Exam Details

  • Exam Code
    :ST0-237
  • Exam Name
    :Symantec Data Loss Prevention 12 Technical Assessment
  • Certification
    :Symantec Certified Security program
  • Vendor
    :Symantec
  • Total Questions
    :237 Q&As
  • Last Updated
    :Apr 16, 2025

Symantec Symantec Certified Security program ST0-237 Questions & Answers

  • Question 301:

    Which two locations can the administrator verify a newly created policy was loaded on a detection server? (Select two.)

    A. System > Servers > Overview

    B. System > Servers > Server Detail

    C. Manage > Policies > Policy List

    D. System > Servers > Overview > Configure Server

    E. System > Servers > Events

  • Question 302:

    How should an administrator export all policies from a test environment to a production environment?

    A. Choose the option to 'export all' on the Manage > Policies > Policies List page

    B. Export one policy template at a time

    C. Navigate to System > Settings > Export and select 'All'

    D. Locate the 'policy' folder under 'SymantecDLP' and copy all of the .XML files

  • Question 303:

    An incident responder is viewing a discover incident snapshot and needs to determine which information to provide to the next level responder. Which information would be most useful in assisting the next level responder with data clean-up?

    A. Incident Details: Message Body content

    B. Custom Attributes: Most Active User from Data Insight

    C. Incident Details: File Owner metadata

    D. Access Information: File Permissions

  • Question 304:

    A DLP administrator is creating a role that contains an incident access condition that restricts users from viewing specific incidents.

    Which two conditions can the administrator specify when creating the incident access condition in a role? (Select two.)

    A. file type

    B. custom attribute

    C. recipient

    D. file size

    E. policy group

  • Question 305:

    What should an incident responder select to remediate multiple incidents simultaneously?

    A. Smart Response on the Incident Snapshot page

    B. Automated Response on an Incident List report

    C. Smart Response on an Incident List report

    D. Automated Response on the Incident Snapshot page

  • Question 306:

    Which two options are available when selecting an incident for deletion? (Select two.)

    A. Delete the incident completely

    B. Delete the original message and retain the incident

    C. Delete the incident and retain the original message

    D. Delete the incident and export incident details to .CSV file

    E. Delete all attachments or files and export incident to .XML file

  • Question 307:

    A compliance officer needs to understand how the company is complying with its data security policies over time. Which report should the compliance officer generate to obtain the compliance information?

    A. Policy Trend report, summarized by policy, then quarter

    B. Policy Trend report, summarized by policy, then severity

    C. Policy report, filtered on quarter, and summarized by policy

    D. Policy report, filtered on date, and summarized by policy

  • Question 308:

    A divisional executive requests a report of all incidents generated by a particular region, summarized by department. What must be populated to generate this report?

    A. remediation attributes

    B. sender correlations

    C. status groups

    D. custom attributes

  • Question 309:

    A divisional executive requests a report of all incidents generated by a particular region and summarized by department. Which incident information must be populated to generate this report?

    A. remediation attributes

    B. custom attributes

    C. sender correlations

    D. status groups

  • Question 310:

    A company needs to disable USB devices on computers that are generating a number of recurring DLP incidents. It decides to implement Endpoint Lockdown using Endpoint Prevent, which integrates with Symantec Endpoint Protection Manager and Symantec Management Platform. After incidents are still detected from several agents, the company determines that a component is missing.

    Which component needs to be added to disable the USB devices once incidents are detected?

    A. Control Compliance Suite

    B. Workflow Solution

    C. pcAnywhere

    D. Risk Automation Suite

Related Exams:

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Symantec exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your ST0-237 exam preparations and Symantec certification application, do not hesitate to visit our Vcedump.com to find your solutions here.