250-580 Sample Questions

250-580 Sample Questions & Answers

Setting security policies and exceptions carries the most weight, next to an overview of the product offering, installing agents under cloud or hybrid management, endpoint detection and response, reporting and analytics, and ongoing maintenance and troubleshooting.

Launch the full 250-580 simulator →

Showing 10 of 20 free samples.

  1. Question 1Advanced

    Policy Configuration and Management · Exceptions and Exclusions

    A hospital is using SES Complete to protect workstations that are frequently moved between wards. They are experiencing performance issues with a critical medical imaging application that writes large temporary files to C:\Temp\ImagingData\. A previous administrator created a folder exception for this path in the Antivirus and Spyware Protection policy. Despite this, SONAR continues to generate detections on the application's processes when they access this directory. Why are the SONAR detections still occurring?

    Show answer & explanation

    Correct answer: C

    This is a critical distinction. SONAR monitors process behavior in real-time (API calls, memory access, etc.), not just files at rest. Standard file/folder exceptions are designed for file-based scanning engines. To prevent SONAR from flagging a legitimate application's behavior, a separate SONAR-specific exception (e.g., by application path or hash) must be created in the Exceptions policy.

  2. Question 2Intermediate

    Maintenance and Troubleshooting · Client Communication

    An administrator is reviewing the sylink.log file on a client that is failing to communicate with its SEPM. The log contains repeated entries of HTTP 407 Proxy Authentication Required. The client is configured with the correct proxy settings in its communication policy. What is the most likely cause of this error?

    Show answer & explanation

    Correct answer: B

    The Symantec agent (sylink) runs under the local SYSTEM account. If the proxy server requires user-based authentication (e.g., domain credentials), the SYSTEM account will not have them, leading to an authentication failure (HTTP 407). The proxy credentials specified in the policy are often user-context specific and not available to the SYSTEM account. The solution is often to use a proxy that allows authentication based on machine account or IP address, or to configure proxy bypass for SEPM traffic.

  3. Question 3Intermediate

    Threat Detection and Response · Threat Hunting

    A security analyst needs to create a custom EDR query to hunt for evidence of a specific MITRE ATT&CK technique: T1059.001, PowerShell. The goal is to find any PowerShell command that contains the string IEX (New-Object Net.WebClient).DownloadString. Which search query syntax should be used in the ICDm console's threat hunting interface?

    Show answer & explanation

    Correct answer: B

    The ICDm threat hunting query language uses a Lucene-like syntax. The correct format specifies the field (process.name), a colon, and the value (powershell.exe). The AND operator links conditions. For the command line, wildcards (*) are used to match the contained substrings effectively. The other options use incorrect operators (=, CONTAINS) or syntax for this specific interface.

  4. Question 4Advanced

    Policy Configuration and Management · Device Control Policy

    An administrator wants to prevent users from copying sensitive data to any USB storage devices, but must allow specific, company-issued encrypted USB drives to function normally. They also need to allow HID devices like keyboards and mice. What is the most precise way to configure this in the Device Control policy?

    Show answer & explanation

    Correct answer: C

    This is the correct, layered approach. First, you block the entire class of devices you want to control ('USB Mass Storage Devices'), which is more efficient than blocking the generic 'USB' class. Then, you add specific, granular exclusions for the hardware you want to permit. Using the unique Device ID (or Hardware ID) for each company-issued encrypted drive ensures only those specific devices are allowed, fulfilling the security requirement precisely.

  5. Question 5Beginner

    Installation and Deployment · Agent Installation Troubleshooting

    What is the primary function of the sesinstaller.log file during the installation of the Symantec Agent on a Windows endpoint?

    Show answer & explanation

    Correct answer: C

    The sesinstaller.log is the primary troubleshooting tool for failed agent installations. It captures each action performed by the installer, from system checks and file copying to registry modifications and service creation. Any errors that cause the installation to fail or roll back will be recorded in this file, making it essential for diagnostics.

  6. Question 6IntermediateSelect 2

    Reporting and Monitoring · SIEM Integration

    A financial services company has a strict security policy that requires all endpoint security events to be forwarded to their central SIEM platform for correlation and long-term retention. An administrator needs to configure SES Complete to send detailed event data to the SIEM. Which two methods are supported for this integration? (Select TWO).

    Show answer & explanation

    Correct answers: B, D

    The Integrated Cyber Defense Manager (ICDm) cloud console has a built-in feature to forward security events to an external Syslog server, which is a standard ingestion method for most SIEM platforms.

    SES Complete provides a robust REST API that allows for programmatic access to event data. A SIEM platform can use its API connector to periodically poll for and ingest new events, providing a flexible and powerful integration method.

  7. Question 7Intermediate

    Policy Configuration and Management · Firewall Policy

    An organization's security policy states that all firewall rules should follow the principle of least privilege. An administrator needs to create a firewall rule to allow a specific application, billing.exe, to communicate with a database server at 10.10.5.25 on TCP port 1433. Which is the MOST securely configured rule?

    Show answer & explanation

    Correct answer: D

    This rule is the most specific and adheres to the principle of least privilege. It restricts the communication by application (billing.exe), protocol (TCP), direction (outbound), destination host (10.10.5.25), and destination port (1433). The other options are overly permissive and create unnecessary security risks.

  8. Question 8Intermediate

    Reporting and Monitoring · Compliance Reporting

    A company is preparing for an audit and must demonstrate that all endpoints are compliant with a custom Host Integrity policy. The policy requires that a specific registry key exists. An administrator needs to generate a report showing only the endpoints that are currently failing this specific Host Integrity check. How can this be accomplished in the ICDm console?

    Show answer & explanation

    Correct answer: B

    The 'Computer Status' report is the correct tool for this task. It provides detailed information about the state of clients, including their compliance status. By filtering this report to show only 'Non-compliant' computers and focusing on Host Integrity failures, the administrator can generate the precise list required for the audit.

  9. Question 9Intermediate

    Policy Configuration and Management · System Lockdown

    True or False: The System Lockdown feature, when configured in whitelist mode, blocks all unapproved applications from running, including operating system updates and patches, unless they are explicitly defined in the file fingerprint list.

    Show answer & explanation

    Correct answer: A

    True. System Lockdown in whitelist mode is extremely strict. It works from a list of known-good application file fingerprints (hashes). Any executable that is not on this list is blocked from running. This includes legitimate OS patches and software updates. Administrators must carefully manage the fingerprint list, updating it before deploying any system or application updates to avoid disruption.

  10. Question 10Intermediate

    Threat Detection and Response · Antimalware and Threat Protection

    A new malware variant is discovered that uses a fileless technique by injecting malicious code directly into the memory space of lsass.exe. Which SES Complete protection technology is specifically designed to detect and block this type of threat?

    Show answer & explanation

    Correct answer: C

    Memory Exploit Mitigation (MEM) is purpose-built to counter memory-based, fileless attacks. It monitors legitimate applications for exploit-like behavior (such as ROP attacks, stack pivots, and heap sprays) and terminates the process before it can be compromised. Injecting code into a critical system process like lsass.exe is a classic technique that MEM is designed to prevent.

Ready for the real thing?

The full 250-580 simulator has every exam-style question, timed mode, and instant scoring.