Summer Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70track

Free Symantec 250-587 Practice Exam with Questions & Answers | Set: 2

Questions 11

Which detection method is best suited for identifying sensitive content within scanned images or image-based PDF files?

Options:
A.

Keyword-Based Detection

B.

Optical Character Recognition (OCR)

C.

Regular Expression Matching

D.

Exact Data Matching (EDM)

Symantec 250-587 Premium Access
Questions 12

How do Cloud Detection Service and the Enforce server communicate with each other?

Options:
A.

Enforce initiates communication with Cloud Detection Service, which is expecting connections on port 8100.

B.

Cloud Detection Service initiates communication with Enforce, which is expecting connections on port 443.

C.

Cloud Detection Service initiates communication with Enforce, which is expecting connections on port 1443.

D.

Enforce initiates communication with Cloud Detection Service, which is expecting connections on port 443.

Questions 13

What is the recommended ratio of Enforce servers to Oracle database servers when deploying Symantec DLP?

Options:
A.

1:1

B.

1:2

C.

2:1

D.

3:1

Questions 14

Which two DLP products support the new Optical Character Recognition (OCR) engine in Symantec DLP 15.0? (Choose two.)

Options:
A.

Endpoint Prevent

B.

Cloud Service for Email

C.

Network Prevent for Email

D.

Network Discover

E.

Cloud Detection Service

Questions 15

A DLP administrator has enabled and successfully tested custom attribute lookups for incident data based on the Active Directory LDAP plugin. The Chief Information Security Officer (CISO) has attempted to generate a User Risk Summary report, but the report is empty. The DLP administrator confirms the Cisco’s role has the “User Reporting” privilege enabled, but User Risk reporting is still not working.

What is the probable reason that the User Risk Summary report is blank?

Options:
A.

Only DLP administrators are permitted to access and view data for high risk users.

B.

The Enforce server has insufficient permissions for importing user attributes.

C.

User attribute data must be configured separately from incident data attributed.

D.

User attributes have been incorrectly mapped to Active Directory accounts.

Questions 16

Which statement accurately describes where Optical Character Recognition (OCR) components must be installed?

Options:
A.

The OCR engine must be installed on detection server other than the Enforce server.

B.

The OCR server software must be installed on one or more dedicated (non-detection) Linux servers.

C.

The OCR engine must be directly on the Enforce server.

D.

The OCR server software must be installed on one or more dedicated (non-detection) Windows servers.

Questions 17

Which server target uses the “Automated Incident Remediation Tracking” feature in Symantec DLP?

Options:
A.

Exchange

B.

File System

C.

Lotus Notes

D.

SharePoint

Questions 18

Under the “System Overview” in the Enforce management console, the status of a Network Monitor detection server is shown as “Running Selected.” The Network Monitor server’s event logs indicate that the packet capture and filereader processes are crashing.

What is a possible cause for the Network Monitor server being in this state?

Options:
A.

There is insufficient disk space on the Network Monitor server.

B.

The Network Monitor server’s certificate is corrupt or missing.

C.

The Network Monitor server’s license file has expired.

D.

The Enforce and Network Monitor servers are running different versions of DLP.

Questions 19

What detection method utilizes Data Identifiers?

Options:
A.

Indexed Document matching (IDM)

B.

Described Content Matching (DCM)

C.

Directory Group Matching (DGM)

D.

Exact Data Matching (EDM)

Questions 20

A software company wants to protect its source code, including new source code created between scheduled indexing runs.

Which detection method should the company use to meet this requirement?

Options:
A.

Exact Data Matching (EDM)

B.

Described Content Matching (DCM)

C.

Vector Machine Learning (VML)

D.

Indexed Document Matching (IDM)

Exam Code: 250-587
Certification Provider: Symantec
Exam Name: Symantec Data Loss Prevention 16.x Administration Technical Specialist
Last Update: Aug 8, 2026
Questions: 108