 examen   certification ST0-134   certification ST0-134

NO.12 Which Symantec Endpoint Protection 12.1 protection technology provides the primary protection
layers against zero-day network attacks?
A. SONAR
B. Client Firewall
C. Intrusion Prevention
D. System Lockdown
Answer: C

certification Symantec   certification ST0-134   certification ST0-134   certification ST0-134

NO.13 Which Symantec Endpoint Protection 12.1 component improves performance because known good
files are skipped?
A. LiveUpdate Administrator server
B. Group Update Provider
C. Shared Insight Cache server
D. Central Quarantine server
Answer: C

certification Symantec   certification ST0-134   ST0-134   certification ST0-134   ST0-134

NO.14 The fake antivirus family "PC scout" infects systems with a similar method regardless of its variant.
Which SONAR sub-feature can block new variants of the same family, based on sequence of events?
A. artificial intelligence
B. behavioral heuristic
C. human authored signatures
D. behavioral policy lockdown
Answer: C

certification Symantec   ST0-134   ST0-134   ST0-134

NO.15 Which Symantec Endpoint Protection 12.1 component uses Sybase SQL Anywhere?
A. Symantec Endpoint Protection Manager embedded database
B. Symantec Endpoint Protection Manager remote database
C. LiveUpdate Administrator server
D. Shared Insight Cache server
Answer: A

Symantec examen   ST0-134   ST0-134   ST0-134

NO.16 In addition to performance improvements, which two benefits does Insight provide? (Select two.)
A. reputation scoring for documents
B. zero-day threat detection
C. protection against system file modifications
D. false positive mitigation
E. blocking of malicious websites
Answer: BD

Symantec   certification ST0-134   ST0-134   ST0-134   ST0-134

NO.17 Which two objects in the Symantec Endpoint Protection Manager console describe the most
granular level to which a policy can be applied? (Select two.)
A. Site
B. Domain
C. Group
D. Location
E. Computer
F. User
Answer: CD

certification Symantec   ST0-134   ST0-134   ST0-134   certification ST0-134   ST0-134

NO.18 How does the Intrusion Prevention System add an additional layer of protection to Network Threat
Protection?
A. It inspects the TCP packet headers and tracks the sequence number.
B. It performs deep packet inspection, reading the packet headers, and data portion.
C. It examines TCP/IP traffic from the application and traces the source of the traffic.
D. It monitors IP datagrams for abnormalities.
Answer: B

Symantec   certification ST0-134   ST0-134 examen   ST0-134   ST0-134 examen

NO.19 A company with one site has a factory with computers in the manufacturing area. Both factory
managers and operators need to log in to these shared computers. Different policies will be applied
depending on whether the individual logging in to the machine is a manager or an operator. Which
Symantec Endpoint Protection 12.1 feature provides this ability?
A. Computer mode
B. Active Directory synchronization
C. User mode
D. Console authentication
Answer: C

Symantec examen   certification ST0-134   certification ST0-134

NO.20 A company is experiencing a malware outbreak. The company deploys Symantec Endpoint
Protection 12.1, with only Virus and Spyware Protection, Application and Device Control, and
Intrusion Prevention technologies. Why would Intrusion Prevention be unable to block all
communications from an attacking host?
A. Intrusion Prevention needs the firewall component to block all traffic from the attacking host.
B. Intrusion Prevention blocks the attack only if the administrator wrote a signature for it.
C. Intrusion Prevention definitions are out-of-date.
D. Intrusion Prevention is set to log only.
Answer: A

Symantec   ST0-134 examen   ST0-134 examen   ST0-134   ST0-134 examen

2013年7月12日星期五

Les meilleures Symantec 250-511 examen pratique questions et réponses

Pass4Test est un seul site web qui peut offrir toutes les documentations de test Symantec 250-511. Ce ne sera pas un problème à réussir le test Symantec 250-511 si vous préparez le test avec notre guide d'étude.


Pass4Test peut offrir nombreux de documentations aux candidats de test Symantec 250-511, et aider les candidats à réussir le test. Les marétiaux visés au test Symantec 250-511 sont tout recherchés par les experts avec leurs connaissances professionnelles et les expériences. Les charactéristiques se reflètent dans la bonne qualité de Q&A, la vitesse de la mise à jour. Le point plus important est que notre Q&A est laquelle le plus proche du test réel. Pass4Test peut vous permettre à réussir le test Symantec 250-511 100%.


Dans cette société, il y a plein de gens talentueux, surtout les professionnels de l'informatique. Beaucoup de gens IT se battent dans ce domaine pour améliorer l'état de la carrière. Le test 250-511 est lequel très important dans les tests de Certification Symantec. Pour être qualifié de Symantec, on doit obtenir le passport de test Symantec 250-511.


Pass4Test provide non seulement le produit de qualité, mais aussi le bon service. Si malheureusement vous ne pouvez pas réussir le test, votre argent sera tout rendu. Le service de la mise à jour gratuite est aussi pour vous bien que vous passiez le test Certification.


Vous aurez le service de la mise à jour gratuite pendant un an une fois que vous achetez le produit de Pass4Test. Vous pouvez recevoir les notes immédiatement à propos de aucun changement dans le test ou la nouvelle Q&A sortie. Pass4Test permet tous les clients à réussir le test Symantec 250-511 à la première fois.


Pass4Test a une équipe se composant des experts qui font la recherche particulièrement des exercices et des Q&As pour le test certification Symantec 250-511, d'ailleurs ils peuvent vous proposer à propos de choisir l'outil de se former en ligne. Si vous avez envie d'acheter une Q&A de Pass4Test, Pass4Test vous offrira de matériaux plus détailés et plus nouveaux pour vous aider à approcher au maximum le test réel. Assurez-vous de choisir le Pass4Test, vous réussirez 100% le test Symantec 250-511.


Finalement, la Q&A Symantec 250-511 plus nouvelle est lancé avec tous efforts des experts de Pass4Test. Aujourd'hui, dans l'Industrie de IT, si on veut se renforcer sa place, il faut se preuve la professionnalité aux les autres. Le test Symantec 250-511 est une bonne examination des connaissances professionnelles. Avec le passport de la Certification Symantec, vous aurez un meilleur salaire et une plus grande space à se développer.


Code d'Examen: 250-511

Nom d'Examen: Symantec (Administration of Symantec(TM) Data Loss Prevention 11)

Questions et réponses: 176 Q&As

250-511 Démo gratuit à télécharger: http://www.pass4test.fr/250-511.html


NO.1 Where should the Network Discover detection server be placed in a corporate network architecture?
A. inside the DMZ
B. on the same virtual LAN as the proxy server
C. inside the corporate network
D. on the same switch as the Oracle database server
Answer: C

Symantec   250-511   250-511

NO.2 To manually troubleshoot DLP Agent issues, the database and log viewer tools must be executed in
which location?
A. in the same location as the dcs.ead file location
B. in the same location as the cg.ead file location
C. in the same location as the ks.ead file location
D. in the same location as the is.ead file location
Answer: C

Symantec   250-511   250-511   250-511 examen   250-511

NO.3 What is a feature of keyword proximity matching?
A. It will match on whole keywords only.
B. It has a maximum distance between keywords of 99.
C. It only matches on message body.
D. It evaluates each keyword pair independently.
Answer: D

Symantec   250-511   250-511   250-511 examen   250-511 examen   certification 250-511

NO.4 Which Network Discover option is used to determine whether confidential data exists without having to
scan the entire target?
A. Byte Throttling
B. File Throttling
C. Match Thresholds
D. Inventory Mode Scanning
Answer: D

certification Symantec   250-511   250-511

NO.5 Which two remediation actions are available for Network Protect? (Select two.)
A. Copy
B. Move
C. Block
D. Rename
E. Quarantine
Answer: A,E

Symantec   250-511   250-511 examen   250-511

NO.6 A company needs to scan all of its file shares on a weekly basis to make sure sensitive data is being
stored correctly. The total volume of data on the file servers is greater than 1 TB. Which approach will
allow the company to quickly scan all of this data on a weekly basis?
A. run an initial complete scan of all the file shares, then modify the scan target to add date filters and
exclude any files created or modified before the initial scan was run
B. run an initial complete scan of all the file shares, then modify the scan target to an incremental scan
type
C. create a separate scan target for each file share and exclude files accessed before the start of each
scan
D. run an initial complete scan of all file shares, create a summary report of all incidents created by the
scan, then run weekly scans and compare incidents from weekly scans to incidents from the complete
scan
Answer: B

certification Symantec   250-511   certification 250-511   250-511

NO.7 How can an administrator validate that once a policy is updated and saved it has been enabled on a
specific detection server?
A. check the status of the policy on the policy list page
B. check to see whether the policy was loaded under System > Servers > Alerts
C. check the policy and validate the date and time it was last updated
D. check to see whether the policy was loaded under System > Servers > Events
Answer: D

Symantec   certification 250-511   250-511   certification 250-511

NO.8 What must a policy manager do when working with Exact Data Matching (EDM) indexes?
A. re-index large data sources on a daily or weekly basis
B. index the original data source on the detection server
C. deploy the index only to specific detection servers
D. create a new data profile if data source schema changes
Answer: D

Symantec   250-511   250-511

NO.9 Which two functions of the communications architecture ensure that the system will automatically
recover if a network connectivity failure occurs between the detection servers and the Enforce Server?
(Select two.)
A. Oracle database backup
B. detection server autonomous monitoring
C. Enforce Server offline alert notification
D. detection server incident queuing
E. detection server alert archiving
Answer: B,D

certification Symantec   certification 250-511   certification 250-511   certification 250-511   certification 250-511

NO.10 Which product provides support for the Citrix XenApp virtualization platform?
A. Endpoint Prevent
B. Network Discover
C. Network Protect
D. Network Prevent
Answer: A

Symantec   250-511   certification 250-511   250-511

NO.11 A Data Loss Prevention administrator notices that several errors occurred during a Network Discover
scan. Which report can the administrator use to determine exactly which errors occurred and when?
A. Discover Incident report sorted by target name and scan
B. Full Activity report for that particular scan
C. Server Event report from Server Overview
D. Full Statistics report for that particular scan
Answer: B

Symantec   250-511   250-511   250-511   250-511 examen

NO.12 A divisional executive requests a report of all incidents generated by a particular region, summarized
by department. What must be populated to generate this report?
A. remediation attributes
B. sender correlations
C. status groups
D. custom attributes
Answer: D

Symantec examen   certification 250-511   250-511   250-511

NO.13 What are two benefits of the Symantec Data Loss Prevention 11 security architecture? (Select two.)
A. Communication is initiated by the detection servers inside the firewall.
B. SSL communication is used for user access to the Enforce Platform.
C. Endpoint Agent to Endpoint Server communication uses the Triple Data Encryption Standard (Triple
DES).
D. Confidential information captured by system components is stored using Advanced Encryption
Standards (AES) symmetric keys.
E. All indexed data uploaded into the Enforce Platform is protected with a two-way hash.
Answer: B,D

Symantec   250-511 examen   250-511 examen   certification 250-511

NO.14 Which two policy management actions can result in a reduced number of incidents for a given traffic
flow? (Select two.)
A. adding additional component matching to the rule
B. adding data owner exceptions
C. deploying to additional detection servers
D. increasing condition match count
E. adding additional severities
Answer: B,D

Symantec   certification 250-511   certification 250-511   250-511

NO.15 An administrator is running a Discover Scanner target scan and the scanner is unable to communicate
back to the Discover Server. Where will the files be stored?
A. Discover Server incoming folder
B. scanner's outgoing folder
C. scanner's incoming folder
D. Enforce incident persister
Answer: B

Symantec examen   250-511 examen   certification 250-511   certification 250-511

NO.16 The database is full and the Incident Persister is unable to process incidents. Which two file types
could be present in Vontu/protect/incidents? (Select two.)
A. .idx
B. .edc
C. .idc
D. .inc
E. .bad
Answer: C,E

Symantec examen   certification 250-511   certification 250-511   250-511

NO.17 A role is configured for XML export and a user executes the export XML incident action. What must be
done before history information is included in the export?
A. A remediator must take an action on the incident.
B. History must be enabled as a tab or panel in the incident snapshot layout.
C. Incident history must be enabled in the user's role.
D. The manager.properties must be configured for XML export.
Answer: C

Symantec   250-511 examen   250-511 examen

NO.18 A user is unable to log in as sysadmin. The Data Loss Prevention system is configured to use Active
Directory authentication. The user is a member of two roles, sysadmin and remediator. How should the
user log in to the user interface in the sysadmin role?
A. sysadmin\username@domain
B. sysadmin\username
C. domain\username
D. sysadmin\username\domain
Answer: B

certification Symantec   250-511   certification 250-511   certification 250-511

NO.19 Which DLP Agent task is unique to the Symantec Management Platform and is unavailable through
the Enforce console?
A. Change Endpoint server
B. Restart agent
C. Pull agent logs
D. Set log level
Answer: D

Symantec   250-511   certification 250-511   250-511 examen   250-511   certification 250-511

NO.20 After installing several new DLP Agents, the Data Loss Prevention administrator discovers that none of
the endpoint agents are appearing on the Agent Overview page. After refreshing the page several times,
and determining that the equipment is powered on and connected to the network, the Agent Overview
page still fails to display the new agents. What is a possible cause for this issue?
A. The DLP Agents need to be added manually through the Symantec Management Platform.
B. The DLP Agents were installed with the incorrect Endpoint server IP address.
C. The assigned Endpoint server needs to be recycled in order to detect the new DLP Agents.
D. The Endpoint Location is set to "Manually" instead of "Automatically" in the Enforce user interface.
Answer: B

Symantec   250-511 examen   certification 250-511   250-511   250-511

Dans l'Industrie IT, le certificat IT peut vous permet d'une space plus grande de se promouvoir. Généralement, la promotion de l'entreprise repose sur ce que vous avec la certification. Le Certificat Symantec 250-511 est bien autorisé. Avec le certificat Symantec 250-511, vous aurez une meilleure carrière dans le future. Vous pouvez télécharger tout d'abord la partie gratuite de Q&A Symantec 250-511.