Skip to content

250-589 Symantec Web Protection—Edge SWG R2 Technical Specialist Practice Questions

Prepare for 250-589 with more than an answer.

198 questions in the full set20 sample questionsUpdated Oct 18, 2025
Exam fee
$250 USD
Time limit
90 minutes
Questions on the exam
75
Passing score
70%
Level
Technical Specialist
Valid for
24 months
Domains covered on the exam 9
  1. Edge SWG Overview and Architecture10%
  2. Traffic Interception and Policy Application15%
  3. SSL/TLS and Encrypted Traffic Management12%
  4. Central Management and Reporting13%
  5. Authentication and Access Control12%
  6. Content Filtering and Web Usage10%
  7. Security Services and Threat Protection13%
  8. High Risk Isolation and Cloud Integration8%
  9. Diagnostics and Troubleshooting7%
  1. 1

    A university wants to provide content-filtered internet access to students in dormitories. Due to the high volume of streaming media, caching performance is a top priority. The network team is deciding between an explicit proxy and a transparent proxy deployment. Which deployment mode is generally better suited for maximizing caching effectiveness and why?

    Show answer details

    Correct answer: B

    In an explicit deployment, the client's browser is aware of the proxy. For an HTTPS request, the browser sends an HTTP CONNECT method to the proxy containing the full hostname of the destination server. This allows the proxy to make caching, routing, and policy decisions based on the hostname before the SSL session is even established. In a transparent deployment, the proxy initially only sees a destination IP address, which can make it more difficult to apply domain-based policies and can be less efficient for caching until after decryption occurs.

  2. 2

    The command to test the Edge SWG's ability to resolve a specific hostname using its configured DNS servers is dns ____.

    Show answer details

    Correct answer: B

    The dns lookup command, executed from the enabled command-line interface (CLI) of the Edge SWG, is the direct method to test the appliance's own DNS resolution capabilities. It queries the DNS servers configured on the appliance, which is essential for troubleshooting issues where the proxy itself cannot resolve destination hosts.

  3. 3

    What is the primary difference in how authentication is handled between IWA direct and IWA BCAAA (Broadcom Client Application Agent) modes?

    Show answer details

    Correct answer: B

    The core architectural difference is domain membership. In IWA direct mode, the Edge SWG appliance itself must be joined to the Active Directory domain, allowing it to communicate directly with domain controllers. In IWA BCAAA mode, the Edge SWG is not domain-joined. Instead, it offloads authentication and user group lookups to the BCAAA service, which runs on a separate, domain-joined Windows server. This mode is often used when security policies prohibit network appliances from joining the AD domain.

  4. 4

    A security administrator notices that despite having a policy to block access to 'Gambling' websites, some users are still able to access new gambling sites. The administrator confirms the URL categorization subscription is active and the database is up to date. Which Symantec Intelligence Services feature should be enabled to provide more dynamic, real-time protection against such sites?

    Show answer details

    Correct answer: B

    While the local categorization database is a primary defense, it relies on periodic updates. For new or uncategorized URLs, the WebPulse dynamic real-time rating service is essential. When the Edge SWG encounters a URL not in its local database, it can query the WebPulse cloud service. WebPulse uses a global sensor network and advanced analytics to provide an up-to-the-minute category and risk score for the URL, allowing the Edge SWG to block new gambling sites even before the local database is updated.

  5. 5

    A policy trace on an Edge SWG shows the following evaluation flow for a user's request to https://example.com:

    flowchart TD A[Start Request] --> B{SSL Access Layer} B -- Rule 1: SNI=example.com --> C[Action: Intercept] C --> D{Web Auth Layer} D -- Rule 5: User Group=Sales --> E[Action: Authenticate] E --> F{Web Access Layer} F -- Rule 10: Category=Technology --> G[Action: Allow] G --> H[End: Allowed]

    Based on this trace, what can be concluded about the user and the request?

    Show answer details

    Correct answer: C

    The diagram clearly shows the step-by-step evaluation. The SSL Access Layer decided to 'Intercept' the traffic. The Web Authentication Layer then matched a rule for the 'Sales' group, triggering authentication. Finally, the Web Access Layer matched the request against the 'Technology' category and the action was 'Allow'. This demonstrates a successful, authenticated, and allowed transaction for a sales user accessing a technology site.

  6. 6

    A financial services company is experiencing intermittent connectivity issues with a critical banking application that uses mutual TLS (mTLS) for client-server authentication. The issues began after deploying Edge SWG with full SSL interception. A policy trace reveals that the Edge SWG is attempting to intercept the traffic, causing the mTLS handshake to fail. Which configuration change is the most effective and secure method to resolve this issue?

    Show answer details

    Correct answer: C

    Mutual TLS (mTLS) requires both the client and server to present valid certificates. SSL interception breaks this process because the Edge SWG presents its own emulated certificate to the client. The correct solution is to bypass interception for this specific traffic. Using the Server Certificate Common Name in the SSL Interception Layer is a precise and secure way to create this bypass, ensuring only the intended application traffic is excluded from inspection. Installing the client's private key on the proxy is a significant security risk, and disabling protocol detection is too broad and may have unintended consequences.

  7. 7

    A network administrator is configuring IWA direct authentication on an Edge SWG appliance. Despite correctly configuring the realm and joining the domain, users are still being prompted for credentials. A packet capture shows that client requests to the Edge SWG lack the necessary Kerberos ticket. Which of the following is the most likely cause of this issue?

    Show answer details

    Correct answer: B

    For IWA to function transparently, the client browser must recognize the proxy as part of the Local Intranet zone. This setting allows the browser to automatically send the user's Kerberos ticket with the request. If the proxy's hostname or IP is not in this zone, the browser will treat it as an external site and will not send the authentication ticket, resulting in a credential prompt. While time sync issues and incorrect SPNs can cause IWA failures, the lack of a Kerberos ticket in the initial request points directly to a client-side zone configuration problem.

  8. 8

    An administrator needs to create a policy that isolates all web traffic destined for newly registered domains, as these are considered high-risk. Which TWO components are essential to build this policy in the Visual Policy Manager (VPM)? (Select TWO)

    Show answer details

    Correct answer: A, B

    To implement this policy, an administrator needs a Web Access Layer to define the traffic handling rule. The destination must be configured to match the 'Newly Registered Domains' category, which is provided by Symantec's categorization services. The action would then be set to trigger High Risk Isolation. A 'Threat Risk Level' object is for risk scores, not domain age, and an 'SSL Access Layer' is for controlling the initial SSL handshake, not for applying isolation based on content category.

  9. 9

    A multinational corporation uses Management Center to administer a fleet of Edge SWG appliances across different geographical regions. The security team needs to deploy a new, urgent VPM policy to block a zero-day threat, but only to the appliances in the European region. What is the most efficient method to achieve this in Management Center?

    Show answer details

    Correct answer: B

    Management Center is designed for centralized administration. The most efficient and scalable method is to organize appliances into logical groups (e.g., by region). A job can then be created to distribute the policy file specifically to the 'European' device group. This ensures targeted deployment without affecting other regions and provides a clear audit trail. Distributing to all devices is incorrect, and manual configuration defeats the purpose of centralized management.

  10. 10

    True or False: When Edge SWG is integrated with a Content Analysis appliance via ICAP, the Edge SWG is solely responsible for performing the actual malware scanning of files.

    Show answer details

    Correct answer: B

    This statement is false. In an ICAP integration, the Edge SWG acts as the ICAP client. It intercepts the traffic and, based on policy, forwards the content (e.g., a file download) to the Content Analysis appliance (the ICAP server). The Content Analysis appliance is the component that performs the actual malware scanning, sandboxing, and analysis, and then sends a response back to the Edge SWG indicating whether the content is clean or malicious.

Create an account to continue.