Exam Details

  • Exam Code
    :250-561
  • Exam Name
    :Endpoint Security Complete - Administration R1
  • Certification
    :Symantec Certifications
  • Vendor
    :Symantec
  • Total Questions
    :70 Q&As
  • Last Updated
    :Mar 08, 2025

Symantec Symantec Certifications 250-561 Questions & Answers

  • Question 51:

    A user downloads and opens a PDF file with Adobe Acrobat. Unknown to the user, a hidden script in the file begins downloading a RAT.

    Which Anti-malware engine recognizes that this behavior is inconsistent with normal Acrobat functionality, blocks the behavior and kills Acrobat?

    A. SONAR

    B. Sapient

    C. IPS

    D. Emulator

  • Question 52:

    Which alert rule category includes events that are generated about the cloud console?

    A. Security

    B. Diagnostic

    C. System

    D. Application Activity

  • Question 53:

    In the ICDm, administrators are assisted by the My Task view. Which automation type creates the tasks within the console?

    A. Artificial Intelligence

    B. Machine Learning

    C. Advanced Machine Learning

    D. Administrator defined rules

  • Question 54:

    What is the frequency of feature updates with SES and the Integrated Cyber Defense Manager (ICDm)

    A. Monthly

    B. Weekly

    C. Quarterly

    D. Bi-monthly

  • Question 55:

    An administrator selects the Discovered Items list in the ICDm to investigate a recent surge in suspicious file activity. What should an administrator do to display only high risk files?

    A. Apply a list control

    B. Apply a search rule

    C. Apply a list filter

    D. Apply a search modifier

  • Question 56:

    What characterizes an emerging threat in comparison to traditional threat?

    A. Emerging threats use new techniques and 0-day vulnerability to propagate.

    B. Emerging threats requires artificial intelligence to be detected.

    C. Emerging threats are undetectable by signature based engines.

    D. Emerging threats are more sophisticated than traditional threats.

  • Question 57:

    Which technique randomizes the e memory address map with Memory Exploit Mitigation?

    A. SEHOP

    B. ROPHEAP

    C. ASLR

    D. ForceDEP

  • Question 58:

    What should an administrator know regarding the differences between a Domain and a Tenant in ICDm?

    A. A tenant can contain multiple domains

    B. A domain can contain multiple tenants

    C. Each customer can have one domain and many tenant

    D. Each customer can have one tenant and many domains

  • Question 59:

    Which Anti-malware technology should an administrator utilize to expose the malicious nature of a file created with a custom packet?

    A. Sandbox

    B. SONAR

    C. Reputation

    D. Emulator

  • Question 60:

    An administrator must create a custom role in ICDm.

    Which area of the management console is able to have access restricted or granted?

    A. Policy Management

    B. Hybrid device management

    C. Agent deployment

    D. Custom Dashboard Creation

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Symantec exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 250-561 exam preparations and Symantec certification application, do not hesitate to visit our Vcedump.com to find your solutions here.