250-589 Sample Questions & Answers
Intercepting traffic and writing VPM policy carries the most weight, next to Edge SWG's caching design, managing encrypted sessions, pulling reports centrally, verifying who's connecting, filtering content, blocking threats, integrating with the cloud, and diagnostics.
Launch the full 250-589 simulator →Showing 10 of 20 free samples.
- Question 1Intermediate
Intercepting traffic and applying policy · Transparent Deployment Configuration
A hospital is deploying an Edge SWG in transparent mode to filter traffic for all devices on its network, including medical IoT devices that cannot be configured with explicit proxy settings. The primary goal is to prevent these devices from accessing known malicious command-and-control (C2) servers while allowing legitimate vendor update traffic. What is the most critical initial configuration step to ensure traffic is correctly intercepted?
Show answer & explanation
Correct answer: C
In a transparent deployment, client devices are unaware of the proxy. Therefore, traffic must be redirected to the Edge SWG at the network level. This is typically done using methods like Web Cache Communication Protocol (WCCP) or Policy Based Routing (PBR) on a router or Layer 3 switch that sits in the traffic path. This device is configured to identify web traffic and forward it to the proxy for inspection. Manually configuring routes on unmanageable IoT devices is not feasible, and installing SSL certificates is a step for decryption, not initial interception.
- Question 2Advanced
Intercepting traffic and applying policy · VPM Rule Evaluation Order
During a security audit, it was discovered that the research department is using unsanctioned cloud storage applications. An administrator is tasked with creating a policy to block access to all 'Cloud Storage' category websites, EXCEPT for the company-approved application, 'corp-storage.com'. What is the best practice for structuring the rules in the VPM Web Access Layer to achieve this?
Show answer & explanation
Correct answer: C
VPM policies are evaluated from top to bottom, and the first matching rule determines the outcome. To create an exception, the more specific 'Allow' rule must be placed before the broader 'Deny' rule. A rule allowing access to 'corp-storage.com' should be first. Any request for that site will match this rule and be allowed, and policy processing for that layer stops. All other requests for sites in the 'Cloud Storage' category will not match the first rule, fall through to the second rule, and be denied. Placing the Deny rule first would block all cloud storage, including the allowed site.
- Question 3Intermediate
Using built-in diagnostic tools on Edge SWG · Interpreting Health Checks
A system administrator is reviewing the health checks on an Edge SWG appliance and notices that the 'TCP-IP' health check is showing a 'critical' status. What does this status most likely indicate?
Show answer & explanation
Correct answer: C
The 'TCP-IP' health check specifically monitors the state of the networking stack, including the number of concurrent connections. A 'critical' status for this check typically means that the appliance is approaching or has reached its maximum configured limit for concurrent client connections. This indicates network pressure or a potential connection leak issue, but it is distinct from high CPU or memory usage, which are monitored by different health checks.
- Question 4Beginner
Using built-in diagnostic tools on Edge SWG · Sysinfo Files
What is the primary function of the
sysinfofile when troubleshooting an issue with an Edge SWG appliance?Show answer & explanation
Correct answer: C
The
sysinfofile is a critical diagnostic tool that generates a detailed, point-in-time report of the Edge SWG's entire state. This includes hardware status, SGOS version, licensing, network configuration, running configuration, performance statistics, and logs. It is the primary file requested by Symantec support for offline analysis of an appliance's health and configuration to diagnose complex issues. - Question 5Intermediate
Enhancing security with virus scanning · Content Analysis and ICAP for Data Loss Prevention
A company wants to prevent employees from uploading sensitive documents to any website categorized as 'Personal Storage' or 'Social Networking'. Which Symantec Web Protection component and protocol are primarily used to inspect the content of these uploads for policy enforcement?
Show answer & explanation
Correct answer: D
To inspect the content of file uploads (HTTP POST requests), the Edge SWG must forward the data to a device capable of deep content inspection. The Content Analysis appliance serves this role. The standard protocol for this communication is the Internet Content Adaptation Protocol (ICAP). A policy on the Edge SWG would trigger an ICAP request to Content Analysis for matching uploads, which would then scan the content and return a verdict.
- Question 6Advanced
Understanding SGOS architecture and caching on Edge SWG · Caching Optimization
An e-commerce company has deployed an Edge SWG cluster for performance and redundancy. An administrator observes that the web cache hit rate is lower than expected, leading to increased bandwidth usage and latency. Which SGOS feature should be configured to improve cache efficiency by storing a single copy of a resource that can be served to any client, regardless of minor variations in the request headers?
Show answer & explanation
Correct answer: D
Adaptive Caching is an SGOS feature specifically designed to improve cache hit rates for content served by modern web applications. It intelligently identifies and ignores insignificant variations in request headers (like cookies or user-agent strings) that would normally cause the proxy to store multiple, identical copies of an object. By normalizing these requests, it stores a single, 'generic' version of the object that can be served to multiple users, significantly increasing cache efficiency.
- Question 7Intermediate
Using built-in diagnostic tools on Edge SWG · Policy Tracing Analysis
A security analyst is using the policy trace tool on an Edge SWG to debug why a user is able to access a website that should be blocked. The trace output shows multiple layer evaluations. At which point in the trace does the final policy decision for the request get made?
Show answer & explanation
Correct answer: D
In Edge SWG policy evaluation, processing occurs layer by layer, and within each layer, rule by rule from top to bottom. When a request matches the criteria of a rule that has a terminating action (like Allow or Deny), the decision is made, and policy evaluation for that specific layer concludes. The policy trace will show this final decision for the layer, indicated by 'MATCH'. The key is that the first match with a terminating action within a layer determines the outcome for that layer.
- Question 8Advanced
Providing security and web usage policies based on role or group · Conditional Authentication
A company is migrating from a legacy proxy solution to Edge SWG and wants to replicate a specific authentication behavior. They need to authenticate users transparently for on-premise users via IWA, but present a captive portal login page for guest wireless users who are on a separate VLAN. Which Edge SWG feature allows for this type of conditional authentication policy?
Show answer & explanation
Correct answer: B
The Visual Policy Manager (VPM) allows for highly granular control over authentication. By creating a Web Authentication Layer, an administrator can define rules based on various criteria, including the source IP subnet. Two rules can be created: the first rule would match the guest VLAN subnet and trigger an action to authenticate using a captive portal (form-based) realm. The second rule would match the corporate subnet and trigger authentication using the IWA realm. This allows the Edge SWG to apply different authentication schemes based on the user's network location.
- Question 9IntermediateSelect 3
Reporting for Edge SWG features · Reporter Integration
When configuring an Edge SWG appliance to forward its access logs to a Symantec Reporter appliance, which THREE of the following settings must be configured correctly? (Select THREE)
Show answer & explanation
Correct answers: A, C, E
For successful integration, three key steps are required: 1) The Edge SWG must be configured with the IP address and port of the Reporter as a destination for the logs. 2) The log format used by the Edge SWG (e.g.,
bcreportermain_v1) must be recognized by the Reporter for correct parsing. 3) A client protocol (like FTP or HTTP) must be configured on the Edge SWG to periodically upload the log files to the Reporter appliance. A Log Facility is a Splunk term, and while secure logging is an option, it is not a mandatory requirement for basic functionality. - Question 10Beginner
Applying security and web usage policy to encrypted traffic · VPM SSL Access Layer
What is the primary purpose of the 'SSL Access Layer' in the Visual Policy Manager?
Show answer & explanation
Correct answer: C
The SSL Access Layer is processed very early during the SSL handshake (after the Client Hello). At this stage, the Edge SWG has limited information, such as the destination IP and the Server Name Indication (SNI) from the client. Its primary purpose is to make a high-level decision on the connection itself—whether to intercept it for later inspection, tunnel it without inspection (bypass), or drop it entirely. It acts as a gatekeeper for encrypted connections before the more detailed Web Access Layer policies are applied.
Ready for the real thing?
The full 250-589 simulator has every exam-style question, timed mode, and instant scoring.