Weekend Sale 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sale65best

Free Symantec 250-561 Practice Exam with Questions & Answers | Set: 2

Questions 11

What are two (2) benefits of a fully cloud managed endpoint protection solution? (Select two)

Options:
A.

Increased content update frequency

B.

Increased visibility

C.

Reduced 3rd party licensing cost

D.

Reduced database usage

E.

Reduced network usage

Symantec 250-561 Premium Access
Questions 12

The ICDm has generated a blacklist task due to malicious traffic detection. Which SES component was utilized to make that detection?

Options:
A.

Antimalware

B.

Reputation

C.

Firewall

D.

IPS

Questions 13

Why would an administrator choose the Server-optimized installation option when creating an installation package?

Options:
A.

To limit the Intrusion Prevention policy to use server-only signatures.

B.

To add the Server-optimized Firewall policy

C.

To add the SES client's Optimize Memory setting to the default server installation.

D.

To reduce the SES client's using resources that are required for other server-specific processes.

Questions 14

Which statement best describes Artificial Intelligence?

Options:
A.

A program that automates tasks with a static set of instructions

B.

A program that can predict when a task should be performed

C.

A program that is autonomous and needs training to perform a task

D.

A program that learns from experience and perform autonomous tasks

Questions 15

Which security threat uses malicious code to destroy evidence, break systems, or encrypt data?

Options:
A.

Execution

B.

Persistence

C.

Impact

D.

Discovery

Questions 16

Which technique randomizes the e memory address map with Memory Exploit Mitigation?

Options:
A.

SEHOP

B.

ROPHEAP

C.

ASLR

D.

ForceDEP

Questions 17

An administrator must create a custom role in ICDm.

Which area of the management console is able to have access restricted or granted?

Options:
A.

Policy Management

B.

Hybrid device management

C.

Agent deployment

D.

Custom Dashboard Creation

Questions 18

Which device page should an administrator view to track the progress of an issued device command?

Options:
A.

Command Status

B.

Command History

C.

Recent Activity

D.

Activity Update

Questions 19

An administrator suspects that several computers have become part of a botnet. What should the administrator do to detect botnet activity on the network?

Options:
A.

Enable the Command and Control Server Firewall

B.

Add botnet related signatures to the IPS policy's Audit Signatures list

C.

Enable the IPS policy's Show notification on the device setting

D.

Set the Antimalware policy's Monitoring Level to 4

Questions 20

What must an administrator check prior to enrolling an on-prem SEPM infrastructure into the cloud?

Options:
A.

Clients are running SEP 14.2 or later

B.

Clients are running SEP 14.1.0 or later

C.

Clients are running SEP 12-6 or later

D.

Clients are running SEP 14.0.1 or late

Exam Code: 250-561
Certification Provider: Symantec
Exam Name: Endpoint Security Complete - Administration R1
Last Update: Jul 19, 2025
Questions: 70
PDF + Testing Engine
$164.99
$57.75
Testing Engine
$124.99
$43.75
PDF (Q&A)
$104.99
$36.75