Welcome to TestSimulate

Pass Your Next Certification Exam Fast!

Everything you need to prepare, learn & pass your certification exam easily.

365 days free updates. First attempt guaranteed success.

Symantec Administration of Symantec Advanced Threat Protection 3.0 (250-441) Free Practice Test

Question 1
Which two tasks should an Incident Responder complete when recovering from an incident? (Choose two.)

Correct Answer: A,B
Question 2
A network control point discovered a botnet phone-home attempt in the network stream.
Which detection method identified the event?

Correct Answer: D
Question 3
What is the second stage of an Advanced Persistent Threat (APT) attack?

Correct Answer: B
Question 4
What is the role of Cynic within the Advanced Threat Protection (ATP) solution?

Correct Answer: A
Question 5
An Incident Responder has reviewed a STIX report and now wants to ensure that their systems have NOT been compromised by any of the reported threats.
Which two objects in the STIX report will ATP search against? (Choose two.)

Correct Answer: C,D
Question 6
How does an attacker use a zero-day vulnerability during the Incursion phase?

Correct Answer: A
Question 7
An Incident responder added a files NDS hash to the blacklist.
Which component of SEP enforces the blacklist?

Correct Answer: A
Question 8
Which two questions can an Incident Responder answer when analyzing an incident in ATP? (Choose two.)

Correct Answer: D,E
Question 9
What is the minimum amount of RAM required for a virtual deployment of the ATP Manager in a production environment?

Correct Answer: C
Question 10
Which two actions an Incident Responder take when downloading files from the ATP file store? (Choose two.)

Correct Answer: A,B