Free 250-580 Practice Test Questions and Answers (2026) | Cert Empire Practice Questions
Free preview: 20 questions.
Broadcom 250 580
Q: 1
Which device page should an administrator view to track the progress of an issued device command?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 2
A user is unknowingly about to connect to a malicious website and download a known threat within
a .rar file. All Symantec Endpoint Protection technologies are installed on the client's system.
In which feature set order must the threat pass through to successfully infect the system?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 3
Which Symantec Endpoint Protection technology blocks a downloaded program from installing
browser plugins?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 4
What is an appropriate use of a file fingerprint list?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 5
What should an administrator know regarding the differences between a Domain and a Tenant in
ICDm?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 6
An Application Control policy includes an Allowed list and a Blocked list. A user wants to use an
application that is neither on the Allowed list nor on the Blocked list. What can the user do to gain
access to the application?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 7
Why is it important for an Incident Responder to copy malicious files to the SEDR file store or create
an image of the infected system during the Recovery phase?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 8
Which designation should an administrator assign to the computer configured to find unmanaged
devices?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 9
Which report template type should an administrator utilize to create a daily summary of network
threats detected?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 10
A Symantec Endpoint Protection (SEP) administrator receives multiple reports that machines are
experiencing performance issues. The administrator discovers that the reports happen at about the
same time as the scheduled LiveUpdate.
Which setting should the SEP administrator configure to minimize I/O when LiveUpdate occurs?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 11
Which communication method is utilized within SES to achieve real-time management?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 12
What type of Threat Defense for Active Directory alarms are displayed after domain
misconfigurations or hidden backdoors are detected?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 13
What does the Endpoint Communication Channel (ECC) 2.0 allow Symantec EDR to directly connect
to?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 14
Which IPS signature type is primarily used to identify specific unwanted network traffic?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 15
An organization identifies a threat in its environment and needs to limit the spread of the threat.
How should the SEP Administrator block the threat using Application and Device Control?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 16
A company allows users to create firewall rules. During the course of business, users are accidentally
adding rules that block a custom internal application.
Which steps should the Symantec Endpoint Protection administrator take to prevent users from
blocking the custom application?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 17
What protection technology should an administrator enable to prevent double executable file names
of ransomware variants like Cryptolocker from running?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 18
If an administrator enables the setting to manage policies from the cloud, what steps must be taken
to reverse this process?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 19
Administrators at a company share a single terminal for configuring Symantec Endpoint Protection.
The administrators want to ensure that each administrator using the console is forced to
authenticate using their individual credentials. They are concerned that administrators may forget to
log off the terminal, which would easily allow others to gain access to the Symantec Endpoint
Protection Manager (SEPM) console.
Which setting should the administrator disable to minimize the risk of non-authorized users logging
into the SEPM console?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 20
Which Incident View widget shows the parent-child relationship of related security events?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Question 1 of 20