Skip to content

250-580 Endpoint Security Complete - R2 Technical Specialist Practice Questions

Prepare for 250-580 with more than an answer.

226 questions in the full set20 sample questionsUpdated Aug 11, 2025
Exam fee
$250 USD
Level
Technical Specialist
Valid for
2 years
Domains covered on the exam 6
  1. Describe the Symantec Endpoint Security Complete Offering15%
  2. Installation and Deployment20%
  3. Policy Configuration and Management25%
  4. Threat Detection and Response20%
  5. Reporting and Monitoring10%
  6. Maintenance and Troubleshooting10%
  1. 1

    A university with a large, transient student population needs to deploy the Symantec Agent to thousands of student-owned laptops (Windows and macOS) that are not part of the university's domain. The deployment must be simple for non-technical users and ensure the devices are placed in the correct 'Student' group in the ICDm console. Which deployment method is best suited for this scenario?

    Show answer details

    Correct answer: B

    Creating a redistributable package is the ideal method for unmanaged, non-domain devices. The administrator can pre-configure the package to automatically assign the client to the 'Student' group upon installation. Hosting this self-contained installer on a portal allows students to easily download and install it themselves without requiring administrative intervention or complex deployment tools.

  2. 2

    After a recent network change, an administrator notices that a group of clients managed by a specific Group Update Provider (GUP) are no longer receiving definition updates. The clients can still communicate with the SEPM. The administrator suspects a firewall is blocking the GUP traffic. Which port must be open for clients to download content from a GUP?

    Show answer details

    Correct answer: C

    Clients download content from a GUP over TCP port 2967. This is the port the GUP's lightweight web service listens on to serve definition files. Port 8014 is the default for client-SEPM communication, but content distribution from a GUP uses this dedicated port.

  3. 3

    An EDR analyst is reviewing a high-priority incident and needs to quickly gather all relevant artifacts from the affected endpoint for offline analysis. This includes running processes, network connections, registry keys, and a copy of a suspicious file located at C:\Users\Public\update.exe. Which single EDR command should the analyst execute?

    Show answer details

    Correct answer: B

    The 'Trigger Endpoint Dump' command is a comprehensive forensic tool. It collects a snapshot of the endpoint's state, including running processes, services, network connections, registry information, and more, into a single package. While 'Get File' would retrieve the executable, it would not gather the other critical system artifacts needed for a full analysis.

  4. 4

    A retail company is deploying SES Complete to its Point-of-Sale (POS) terminals. These devices run a specific set of applications and should never have new software installed. The administrator needs to implement the most restrictive security posture possible to prevent any unauthorized executables from running. Which feature and mode should be used?

    Show answer details

    Correct answer: B

    System Lockdown in whitelist mode is the ideal solution for fixed-function devices like POS terminals. This mode creates a fingerprint list (hash) of all executables in a known-good state and blocks any file not on the list from running. This provides the highest level of protection against unauthorized code execution, as it follows a default-deny principle.

  5. 5

    A company is using the SEPM Bridge to manage its on-premises clients via the ICDm cloud console. An administrator makes a change to a firewall policy in the ICDm console. What is the process flow for this policy change to reach an on-premises client?

    sequenceDiagram participant Admin participant ICDm as ICDm Cloud Console participant Bridge as SEPM Bridge participant SEPM as On-Prem SEPM participant Client Admin->>ICDm: Modifies Firewall Policy ICDm->>Bridge: Pushes Policy Update Bridge->>SEPM: Relays Policy to SEPM DB SEPM-->>Client: ??? Client-->>SEPM: Acknowledges Policy

    What action correctly fills in the '???' in the diagram, representing how the client receives the new policy from the SEPM?

    Show answer details

    Correct answer: B

    In a standard SEPM-managed environment (even when bridged to the cloud), clients operate on a pull model. They check in with the SEPM at a configured interval, known as the heartbeat. During this heartbeat, the SEPM informs the client if a new policy is available, and the client then downloads it. The SEPM does not actively push policies to clients.

  6. 6

    A security architect is designing a Symantec Endpoint Security (SES) Complete policy for a group of developers who frequently use unsigned, custom-compiled executables for testing. The CISO has mandated that Application Control must be enabled in blacklist mode for all workstations, but developer productivity should not be impeded. Which policy configuration provides the most secure and efficient solution to meet these conflicting requirements?

    Show answer details

    Correct answer: D

    This is the most secure and scalable solution. Using a trusted publisher certificate allows developers to sign their own compiled code, which Application Control will then trust. This avoids the insecurity of path-based exceptions (where malware could be placed), the potential over-permission of allowing any process from an IDE, and the administrative nightmare of constantly updating file hashes every time the code is recompiled.

  7. 7

    A SOC analyst is investigating an incident in the ICDm console that originated from a suspicious PowerShell command. The Endpoint Activity Recorder (EAR) data shows the PowerShell process spawned from winword.exe, which was launched by a user opening an email attachment. To understand the full scope of the attack, what is the most effective next step within the EDR console?

    Show answer details

    Correct answer: C

    While isolation and memory dumps are valid response actions, the immediate next step for investigation is to understand the scope. The Process Lineage view provides a graphical representation of the entire attack chain, from the initial email attachment to the PowerShell execution and any subsequent actions. This is the most efficient way to quickly grasp the full context before deciding on specific remediation or containment actions.

  8. 8

    A global corporation is deploying SES Complete using a hybrid model. They have an existing on-premises SEPM managing 10,000 clients and need to enroll it with the ICDm cloud console. The security policy requires that all communication between the SEPM and the cloud must pass through a dedicated, explicit proxy server that requires authentication. Which two actions are required to ensure successful enrollment? (Select TWO).

    Show answer details

    Correct answer: B, D

    The Symantec Endpoint Protection Manager itself must be configured to use the proxy for its outbound communications to the cloud console. This is the primary location for setting up this connection.

    For certain SEPM services and the enrollment process itself, SEPM relies on the Windows HTTP Services (WinHTTP). Configuring the proxy at this level ensures that all necessary components can reach the cloud services, supplementing the settings within the SEPM console.

  9. 9

    During a security audit, an administrator discovers that the content definitions for a group of isolated servers in a secure network segment are severely outdated. These servers have no internet access. The administrator has access to a Symantec Endpoint Protection Manager (SEPM) with up-to-date content. What is the most efficient method to update the clients in the secure segment?

    Show answer details

    Correct answer: C

    This is the standard, supported method for managing air-gapped environments. The LUA server acts as an intermediary, downloading content from Symantec and placing it on an internal web or file share (distribution center). The GUP in the secure segment is then configured to pull from this internal location and distribute the updates to its peers. This is far more scalable and manageable than manual .jdb updates or setting up a full replication partner.

  10. 10

    True or False: When an SES Complete policy's Host Integrity check fails for a client, the client is automatically moved to the Quarantine group, regardless of the firewall policy configuration.

    Show answer details

    Correct answer: B

    False. A Host Integrity failure does not automatically move a client to a different group. Instead, it typically triggers a firewall rule that applies a more restrictive 'Quarantine' firewall policy to the non-compliant client, limiting its network access until it meets the integrity requirements. The client remains in its original management group.

Create an account to continue.