Broadcom VIP Technical Specialist (250-420) Certification Sample Questions

Broadcom 250-420 VCE, VIP Technical Specialist Dumps, 250-420 PDF, 250-420 Dumps, VIP Technical Specialist VCE, Broadcom VIP Technical Specialist PDFGetting knowledge of the Broadcom 250-420 exam structure and question format is vital in preparing for the Symantec VIP Technical Specialist certification exam. Our Broadcom VIP Technical Specialist sample questions offer you information regarding the question types and level of difficulty you will face in the real exam. The benefit of using these Broadcom 250-420 sample questions is that you will get to check your preparation level or enhance your knowledge by learning the unknown questions. You will also get a clear idea of the exam environment and exam pattern you will face in the actual exam with the Symantec VIP Technical Specialist Sample Practice Test. Therefore, solve the Broadcom VIP Technical Specialist sample questions to stay one step forward in grabbing the Broadcom Symantec VIP Technical Specialist credential.

These Broadcom 250-420 sample questions are simple and basic questions similar to the actual Broadcom VIP Technical Specialist questions. If you want to evaluate your preparation level, we suggest taking our Symantec VIP Technical Specialist Premium Practice Test. You might face difficulties while solving the real-exam-like questions. But, you can work hard and build your confidence on the syllabus topics through unlimited practice attempts.

Broadcom 250-420 Sample Questions:

01. After a VPN is moved to strong authentication, most users are prompted for a second piece of evidence, but one group consistently connects on the password alone. No risk-based policy is in use, and that group's registered devices are unchanged.
Which explanation fits what is observed?

a) The shared secret between the two services no longer matches for that group.
b) The VPN client is reusing an earlier successful session for those users.
c) Those connections are still being decided by the VPN itself rather than forwarded, so nothing ever asks for the second factor.
d) Those users connect from locations the service already treats as familiar.

02. A policy requires a second factor for staff connecting from outside the office, but not for staff already working on the internal network.
Where should that distinction be enforced?

a) At the device terminating the remote connection, which is the only point that knows the session came from outside
b) On the user's own machine, by demanding the second factor whenever the remote-access client is launched
c) At each internal application, since the applications hold the records the policy was written to protect
d) In the directory, by holding two separate credential records for each user and choosing between them at the moment of sign-in

03. Two applications ask for the same second factor. In the first, the sign-in page presents the prompt and moves on to the requested page once it is satisfied. In the second, the server returns nothing at all until it has evaluated the evidence itself.
Which arrangement can a determined user get past?

a) The second, because a server that decides for itself has to reveal the address of the protected page before it can evaluate anything
b) The first, since the check runs where the user is in control and the page can be requested directly
c) Both equally, as the strength of either arrangement rests on the method chosen rather than on anything about the flow
d) Neither, since both ask for the same evidence and a user who cannot produce it is turned away in either case

04. A user reports that the credential registered to her account has stopped being accepted. Separately, the service desk finds a pending request in her name to register a replacement credential. The user says she made no such request.
What do the two events together indicate, and what stops it?

a) Her password has been exposed, and forcing a password change is what closes that exposure.
b) Her credential has fallen out of step with the service, and the replacement request is a coincidence that resynchronizing the credential makes unnecessary.
c) An attacker is attempting to sign in as her, and locking the account until she can be reached is what denies them the attempt.
d) An attacker is working on the replacement step rather than the sign-in step, so the pending registration is what has to be halted.

05. Support staff sign in dozens of times a shift, and the security team wants stronger authentication without slowing routine work. Two proposals are on the table: prompt everyone for a second factor on every sign-in, or prompt only when a request looks unusual.
What is the strongest argument for the second proposal?

a) The contextual signals themselves count as the additional factor, so no separate credential is needed for the stronger check
b) Routine sign-ins are exempted from the policy
c) Extra evidence is demanded when the risk of the request rises, rather than uniformly
d) Unusual requests are blocked outright

06. A deployment plan describes the stages a strong-authentication credential passes through.
Which sequence is correct?

a) A credential is issued and then remains valid indefinitely, with revocation applying to the account rather than to the credential.
b) A credential is issued, registered to one user, used, then revoked when the need ends.
c) A credential is registered to a user first and is issued only once that registration has been used successfully.
d) A credential is issued to a group and bound to whichever member presents it first, then revoked when the group is dissolved.

07. An attacker obtains the token that identifies a user's already-established session with a web application and replays it from their own browser.
What does the strength of the original sign-in contribute in that situation?

a) It blocks the replay, because the application re-checks the second factor against that token on every request
b) It limits the damage, because a session opened with two factors ends as soon as it appears in a new browser
c) It prevents reuse, because the token is not accepted unless the credential that produced the second factor is present
d) Nothing, because the token is honored after the authentication decision has already been made

08. A Symantec VIP rollout includes written guidance for users about the new sign-in process.
Which instruction is the most important one to communicate?

a) Keep the registered credential with a colleague when you are away, so urgent work is never blocked
b) Record the codes you receive so that a support agent can confirm them if a sign-in has to be repeated
c) Refuse and report any authentication prompt that arrives when you were not signing in, because it means someone else is trying
d) Approve any pending prompt promptly so that the request does not expire and force the whole sign-in sequence to be started again from the beginning

09. Users are told to refuse any authentication request they did not start themselves. Several routine business processes in the same organization legitimately produce requests that users did not start.
Which side of that conflict has to change, and why?

a) The processes: the legitimate exceptions have to be removed so that an unexpected request is always somebody else's attempt.
b) Neither: an announcement sent before each legitimate process runs lets users expect those requests and refuse everything else that arrives.
c) The guidance: users should be taught to judge which unexpected requests are legitimate, from the system involved and the hour at which they arrive.
d) Neither: an unanswered request should be left to lapse on its own, so anything a user did not start expires before it can be acted on.

10. A time-based code generator and the service that validates the code each derive the current value from a clock. Because the two clocks can drift apart, the verifier also accepts values from periods either side of the current one.
What does widening that acceptance range trade away?

a) It forgives more clock error, and it removes the need to pair the code with a password when the user signs in
b) It forgives more clock error, and it lengthens the period in which a captured code is still spendable
c) It forgives more clock error, and it moves the credential out of the possession category
d) It forgives more clock error, and it protects the code against an attacker relaying it in real time

Answers:

Question: 01
Answer: c
Question: 02
Answer: a
Question: 03
Answer: b
Question: 04
Answer: d
Question: 05
Answer: c
Question: 06
Answer: b
Question: 07
Answer: d
Question: 08
Answer: c
Question: 09
Answer: a
Question: 10
Answer: b

Note: For any error in Symantec VIP Technical Specialist (250-420) certification exam sample questions, please update us by writing an email on feedback@certfun.com.

Rating: 5 / 5 (75 votes)