Broadcom Data Center Security Server Advanced Technical Specialist (250-611) Certification Sample Questions

Broadcom 250-611 VCE, Data Center Security Server Advanced Technical Specialist Dumps, 250-611 PDF, 250-611 Dumps, Data Center Security Server Advanced Technical Specialist VCE, Broadcom Data Center Security Server Advanced Technical Specialist PDFGetting knowledge of the Broadcom 250-611 exam structure and question format is vital in preparing for the Symantec Data Center Security - Server Advanced 6.x Technical Specialist certification exam. Our Broadcom Data Center Security Server Advanced Technical Specialist sample questions offer you information regarding the question types and level of difficulty you will face in the real exam. The benefit of using these Broadcom 250-611 sample questions is that you will get to check your preparation level or enhance your knowledge by learning the unknown questions. You will also get a clear idea of the exam environment and exam pattern you will face in the actual exam with the Symantec Data Center Security - Server Advanced 6.x Technical Specialist Sample Practice Test. Therefore, solve the Broadcom Data Center Security Server Advanced Technical Specialist sample questions to stay one step forward in grabbing the Broadcom Symantec Data Center Security - Server Advanced 6.x Technical Specialist credential.

These Broadcom 250-611 sample questions are simple and basic questions similar to the actual Broadcom Data Center Security Server Advanced Technical Specialist questions. If you want to evaluate your preparation level, we suggest taking our Symantec Data Center Security - Server Advanced 6.x Technical Specialist Premium Practice Test. You might face difficulties while solving the real-exam-like questions. But, you can work hard and build your confidence on the syllabus topics through unlimited practice attempts.

Broadcom 250-611 Sample Questions:

01. A detection policy reporting network shares being created is applied across the estate. The operations team is alerted every time a share appears on a group of test servers, which happens several times a day, and the events themselves are still wanted for the record.
What should be changed?

a) The detection policy, removed from the test servers so their share activity no longer reaches the server
b) 
The policy, reapplied to the group so the alerting is rebuilt
c) The agents on the test servers, set to hold their events instead of uploading them
d) 
The criteria the Management Server matches when it raises alerts, so the routine activity stops being alerted while the events go on being logged

02. During a deployment one administrator works in the web-based console on registration and configuration while a colleague uses the Java Console to create the policies the hosts will run. The first administrator asks whether the two of them are editing separate copies of the configuration.
What is the accurate answer?

a) 
Both consoles work against the same Management Server and the policy it stores centrally.
b) The Java Console holds what it creates until an administrator publishes it to the web console for storage.
c) The web console works against the Management Server, while the Java Console connects to each protected host in turn.
d) 
Each console keeps its own set of policies, which the Management Server merges the next time agents download.

03. A USB detection event is raised on a protected server. An investigator asks the administrator for the list of files that were copied to the drive while it was attached.
What should the administrator say?

a) The event carries that file activity, because the sensors that watch deletions also record what was written to the device
b) The Management Server assembles the list of files when it processes the alert raised from that event
c) The event records the device being attached and removed, not the files moved
d) The agent holds that detail on the host until an investigator asks the console for it

04. One service on a legacy server is reachable from outside the data center. The rest of the host runs work that has been stable for years, and the team does not want to disturb it while the exposed service is brought under control.
Which approach matches what prevention policies provide?

a) 
Have the management server intervene for that service, so nothing on the host itself changes.
b) Use a targeted prevention sandbox, so the controls bear on that service while the other programs go on as they are.
c) Put every program on the host into one stringent sandbox, since behavior controls are set for a host rather than for a program.
d) Constrain the service with a detection policy scoped to it, so its activity is refused on the host.

05. A general-purpose server carries several teams' tools, and the administrators add and remove utilities on it from week to week. The security team wants the operating system and the usual applications protected, without maintaining an inventory of every executable on the host.
Which strategy suits that server?

a) The Hardened strategy, whose coverage does not depend on listing each utility
b) Protected Whitelisting, since an unlisted utility can be added to the configuration whenever an administrator needs it
c) A policy with no strategy named, so that the agent applies the least restrictive controls
d) The Security Virtual Appliance, which needs no agent on the guests

06. A Windows prevention policy names a file and a registry key as resources that no program and no user may reach.
What does that mean for an administrator signed in locally on that host?

a) The administrator may reach the resource, since the rule governs programs rather than people
b) 
The administrator may reach it once the local rights on the resource are widened
c) The administrator is refused along with every other account
d) The administrator's access is recorded as an event rather than refused

07. A process on a protected server opens the running process of an unrelated business application and asks for write access to it. The request is refused before anything is written.
Which prevention control accounts for the refusal?

a) The file controls, since another running process is treated as a resource the policy names.
b) 
The process access control rules, which refuse one process write access to another.
c) The self protection rules, which cover the agent's own processes rather than processes generally.
d) Buffer overflow detection, which acts once code is running from somewhere it does not belong.

08. Two operators share a single console sign-in so that either of them can respond out of hours. A reviewer objects to the arrangement.
What does the product's user administration allow instead?

a) A single account whose role changes according to which operator has signed in.
b) One account for each protected host, so that actions are recorded against the host they concern.
c) A shared account limited by the prevention policy applied to the host the console runs on.
d) An account for each operator, carrying the role that operator needs.

09. An operator asks whether enabling the memory protections will also protect the files the application writes on the host.
What should the operator be told?

a) No, since they concern what happens inside a running process.
b) Yes, because they cover every resource the protected process touches.
c) Yes, for the files the process has open at the time, and not for the others.
d) No, and those files can only be watched by a sensor rather than protected.

10. A stringent prevention policy refuses changes to the resources it protects, and authorized updating still has to happen on those hosts.
Which two sandboxes are provided for that purpose?

(Select two)
a) 
Protected Whitelisting
b) Safe Privilege
c) SDCSS Updater
d) Fully Open
e) 
Trusted Updater

Answers:

Question: 01
Answer: d
Question: 02
Answer: a
Question: 03
Answer: c
Question: 04
Answer: b
Question: 05
Answer: a
Question: 06
Answer: c
Question: 07
Answer: b
Question: 08
Answer: d
Question: 09
Answer: a
Question: 10
Answer: c, e

Note: For any error in Symantec Data Center Security - Server Advanced 6.x Technical Specialist (250-611) certification exam sample questions, please update us by writing an email on feedback@certfun.com.

Rating: 5 / 5 (76 votes)