Exam Details

  • Exam Code
    :ST0-237
  • Exam Name
    :Symantec Data Loss Prevention 12 Technical Assessment
  • Certification
    :Symantec Certified Security program
  • Vendor
    :Symantec
  • Total Questions
    :237 Q&As
  • Last Updated
    :Apr 16, 2025

Symantec Symantec Certified Security program ST0-237 Questions & Answers

  • Question 11:

    Which three are available Export Formats for Symantec Control Compliance Suite 9.0 reports? (Select three.)

    A. Comma Separated Values (CSV)

    B. Adobe Reader (PDF)

    C. Crystal Reports (RPT)

    D. Rich Text

    E. Microsoft Access (MDB)

  • Question 12:

    Where in the Enforce UI can the administrator find the option to participate in the Supportability Telemetry Program?

    A. System > System Reports

    B. System > Incident Data

    C. System > Servers

    D. System > Settings

  • Question 13:

    In System Overview, the status of a detection server is shown as 'unknown'. Examination of the detection server reveals all Vontu services are running. Which port is blocked and causing the server to be in the 'unknown' state?

    A. 443

    B. 8000

    C. 8100

    D. 8300

  • Question 14:

    The DLP services on an Endpoint Server keep stopping. The only events displayed in the Enforce UI are that the server processes have stopped. What is the first step the administrator should take to keep the services on the Endpoint server running?

    A. Perform a complete uninstall and reinstall of the Product

    B. Install malware detection software on the server

    C. Remove the Endpoint server from the UI and add it again

    D. Exclude the DLP directories from any scheduled or real-time virus scanning

  • Question 15:

    What is the minimum percentage of spare disks in a disk group?

    A. 10%

    B. 15%

    C. 20%

    D. 25%

  • Question 16:

    An administrator is checking System Overview and all of the detection servers are showing as 'unknown'. The Vontu services are up and running on the detection servers. Thousands of .IDC files are building up in the Incidents directory on the detection servers. There is good network connectivity between the detection servers and the Enforce server when testing with the telnet command. How can the administrator bring the detection servers to a running state in the Enforce UI?

    A. Delete all of the .BAD files in the incidents folder on the Enforce server

    B. Restart the Vontu Monitor Service on all of the detection servers affected

    C. Ensure the Vontu Monitor Controller service is running on the Enforce server

    D. Ensure port 8300 is configured as open on the firewall

  • Question 17:

    A DLP administrator needs to inspect HTTP traffic using a Network Monitor, including data pushed up to the web and data pulled down from the web. Which configuration changes should the administrator make under the advanced server settings to include all cases?

    A. L7.processGets=false, PacketCapture.DISCARD_HTTP_GET=true, L7.minSizeofGetURL=1000

    B. L7.processGets=true, PacketCapture.DISCARD_HTTP_GET=true, L7.minSizeofGetURL=100

    C. L7.processGets=false, PacketCapture.DISCARD_HTTP_GET=false, L7.minSizeofGetURL=10

    D. L7.processGets=true, PacketCapture.DISCARD_HTTP_GET=false, L7.minSizeofGetURL=10

  • Question 18:

    An administrator receives the following error:

    Error Code:3018 lt;profile name> has reached maximum size. Only 44245 out of 97737 documents are indexed. What must the administrator do to resolve this error?

    A. increase the advanced server setting Lexer.MaximumNumberOfTokens to 90k

    B. reindex the current IDM to refresh the .IDX files

    C. split the IDM into multiple indexes when the index is too large

    D. increase the advanced server setting FileReader.MaxFileSize to 300M

  • Question 19:

    A Network Monitor server has been installed and the networking components configured accordingly. The server is receiving traffic, but fails to detect incidents. Running Wireshark indicates that the desired traffic is reaching the detection

    server.

    What is the most likely cause for this behavior?

    A. The mirrored port is sending corrupted packets.

    B. The wrong interface is selected in the configuration.

    C. The configuration is set to process GET requests.

    D. The communication to the database server is interrupted.

  • Question 20:

    An administrator is attempting to uninstall a version 11.6 DLP Agent, but the uninstall password fails to remove the agent. The group who set the initial password is unavailable. Which two options are available to address the password issue? (Select two.)

    A. manually uninstall the agent by stopping the EDPA and WDP services, then remove all related program files

    B. upgrade the agent to version 12 with a newly generated UninstallPasswordKey

    C. reboot and login to Safe Mode and use Add / Remove Programs to uninstall the Agent

    D. contact Symantec Support to obtain the Clean Agent tool

    E. use Regedit.exe and delete the related Endpoint registry entries

Related Exams:

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Symantec exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your ST0-237 exam preparations and Symantec certification application, do not hesitate to visit our Vcedump.com to find your solutions here.