Symantec Data Loss Prevention 16.x Administration Technical Specialist Questions and Answers
What is the first step an administrator should take to improve the performance of Network Monitor when network traffic exceeds 1 Gbps?
A customer needs to integrate information form DLP incidents into external Governance, Risk, and Compliance dashboards.
Which feature should a third-party component integrate with to provide dynamic reporting, create custom incident remediation processes, or support business processes?
How should a DLP administrator change a policy that it retains the original file when an endpoint incident has detected a “copy to USB device” operation?
Why would an administrator set the Similarity Threshold to s=zero when testing and tuning a Vector Machine Learning (VML) profile?
Refer to the exhibit.
What activity should occur during the baseline phase, according to the risk reduction model?
Which two (2) detection technology options run ONLY on detection servers and NOT on endpoint agents? (Choose two.)
A DLP administrator is attempting to add a new Network Discover detection server from the Enforce management console. However, the only available options are Network Monitor and Endpoint servers.
What should the administrator do to make the Network Discover option available?
A DLP administrator created a new agent configuration for an Endpoint server. However, the endpoint agents fail to receive the new configuration.
What is one possible reason that the agent fails to receive the new configuration?
What detection technology supports partial contents matching?
Why would an administrator set the Similarity Threshold to zero when testing and tuning a Vector Machine Learning (VML) profile?
What are two (2) reasons an administrator should utilize a manual configuration to determine the endpoint location? (Choose two.)
When Symantec DLP and Symantec CloudSOC are integrated, what must you configure in Enforce to tell CloudSOC which traffic or content to send to the Cloud Detection Service for analysis?
Where in the Enforce management console can a DLP administrator change the “UI.NO_SCAN.int” setting to disable the “Inspecting data” pop-up?
Which two Infrastructure-as-a-Service providers are supported for hosting Cloud Prevent for Office 365? (Choose two.)
Which two components can perform a file system scan of a workstation? (Choose two.)
Which option correctly describes the two-tier installation type for Symantec DLP?
A DLP administrator has added several approved endpoint devices as exceptions to an Endpoint Prevent policy that blocks the transfer of sensitive data. However, data transfers to these devices are still being blocked.
What is the first action an administrator should take to enable data transfers to the approved endpoint devices?
Which two actions are available for a “Network Prevent: Remove HTTP/HTTPS content” response rule when the content is unable to be removed? (Choose two.)
Refer to the exhibit. Which type of Endpoint response rule is shown?
A DLP administrator determines that the \SymantecDLP\Protect\Incidents folder on the Enforce server contains. BAD files dated today, while other. IDC files are flowing in and out of the \Incidents directory. Only .IDC files larger than 1MB are turning to .BAD files.
What could be causing only incident data smaller than 1MB to persist while incidents larger than 1MB change to .BAD files?
How should a DLP administrator exclude a custom endpoint application named “custom_app.exe” from being monitored by Application File Access Control?
Which two automated response rules will be active in policies that include Exact Data Matching (EDM) detection rule? (Choose two.)
Which option is an accurate use case for Information Centric Encryption (ICE)?
Which tool must a DLP administrator run to certify the database prior to upgrading DLP?
A divisional executive requests a report of all incidents generated by a particular region, summarized by department.
What does the DLP administrator need to configure to generate this report?
Which two detection technology options ONLY run on a detection server? (Choose two.)
What should an incident responder select in the Enforce management console to remediate multiple incidents simultaneously?
Which two detection technology options run on the DLP agent? (Choose two.)
A DLP administrator is preparing to install Symantec DLP and has been asked to use an Oracle database provided by the Database Administration team.
Which SQL *Plus command should the administrator utilize to determine if the database is using a supported version of Oracle?
What is one difference between Exact Data Matching (EDM) and Exact Match Data Identifiers (EMDI)?
Which network Prevent action takes place when the network Incident list shows the message is “Modified”?
In the context of Network Discover scanning of Exchange servers, what is the Exchange Autodiscover service?