Summer Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: dcdisc65

Page: 1 / 3
Total 28 questions
Exam Code: 250-441                Update: Oct 15, 2025
Exam Name: Administration of Symantec Advanced Threat Protection 3.0

Symantec Administration of Symantec Advanced Threat Protection 3.0 250-441 Exam Dumps: Updated Questions & Answers (October 2025)

Question # 1

During a recent virus outbreak, an Incident Responder found that the Incident Response team was successful in identifying malicious domains that were communicating with the infected endpoints.

Which two options should the Incident Responder select to prevent endpoints from communicating with malicious domains? (Select two.)

A.

Use the isolate command in ATP to move all endpoints to a quarantine network.

B.

Blacklist suspicious domains in the ATP manager.

C.

Deploy a High-Security Antivirus and Antispyware policy in the Symantec Endpoint Protection Manager (SEPM).

D.

Create a firewall rule in the Symantec Endpoint Protection Manager (SEPM) or perimeter firewall that blocks traffic to the domain.

E.

Run a full system scan on all endpoints.

Question # 2

Why is it important for an Incident Responder to copy malicious files to the ATP file store or create an image of the infected system during the Recovery phase?

A.

To have a copy of the file policy enforcement

B.

To test the effectiveness of the current assigned policy settings in the Symantec Endpoint Protection Manager (SEPM)

C.

To create custom IPS signatures

D.

To document and preserve any pieces of evidence associated with the incident

Question # 3

Which two database attributes are needed to create a Microsoft SQL SEP database connection? (Choose

two.)

A.

Database version

B.

Database IP address

C.

Database domain name

D.

Database hostname

E.

Database name

Question # 4

An Incident Responder is going to run an indicators of compromise (IOC) search on the endpoints and wants

to use operators in the expression.

Which tokens accept one or more of the available operators when building an expression?

A.

All tokens

B.

Domainname, Filename, and Filehash

C.

Filename, Filehash, and Registry

D.

Domainname and Filename only

Question # 5

An Incident Responder notices traffic going from an endpoint to an IRC channel. The endpoint is listed in an

incident. ATP is configured in TAP mode.

What should the Incident Responder do to stop the traffic to the IRC channel?

A.

Isolate the endpoint with a Quarantine Firewall policy

B.

Blacklist the IRC channel IP

C.

Blacklist the endpoint IP

D.

Isolate the endpoint with an application control policy

Question # 6

Which action should an Incident Responder take to remediate false positives, according to Symantec best

practices?

A.

Blacklist

B.

Whitelist

C.

Delete file

D.

Submit file to Cynic

Question # 7

Why is it important for an Incident Responder to analyze an incident during the Recovery phase?

A.

To determine the best plan of action for cleaning up the infection

B.

To isolate infected computers on the network and remediate the threat

C.

To gather threat artifacts and review the malicious code in a sandbox environment

D.

To access the current security plan, adjust where needed, and provide reference materials in the event of a similar incident

Question # 8

What is the minimum amount of RAM required for a virtual deployment of the ATP Manager in a production environment?

A.

48 GB

B.

64 GB

C.

16 GB

D.

32GB

Question # 9

Which stage of an Advanced Persistent Threat (APT) attack do attackers map an organization’s defenses from the inside?

A.

Discovery

B.

Capture

C.

Exfiltration

D.

Incursion

Question # 10

How does an attacker use a zero-day vulnerability during the Incursion phase?

A.

To perform a SQL injection on an internal server

B.

To extract sensitive information from the target

C.

To perform network discovery on the target

D.

To deliver malicious code that breaches the target

Page: 1 / 3
Total 28 questions

Most Popular Certification Exams

Payment

       

Contact us

dumpscollection live chat

Site Secure

mcafee secure

TESTED 16 Oct 2025