Broadcom Carbon Black Application Control Technical Specialist (250-600) Certification Sample Questions
Getting knowledge of the Broadcom 250-600 exam structure and question format is vital in preparing for the Symantec Carbon Black Application Control Technical Specialist certification exam. Our Broadcom Carbon Black Application Control Technical Specialist sample questions offer you information regarding the question types and level of difficulty you will face in the real exam. The benefit of using these Broadcom 250-600 sample questions is that you will get to check your preparation level or enhance your knowledge by learning the unknown questions. You will also get a clear idea of the exam environment and exam pattern you will face in the actual exam with the Symantec Carbon Black Application Control Technical Specialist Sample Practice Test. Therefore, solve the Broadcom Carbon Black Application Control Technical Specialist sample questions to stay one step forward in grabbing the Broadcom Symantec Carbon Black Application Control Technical Specialist credential.
These Broadcom 250-600 sample questions are simple and basic questions similar to the actual Broadcom Carbon Black Application Control Technical Specialist questions. If you want to evaluate your preparation level, we suggest taking our Symantec Carbon Black Application Control Technical Specialist Premium Practice Test. You might face difficulties while solving the real-exam-like questions. But, you can work hard and build your confidence on the syllabus topics through unlimited practice attempts.
Broadcom 250-600 Sample Questions:
01. A manager reviewing the deployment argues that once every policy sits at High Enforcement, where no unapproved or banned file is permitted to run, the team can stop maintaining approvals and custom rules, because the enforcement level will do that work by itself.
Which assessment of that argument is best supported?
a) It is right, provided every endpoint has completed agent initialization first
b) It is partly right: rules would then be needed only for files to be banned
c) It is wrong: at High, approvals and rules are what let legitimate files run
d) It is right: at High the agent approves each file as it observes it execute
02. An administrative utility is approved across the estate and several teams rely on it. A group of endpoints handling regulated data must not be able to run that utility at all, while every other endpoint continues to use it as before.
Which custom rule type addresses that requirement on the restricted endpoints?
a) An Execution Control rule, applied to the policy those restricted endpoints belong to
b) A Trusted Directory rule, applied to the policy those restricted endpoints belong to
c) A File Integrity Control rule, applied to the policy those restricted endpoints belong to
d) A File Creation Control rule, applied to the policy those restricted endpoints belong to
03. A custom rule naming several paths, several processes and several users has been confirmed on one test endpoint, where it acted exactly as its author intended.
Which two statements correctly describe the limits of what that confirmation supports?
(Choose two.)
a) It establishes that the rule's pattern cannot match any file that the author did not intend
b) It says nothing about whether other endpoints are in a state to apply the rule at all
c) It removes the need to review the block events the rule produces once it is in service
d) It shows the rule expands to the smallest number of rules that the requirement allows
e) It covers the combination exercised; the rule's other expanded combinations stay untested
04. An organisation is setting up console accounts for its App Control team. The administrator who writes and edits custom rules is deliberately given a different console account from the administrator who reviews block events and decides which blocked files are approved.
What does that separation achieve?
a) The estate needs fewer custom rules because the two duties no longer overlap
b) Block events raised for one account's rules are hidden from the other account
c) Rules written by one account are evaluated ahead of rules written by another
d) Neither administrator is the only check on a change that the other has made
05. A user asks for an unapproved utility to be approved after it was stopped on their endpoint. No business owner will vouch for the utility, the user cannot say where the file came from, and the same file has been recorded executing on two endpoints in a department that never requested it. The endpoints run at High Enforcement.
Which response holds up under those facts?
a) Leave the file unapproved and establish its origin and spread before any decision
b) Approve the path it runs from, so the same request does not return from others
c) Lower that endpoint's enforcement level until the investigation has been completed
d) Approve it for that user alone as a temporary measure, and review the case later
06. A firewall change has silently dropped the traffic an endpoint's agent sends to the App Control Server. The endpoint runs at High Enforcement, where no unapproved or banned file is permitted to run.
An administrator approves a file in the console for that endpoint's policy, and the user then tries to run it again.
What does the user experience?
a) Every file is blocked on that endpoint, since the agent stops honouring existing approvals.
b) The file is still blocked, because the approval has not reached the agent on that endpoint.
c) The file runs, because the agent asks the console directly each time a file is executed.
d) The file runs, because High Enforcement is suspended while the server is unreachable.
07. One endpoint produces repeated block events for a file belonging to a departmental application. The forty other endpoints in the same policy run the same application, and the console shows neither block events nor new file events naming that file for any of them.
What does the pattern most strongly indicate?
a) The other forty agents have stopped reporting their events to the App Control Server.
b) The file was banned across the policy and the ban has reached only that endpoint.
c) The policy applies a stricter enforcement level to that endpoint than to its peers.
d) The file exists only on that endpoint, so the cause is local and not a policy fault.
08. A utility that is not part of the approved software set keeps turning up on endpoints in one department. A manager asks the App Control administrator to put a meter on it so that it stops running there while the department finds a replacement.
What should the administrator tell the manager the meter will do?
a) It will record how often the utility runs there and will stop none of those runs
b) It will stop the utility on any endpoint whose policy is at High Enforcement
c) It will approve the utility for that department so its use can be counted
d) It will let the utility run until a chosen count is reached and stop it after that
09. A group of workstations belongs to a policy that has no custom rules applied to it. An administrator states that the enforcement level set in that policy therefore has nothing to work through, and that the level will begin to govern those workstations only once at least one custom rule has been added to their policy.
Is this statement true or false?
a) True
b) False
10. An administrator who ran App Control for two years has left the organisation, and their console login account is removed the same day. During those two years the account approved a number of files and authored several custom rules that are still in service.
What is the effect on the protected endpoints?
a) The rules that account authored stop being applied until they are re-created
b) The endpoints drop to a lower enforcement level until an owner is nominated
c) The approvals and rules stay in force; only console access is withdrawn
d) The approvals granted by that account lapse, so those files become unapproved
Answers:
|
Question: 01 Answer: c |
Question: 02 Answer: a |
Question: 03 Answer: b, e |
Question: 04 Answer: d |
Question: 05 Answer: a |
|
Question: 06 Answer: b |
Question: 07 Answer: d |
Question: 08 Answer: a |
Question: 09 Answer: b |
Question: 10 Answer: c |
Note: For any error in Symantec Carbon Black Application Control Technical Specialist (250-600) certification exam sample questions, please update us by writing an email on feedback@certfun.com.
- 250-600 Questions |
- 250-600 Quiz |
- 250-600 |
- Broadcom Carbon Black Application Control Technical Specialist Certification |
- Broadcom 250-600 Question Bank |
- Carbon Black Application Control Technical Specialist Mock Exam |
- Carbon Black Application Control Technical Specialist |
- Carbon Black Application Control Technical Specialist Sample Questions |
- Broadcom 250-600 Practice Test Free |
- Carbon Black Application Control Technical Specialist Certification Sample Questions
