Free Symantec 250-580 Practice Test & Real Exam Questions

  • Exam Code/Number: 250-580
  • Exam Name/Title: Endpoint Security Complete - Administration R2
  • Certification Provider: Symantec
  • Corresponding Certification: Endpoint Security
  • Exam Questions: 152
  • Updated On: Oct 06, 2026
Which SEP feature is required for using the SEDR Isolate function?
Correct Answer: D Vote an answer
Explanation: Only visible for Pass4Leader members. You can sign-up / login (it's free).
What EDR feature provides endpoint activity recorder data for a file hash?
Correct Answer: B Vote an answer
Explanation: Only visible for Pass4Leader members. You can sign-up / login (it's free).
A file has been identified as malicious.
Which feature of SEDR allows an administrator to manually block a specific file hash?
Correct Answer: A Vote an answer
Explanation: Only visible for Pass4Leader members. You can sign-up / login (it's free).
Which Incident View widget shows the parent-child relationship of related security events?
Correct Answer: D Vote an answer
Explanation: Only visible for Pass4Leader members. You can sign-up / login (it's free).
What are the two (2) locations where an Incident Responder should gather data for an After Actions Report in SEDR? (Select two)
Correct Answer: A,D Vote an answer
Explanation: Only visible for Pass4Leader members. You can sign-up / login (it's free).
Which security threat stage seeks to gather valuable data and upload it to a compromised system?
Correct Answer: D Vote an answer
Explanation: Only visible for Pass4Leader members. You can sign-up / login (it's free).
What must be entered before downloading a file from ICDm?
Correct Answer: C Vote an answer
Explanation: Only visible for Pass4Leader members. You can sign-up / login (it's free).
Files are blocked by hash in the deny list policy. Which algorithm is supported, in addition to MD5?
Correct Answer: D Vote an answer
Explanation: Only visible for Pass4Leader members. You can sign-up / login (it's free).
Which Firewall rule components should an administrator configure to blockfacebook.comuse during business hours?
Correct Answer: C Vote an answer
Explanation: Only visible for Pass4Leader members. You can sign-up / login (it's free).
Why is it important for an Incident Responder to review Related Incidents and Events when analyzing an incident for an After Actions Report?
Correct Answer: D Vote an answer
Explanation: Only visible for Pass4Leader members. You can sign-up / login (it's free).
The Behavioral Heat Map indicates that a specific application and a specific behavior are never used together.
What action can be safely set for the application behavior in a Behavioral Isolation policy?
Correct Answer: B Vote an answer
Explanation: Only visible for Pass4Leader members. You can sign-up / login (it's free).
What type of policy provides a second layer of defense, after the Symantec firewall?
Correct Answer: D Vote an answer
Explanation: Only visible for Pass4Leader members. You can sign-up / login (it's free).
Which type of communication is blocked, when isolating the endpoint by clicking on the isolate button in SEDR?
Correct Answer: C Vote an answer
Explanation: Only visible for Pass4Leader members. You can sign-up / login (it's free).
What protection technology should an administrator enable to prevent double executable file names of ransomware variants like Cryptolocker from running?
Correct Answer: C Vote an answer
Explanation: Only visible for Pass4Leader members. You can sign-up / login (it's free).