Symantec 250-587 Exam Overview:
| Certification Vendor: | Broadcom (Symantec) |
| Exam Name: | Symantec Data Loss Prevention 16.x Administration Technical Specialist |
| Exam Number: | 250-587 |
| Exam Format: | Multiple choice |
| Available Languages: | English |
| Sample Questions: | Symantec 250-587 Sample Questions |
| Exam Way: | Proctored exam (online or authorized testing center depending on region) |
| Pre Condition: | Recommended experience with Symantec (Broadcom) Data Loss Prevention 16.x administration and enterprise security concepts |
Symantec 250-587 Exam Syllabus Topics:
| Section | Objectives |
|---|---|
| Topic 1: Monitoring and Reporting | - System monitoring and alerts - Report generation and analysis |
| Topic 2: System Maintenance and Troubleshooting | - Troubleshooting common issues - Performance tuning and optimization |
| Topic 3: Policy Management | - Data identification and classification rules - Creating and managing DLP policies |
| Topic 4: Incident Management and Response | - Incident detection and workflow - Incident review and remediation |
| Topic 5: Installation and Configuration | - Deployment planning and prerequisites - Initial system setup and configuration |
| Topic 6: Symantec DLP Architecture and Components | - System architecture overview - Detection and enforcement components |
Symantec Data Loss Prevention 16.x Administration Technical Specialist Sample Questions:
1. When managing an Endpoint Discover scan, a DLP administrator notices some endpoint computers are NOT completing their scans.
When does the DLP agent stop scanning?
A) When the endpoint computer is rebooted and the agent is started
B) When the agent is unable to send a status report within the "Scan Idle Timeout" period
C) When the agent sends a report immediately after the "Scan Idle Timeout" period
D) When the agent sends a report within the "Scan Idle Timeout" period
2. A DLP administrator is preparing to install Symantec DLP and has been asked to use an Oracle database provided by the Database Administration team.
Which SQL *Plus command should the administrator utilize to determine if the database is using a supported version of Oracle?
A) select * from db$version;
B) select database version from < database name > ;
C) select db$ver from < database name > ;
D) select * from v$version;
3. Refer to the exhibit.
What activity should occur during the baseline phase, according to the risk reduction model?
A) Monitor incidents and tune the policy to reduce false positives
B) Define and build the incident response team
C) Test policies to ensure that blocking actions minimize business process disruptions
D) Establish business metrics and begin sending reports to business unit stakeholders
4. What should an administrator do if DLP policies are generating too many false positives?
A) Allow users to approve exceptions manually.
B) Disable all policies temporarily.
C) Refine detection methods, such as Exact Data Matching (EDM) and fingerprinting.
D) Ignore incident reports until a critical issue arises.
5. Which detection server is available from Symantec as a hardware appliance?
A) Network Prevent for Web
B) Network Discover
C) Network Monitor
D) Network Prevent for Email
Solutions:
| Question # 1 Answer: B | Question # 2 Answer: D | Question # 3 Answer: D | Question # 4 Answer: C | Question # 5 Answer: A |
We're so confident of our products that we provide no hassle product exchange.


By Lee

