250-586 Endpoint Security Complete Implementation - Technical Specialist Practice Questions
Prepare for 250-586 with more than an answer.
- Exam fee
- $250 USD
- Level
- Technical Specialist
- Valid for
- 3 years
Domains covered on the exam 5
- Architecture & Design Essentials20%
- Assessing Customer Environment and Objectives25%
- Designing the Solution25%
- Implementing the Solution20%
- Managing the Ongoing Customer Relationship10%
- 1
A new SEPM administrator is reviewing the system requirements for a planned upgrade. The documentation states that the SEPM requires access to specific Symantec URLs for various functions. Which of the following functions relies on outbound connectivity to Symantec servers? (Select ALL that apply)
Show answer details
Correct answer: A, B, C
The SEPM must connect to Symantec's licensing servers to activate its license upon installation and periodically validate it.
Unless using an internal LiveUpdate Administrator (LUA) server that gets its updates from another source, the SEPM will connect directly to Symantec's LiveUpdate servers to download all protection content.
SEPMs submit anonymized threat data to the Symantec Global Intelligence Network, which helps improve threat detection for all customers. This requires outbound connectivity.
- 2
True or False: The 'Security Assessment' report within SES Complete can be used to identify systems that are missing critical OS patches, providing visibility into vulnerabilities that cannot be directly fixed by Symantec policies.
Show answer details
Correct answer: A
This is true. The Security Assessment feature within SES Complete provides insights into the overall security posture of endpoints, which includes identifying missing OS patches. While SES cannot deploy the patches, it highlights the risk, allowing administrators to use a dedicated patch management system to remediate the vulnerability.
- 3
A consultant is performing the initial data gathering phase for a new SES Complete implementation. The customer has a complex, multi-VLAN network environment. Which piece of information is most critical for designing the firewall policy and ensuring proper client communication?
Show answer details
Correct answer: B
Understanding the network topology is paramount. A detailed diagram reveals how the network is segmented, which is essential for identifying where firewall rules will be needed to allow communication between clients in various VLANs and the central SEPM servers. Without this, client communication is likely to fail.
- 4
A security analyst is investigating a threat alert from the SES Complete console. The analyst needs to retrieve a suspicious file from an endpoint for further analysis in a sandbox. The endpoint is currently online. Which feature allows the analyst to do this directly from the console?
Show answer details
Correct answer: D
The 'Get File' command is a specific EDR response action available in the SES Complete console. It allows an authorized analyst to directly request and download a specific file from an online endpoint to the console for forensic analysis. This is the most direct and appropriate tool for the task.
- 5
An administrator observes that several clients in a remote office are showing as offline in the SEPM console, but users confirm their machines are powered on and connected to the network. The administrator suspects a communication breakdown. Which client-side log file would provide the most detailed information about the client's attempts to connect to the SEPM?
sequenceDiagram participant Client participant Firewall participant SEPM Client->>Firewall: Heartbeat (Sylink) Firewall--xClient: Blocked Client->>SEPM: (Connection Fails) Note right of Client: Check Sylink.log for error codesShow answer details
Correct answer: B
The sylink.log file is the primary diagnostic tool for troubleshooting client-to-SEPM communication issues. It records every heartbeat attempt, the SEPM server it's trying to contact, and the HTTP response codes or error messages received. Analyzing this log will quickly reveal if the client can resolve the SEPM's address, if the connection is being blocked by a firewall, or if there are server-side errors. This log must often be enabled first via the SEPM console or client-side registry key.
- 6
A financial services company with 15,000 endpoints is designing a new Symantec Endpoint Security Complete (SESC) deployment. The company has a central data center and 50 branch offices with varying bandwidth. The primary goal is to minimize WAN traffic for definition updates while ensuring high availability for policy management. The design proposes two load-balanced Symantec Endpoint Protection Managers (SEPMs) in the data center and Group Update Providers (GUPs) in each branch. How should the SEPMs be configured for replication to meet these requirements?
Show answer details
Correct answer: A
For high availability and reduced WAN traffic, the best practice is to configure the SEPMs as replication partners for logs and policies only. Client packages and definitions are large and should be downloaded from the central LiveUpdate source to each SEPM independently, and then distributed to clients via GUPs. Replicating packages would consume significant bandwidth between the SEPMs without adding value in this GUP-based design.
- 7
During the assessment phase for an SES Complete implementation at a hospital, an administrator discovers that several critical medical imaging devices run on an unsupported legacy Windows XP Embedded OS. These devices cannot be upgraded but must be protected. Which SES Complete features should be prioritized in the solution design for these specific devices? (Select TWO)
Show answer details
Correct answer: A, B
System Lockdown (Application Hardening) is ideal for fixed-function devices like medical equipment. It can create a whitelist of known good applications and block any unauthorized executables from running, effectively preventing malware execution on the unsupported OS.
Since the OS cannot be patched, it is vulnerable to network-based exploits. The Network IPS can block known attack signatures at the network layer, providing a critical compensating control to protect the vulnerable OS from being compromised.
- 8
An administrator is troubleshooting an issue where SES Complete clients in a specific remote office are not receiving policy updates from the central SEPM. All other offices are functioning correctly. The remote office clients can successfully ping the SEPM server by its IP address. What is the most likely cause of this issue?
Show answer details
Correct answer: A
The ability to ping the server confirms basic network connectivity (ICMP), but it does not guarantee that the application-level communication ports (e.g., TCP 8014 or 443) are open. A firewall rule blocking these specific ports for traffic from the remote office's subnet is the most common and logical cause for this type of isolated communication failure.
- 9
True or False: When configuring a System Lockdown policy in 'blacklist' mode, the policy will block only the applications explicitly listed, and all other unlisted applications will be allowed to run.
Show answer details
Correct answer: A
This statement is true. System Lockdown has two modes: whitelist and blacklist. In blacklist mode, it functions as a traditional application blocking tool, preventing only the specified applications (by file hash or path) from executing, while permitting all others.
- 10
A university is implementing SES Complete across its campus, which includes administrative offices, student labs, and faculty research departments. The security team wants to apply a baseline security policy to all computers but allow specific departments, like computer science, to have more lenient script control settings for academic purposes, without duplicating the entire baseline policy. What is the most efficient method to achieve this in SEPM?
Show answer details
Correct answer: A
This is the correct and most efficient design. By creating a child group that inherits from the parent, all baseline settings are automatically applied. Creating a specific, non-shared policy for a single feature (like Application and Device Control) for the child group allows administrators to override just that part of the policy while inheriting all other settings, avoiding policy duplication and simplifying management.
