we provide Accurate Symantec 250-438 torrent which are the best for clearing 250-438 test, and to get certified by Symantec Administration of Symantec Data Loss Prevention 15. The 250-438 Questions & Answers covers all the knowledge points of the real 250-438 exam. Crack your Symantec 250-438 Exam with latest dumps, guaranteed!
Online Symantec 250-438 free dumps demo Below:
NEW QUESTION 1
What is the correct configuration for “BoxMonitor.Channels” that will allow the server to start as a Network Monitor server?
- A. Packet Capture, Span Port
- B. Packet Capture, Network Tap
- C. Packet Capture, Copy Rule
- D. Packet capture, Network Monitor
Answer: C
Explanation:
Reference: https://support.symantec.com/en_US/article.TECH218980.html
NEW QUESTION 2
A customer needs to integrate information from DLP incidents into external Governance, Risk and Compliance dashboards.
Which feature should a third party component integrate with to provide dynamic reporting, create custom incident remediation processes, or support business processes?
- A. Export incidents using the CSV format
- B. Incident Reporting and Update API
- C. Incident Data Views
- D. A Web incident extraction report
Answer: B
NEW QUESTION 3
A DLP administrator is preparing to install Symantec DLP and has been asked to use an Oracle database provided by the Database Administration team. Which SQL *Plus command should the administrator utilize to determine if the database is using a supported version of Oracle?
- A. select database version from <database name>;
- B. select * from db$version;
- C. select * from v$version;
- D. select db$ver from <database name>;
Answer: C
Explanation:
Reference: https://www.symantec.com/connect/forums/new-install-oracle-returns-error
NEW QUESTION 4
Which service encrypts the message when using a Modify SMTP Message response rule?
- A. Network Monitor server
- B. SMTP Prevent
- C. Enforce server
- D. Encryption Gateway
Answer: D
Explanation:
Reference: https://www.symantec.com/connect/articles/network-prevent
NEW QUESTION 5
Which two detection technology options run on the DLP agent? (Choose two.)
- A. Optical Character Recognition (OCR)
- B. Described Content Matching (DCM)
- C. Directory Group Matching (DGM)
- D. Form Recognition
- E. Indexed Document Matching (IDM)
Answer: BE
NEW QUESTION 6
A DLP administrator has added several approved endpoint devices as exceptions to an Endpoint Prevent policy that blocks the transfer of sensitive data. However, data transfers to these devices are still being blocked. What is the first action an administrator should take to enable data transfers to the approved endpoint devices?
- A. Disable and re-enable the Endpoint Prevent policy to activate the changes
- B. Double-check that the correct device ID or class has been entered for each device
- C. Verify Application File Access Control (AFAC) is configured to monitor the specific application
- D. Edit the exception rule to ensure that the “Match On” option is set to “Attachments”
Answer: D
NEW QUESTION 7
A DLP administrator needs to stop the PacketCapture process on a detection server. Upon inspection of the Server Detail page, the administrator discovers that all processes are missing from the display. What are the processes missing from the Server Detail page display?
- A. The Display Process Control setting on the Advanced Settings page is disabled.
- B. The Advanced Process Control setting on the System Settings page is deselected.
- C. The detection server Display Control Process option is disabled on the Server Detail page.
- D. The detection server PacketCapture process is displayed on the Server Overview page.
Answer: B
Explanation:
Reference: https://support.symantec.com/content/unifiedweb/en_US/article.TECH220250.html
NEW QUESTION 8
Which two components can perform a file system scan of a workstation? (Choose two.)
- A. Endpoint Server
- B. DLP Agent
- C. Network Prevent for Web Server
- D. Discover Server
- E. Enforce Server
Answer: BD
NEW QUESTION 9
A DLP administrator is checking the System Overview in the Enforce management console, and all of the detection servers are showing as “unknown”. The Vontu services are up and running on the detection servers. Thousands of .IDC files are building up in the Incidents directory on the detection servers. There is good network connectivity between the detection servers and the Enforce server when testing with the telnet command.
How should the administrator bring the detection servers to a running state in the Enforce management console?
- A. Restart the Vontu Update Service on the Enforce server
- B. Ensure the Vontu Monitor Controller service is running in the Enforce server
- C. Delete all of the .BAD files in the Incidents folder on the Enforce server
- D. Restart the Vontu Monitor Service on all the affected detection servers
Answer: B
NEW QUESTION 10
Which two factors are common sources of data leakage where the main actor is well-meaning insider? (Choose two.)
- A. An absence of a trained incident response team
- B. A disgruntled employee for a job with a competitor
- C. Merger and Acquisition activities
- D. Lack of training and awareness
- E. Broken business processes
Answer: BD
NEW QUESTION 11
Which two actions are available for a “Network Prevent: Remove HTTP/HTTPS content” response rule when the content is unable to be removed? (Choose two.)
- A. Allow the content to be posted
- B. Remove the content through FlexResponse
- C. Block the content before posting
- D. Encrypt the content before posting
- E. Redirect the content to an alternative destination
Answer: AE
NEW QUESTION 12
What detection server type requires a minimum of two physical network interface cards?
- A. Network Prevent for Web
- B. Network Prevent for Email
- C. Network Monitor
- D. Cloud Detection Service (CDS)
Answer: A
NEW QUESTION 13
Which server target uses the “Automated Incident Remediation Tracking” feature in Symantec DLP?
- A. Exchange
- B. File System
- C. Lotus Notes
- D. SharePoint
Answer: B
Explanation:
Reference: https://help.symantec.com/cs/DLP15.0/DLP/v83981880_v120691346/Troubleshooting-automated-incident-remediation-tracking?locale=EN_US
NEW QUESTION 14
A software company wants to protect its source code, including new source code created between scheduled indexing runs. Which detection method should the company use to meet this requirement?
- A. Exact Data Matching (EDM)
- B. Described Content Matching (DCM)
- C. Vector Machine Learning (VML)
- D. Indexed Document Matching (IDM)
Answer: D
Explanation:
Reference: https://help.symantec.com/cs/DLP15.0/DLP/v100774847_v120691346/Scheduling-remote-indexing?locale=EN_US
NEW QUESTION 15
What is the default fallback option for the Endpoint Prevent Encrypt response rule?
- A. Block
- B. User Cancel
- C. Encrypt
- D. Notify
Answer: D
NEW QUESTION 16
DRAG DROP
The Symantec Data Loss risk reduction approach has six stages.
Drag and drop the six correct risk reduction stages in the proper order of Occurrence column.
Select and Place:
- A. Mastered
- B. Not Mastered
Answer: A
Explanation:
Reference: https://www.slideshare.net/iftikhariqbal/symantec-data-loss-prevention-technical-proposal-general
NEW QUESTION 17
Which statement accurately describes where Optical Character Recognition (OCR) components must be installed?
- A. The OCR engine must be installed on detection server other than the Enforce server.
- B. The OCR server software must be installed on one or more dedicated (non-detection) Linux servers.
- C. The OCR engine must be directly on the Enforce server.
- D. The OCR server software must be installed on one or more dedicated (non-detection) Windows servers.
Answer: C
Explanation:
Reference: https://help.symantec.com/cs/dlp15.0/DLP/v122760174_v120691346/Setting-up-OCR-Servers?locale=EN_US
NEW QUESTION 18
A DLP administrator is testing Network Prevent for Web functionality. When the administrator posts a small test file to a cloud storage website, no new incidents are reported. What should the administrator do to allow incidents to be generated against this file?
- A. Change the “Ignore requests Smaller Than” value to 1
- B. Add the filename to the Inspect Content Type field
- C. Change the “PacketCapture.DISCARD_HTTP_GET” value to “false”
- D. Uncheck trial mode under the ICAP tab
Answer: A
Explanation:
Reference: https://help.symantec.com/cs/dlp15.0/DLP/id-SF0B0161467_v120691346/Configuring-Network-Prevent-for-Web-Server?locale=EN_US
NEW QUESTION 19
Why would an administrator set the Similarity Threshold to zero when testing and tuning a Vector Machine Learning (VML) profile?
- A. To capture the matches to the Positive set
- B. To capture the matches to the Negative set
- C. To see the false negatives only
- D. To see the entire range of potential matches
Answer: D
Explanation:
Reference: https://help.symantec.com/cs/dlp15.0/DLP/v45067125_v120691346/Adjusting-the-Similarity-Threshold?locale=EN_US
NEW QUESTION 20
What is Application Detection Configuration?
- A. The Cloud Detection Service (CDS) process that tells Enforce a policy has been violated
- B. The Data Loss Prevention (DLP) policy which has been pushed into Cloud Detection Service (CDC) for files in transit to or residing in Cloud apps
- C. The terminology describing the Data Loss Prevention (DLP) process within the CloudSOC administration portal
- D. The setting configured within the user interface (UI) that determines whether CloudSOC should send a file to Cloud Detection Service (CDS) for analysis.
Answer: A
Explanation:
Reference: https://help.symantec.com/cs/DLP15.0/DLP/v119805091_v120691346/About-Application-Detection%7CSymantec%EF%BF%BD-Data-Loss-Prevention-15.0?locale=EN_US
NEW QUESTION 21
What detection server is used for Network Discover, Network Protect, and Cloud Storage?
- A. Network Protect Storage Discover
- B. Network Discover/Cloud Storage Discover
- C. Network Prevent/Cloud Detection Service
- D. Network Protect/Cloud Detection Service
Answer: B
Explanation:
Reference: https://help.symantec.com/cs/dlp15.0/DLP/v16110606_v120691346/Modifying-the-Network-Discover-Cloud-Storage-Discover-Server-configuration?locale=EN_US
NEW QUESTION 22
What should an incident responder select in the Enforce management console to remediate multiple incidents simultaneously?
- A. Smart Response on the Incident page
- B. Automated Response on the Incident Snapshot page
- C. Smart Response on an Incident List report
- D. Automated Response on an Incident List report
Answer: B
NEW QUESTION 23
......
Recommend!! Get the Full 250-438 dumps in VCE and PDF From Dumpscollection.com, Welcome to Download: https://www.dumpscollection.net/dumps/250-438/ (New 70 Q&As Version)