250-438 Exam Questions
78 real 250-438 exam questions with expert-verified answers and explanations. Page 2 of 2.
- Question #53
The database is full and the Incident Persister is unable to process incidents. Which two file types could be present in Vontu/protect/incidents? (Select two.)
- Question #54
A role is configured for XML export and a user executes the export XML incident action. What must be done before history information is included in the export?
- Question #55System Architecture and Components
What detection server is used for Network Discover, Network Protect, and Cloud Storage?
Network DiscoverNetwork ProtectCloud Storagedetection server types - Question #56Incident Remediation and Reporting
Which product is able to replace a confidential document residing on a file share with a marker file explaining why the document was removed?
Network Protectmarker filefile sharedocument remediation - Question #57Policy Management
Which two locations can Symantec DLP scan and perform Information Centric Encryption (ICE) actions on? (Choose two.)
Information Centric EncryptionICE actionsSharePointfile store - Question #58
Which detection method depends on "training sets"?
- Question #59Troubleshooting
A DLP administrator needs to stop the PacketCapture process on a detection server. Upon inspection of the Server Detail page, the administrator discovers that all processes are mis...
PacketCaptureServer Detail pageAdvanced Process Controlprocess display - Question #60System Architecture and Components
What detection technology supports partial contents matching?
detection technologyIndexed Document Matchingpartial contents matchingIDM - Question #61System Architecture and Components
What is Application Detection Configuration?
Application Detection ConfigurationCloud Detection ServiceCloudSOCpolicy violation notification - Question #62
What detection method utilizes Data Identifiers?
- Question #63
A user is unable to log in as sysadmin. The Data Loss Prevention system is configured to use Active Directory authentication. The user is a member of two roles, sysadmin and remedi...
- Question #64
Which product provides support for the Citrix XenApp virtualization platform?
- Question #65Administration and Maintenance
Which tool must a DLP administrator run to certify the database prior to upgrading DLP?
database certificationupgrade preparationUpgrade Readiness Toolpre-upgrade - Question #66
What is the correct order for data in motion when a customer has integrated their CloudSOC and DLP solutions?
- Question #67
Refer to the exhibit. What activity should occur during the baseline phase, according to the risk reduction model?
- Question #68
Which two DLP products support the new Optical Character Recognition (OCR) engine in Symantec DLP 15.0? (Choose two.)
- Question #69Policy Management
Which two actions are available for a "Network Prevent: Remove HTTP/HTTPS content" response rule when the content is unable to be removed? (Choose two.)
Network PreventHTTP/HTTPSresponse rule fallbackcontent removal - Question #70
Which two factors are common sources of data leakage where the main actor is well-meaning insider? (Choose two.)
- Question #71
What is required on the Enforce server to communicate with the Symantec DLP database?
- Question #72Policy Management
Which option is an accurate use case for Information Centric Encryption (ICE)?
Information Centric EncryptionICE use caseremovable storagefile encryption - Question #73
Which two functions of the communications architecture ensure that the system will automatically recover if a network connectivity failure occurs between the detection servers and...
- Question #74
Which DLP Agent task is unique to the Symantec Management Platform and is unavailable through the Enforce console?
- Question #75Planning and Deployment
Which two detection servers are available as virtual appliances? (Choose two.)
virtual applianceNetwork Prevent for WebNetwork Prevent for Emaildetection servers - Question #76Policy Management
A company needs to secure the content of all Mergers and Acquisitions Agreements However, the standard text included in all company literature needs to be excluded. How should the...
IDM profilewhitelistingDLP content detectionIndexed Document Matching - Question #77Incident Remediation and Reporting
Which server target uses the "Automated Incident Remediation Tracking" feature in Symantec DLP?
Automated Incident Remediation Trackingserver targetsFile SystemSymantec DLP - Question #78
An administrator is unable to log in to the Enforce management console as "sysadmin". Symantec DLP is configured to use Active Directory authentication. The administrator is a memb...
- Question #79
A DLP administrator is attempting to add a new Network Discover detection server from the Enforce management console. However, the only available options are Network Monitor and En...
- Question #80Troubleshooting
A DLP administrator is testing Network Prevent for Web functionality. When the administrator posts a small test file to a cloud storage website, no new incidents are reported. What...
Network Prevent for WebICAPfile size thresholdincident generation