Browse all practice questions for the Symantec Data Loss Prevention (DLP) Practice Test. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

Symantec Data Loss Prevention (DLP) Practice Test course image
All questions

These questions are part of the practice quiz. Start practicing

  • What are lexicons in DLP used for?
  • Which of the following is a common source of data leakage when the main actor is a well-meaning insider?
  • Which report should a compliance officer generate to understand how the company is complying with data security policies over time?
  • When testing Network Prevent for Web functionality, no incidents are reported for a small file posted to a cloud storage website. What should you modify to allow incidents to be generated?
  • In the data in motion flow, which component appears after CloudSOC?
  • What types of data-in-use controls does Endpoint DLP provide to prevent data leakage through devices?
  • Which action is available for use in both Smart Response and Automated Response rules?
  • What is the correct BoxMonitor.Channels configuration that will allow the server to start as a Network Monitor server?
  • What are best practices for data retention and disposal policies within DLP?
  • What is a common remediation action for protecting data exposure in DLP?
  • Which two detection technology options ONLY run on a detection server? (Choose two)
  • What capability does IDM provide in DLP?
  • Which utility is used to create certificates for the detection servers?
  • In a two-tier deployment, where should the Oracle database and Enforce server be installed?
  • What is centralized in the Management Server to enable unified remediation and reporting across DLP components?
  • What detection method utilizes Data Identifiers?
  • What is the correct action to take to enable Network Discover in the Enforce deployment when only certain server types are visible?
  • What factors should be considered when protecting data in cloud apps with DLP?
  • Why would an administrator set the Similarity Threshold to zero when testing and tuning a Vector Learning Machine profile?
  • A DLP policy can enforce across which channels?
  • How should an administrator log in to Enforce with the sysadmin role when using Active Directory authentication?
  • What configuration change is most likely required to produce data in User Risk Summary reports?
  • To secure communications between an on-prem Enforce server and cloud detection servers, which action should you take?
  • Name three PCI DSS data patterns that DLP can detect and a suitable detection approach.
  • Which component can perform a file system scan of a workstation besides the DLP Agent?
  • Which of the following lists best describes how Unicode content should be handled in DLP detections?
  • What is the correct order for data in motion when a customer has integrated their CloudSOC and DLP solutions?
  • What are common maintenance activities for a Symantec DLP rollout to ensure ongoing effectiveness?
  • How can DLP policy scope be aligned with business units and organizational units?
  • Which detection method depends on training sets?
  • Where should an administrator set the debug levels for an Endpoint Agent?
  • To exclude a specific executable from Application File Access Control monitoring, which action is required?
  • Compare continuous monitoring vs point-in-time scanning in DLP.
  • Which statement about detection methods is true?
  • How should a DLP administrator exclude a custom endpoint application named custom_app.exe from being monitored by Application File Access Control?
  • Which virtual appliance is available for Web detection?
  • Only IDC files larger than 1MB become BAD files; what is the most likely root cause?
  • If approved endpoint exceptions do not prevent data transfers as expected, what is the first action to take?
  • Which regex pattern can detect a U.S.-style email address?
  • Which folder on the Enforce server stores incident files?
  • Which tool must be run to certify the database prior to upgrading DLP?
  • Which statement is true about the relationship between IDC and BAD files in the incident folder?
  • What is data at rest and how does DLP enforce protection?
  • Which statement about DLP policy exceptions is true?
  • Why is tuning threshold and rule scope important in DLP, and what strategies help?
  • Which component is deployed on endpoints to enable data scanning under DLP?
  • Which elements are commonly stored in a central DLP database?
  • Which SQL*Plus command should you use to determine if the Oracle database is using a supported version for installation?
  • Which server target uses the Automated Incident Remediation Tracking feature?
  • Which of the following is a remediation action available in Symantec DLP?
  • During the baseline phase in the risk reduction model, what should you establish and begin doing?
  • Which service is responsible for persisting detected incidents on the Enforce server?
  • Which statement correctly distinguishes data masking from redaction in DLP remediation actions?
  • In a DLP governance model, which role is primarily responsible for defining data loss prevention rules?
  • Which detection server is used for Network Discover, Network Protect, and Cloud Storage?
  • What is the primary role of an Auditor in a DLP program?
  • A DLP administrator needs to remove an agents associated events from an Endpoint server. Which Agent Task should the administrator perform to disable the agent's visibility in the Enforce management console?
  • What is the role of data classification in DLP policies?
  • How does DLP integrate with web proxies or gateways for web channel protection?
  • What condition caused all processes to be missing from the Server Detail page display in a DLP environment?
  • Setting the Similarity Threshold to zero reveals which aspect during testing?
  • Which of the following is a reason to manually configure the endpoint location to specify an IP address or range?
  • What is the correct installation sequence for Oracle Database, Enforce Server, Solution Pack, and Detection Server?
  • What is required on the Enforce server to communicate with the Symantec DLP database?
  • Which two Network Discover/Cloud Storage targets apply Information Centric Encryption as policy response rules? (Choose two)
  • What action typically triggers remediation in a DLP workflow?
  • What mechanism enables applying different DLP rules per unit with overrides?
  • What is the concept of legal hold in relation to DLP incidents?
  • How can DLP interact with content repositories like SharePoint or OneDrive?
  • What are the main components of a DLP policy and their roles?
  • Which virtual appliance is available for Email detection?
  • What is the purpose of distributing the grid scan workload across multiple detection servers?
  • What should an incident responder select in the Enforce management console to remediate multiple incidents simultaneously?
  • Which Network Prevent action takes place when the Network Incident list shows the message is 'Modified'?
  • Endpoint Discover scanning stops when the DLP agent cannot send a status report within what period?
  • In policies that include Exact Data Matching, which action is performed by Endpoint Prevent?
  • Which of the following is NOT typically found in DLP dashboards for executives and security teams?
  • What is the purpose of testing a DLP policy?
  • Which option correctly describes the two-tier installation type for Symantec DLP?
  • What is the default fallback option for the Endpoint Prevent Encrypt response rule?
  • If the uninstall password for the DLP 15.0 Endpoint agent is forgotten, what is the recommended workaround?
  • Why is it important for an administrator to utilize the grid scan feature?
  • What is the proper order of the six stages in the Symantec Data Loss risk reduction approach?
  • What is the effect of cross-channel alerts in a DLP system?
  • Explain content fingerprinting in DLP and when you would use it.
  • What are recommended steps when staging a DLP deployment to production?
  • Which of the following is typically included in DLP dashboards for executives and security teams?
  • How should a DLP administrator change a policy so that it retains the original file when an endpoint incident has detected a copy to USB device operation?
  • Which detection server type requires a minimum of two physical network interface cards?
  • Which mechanism enables a unified view across network, endpoint, and cloud DLP by sharing components?
  • The CISO has attempted to generate a User Risk Summary report, but it is blank despite User Reporting privileges. What is the probable reason?
  • How do you enforce DLP for cloud apps like Office 365 or Google Workspace?
  • To restrict copying files only to a specific set of organization-owned USB drives, which detection method should be used?
  • Which channel does Endpoint Prevent protect using Device Control?
  • Which product is able to replace a confidential document residing on a file share with a marker file explaining why the document was removed?
  • Which file size threshold triggers conversion of IDC files to BAD?
  • How should you manage and update lexicons to maintain accuracy?
  • Which of the following pairs of providers are supported for hosting Cloud Prevent for Office 365? (Choose Two)
  • What is a policy pack in DLP and how is it used?
  • A customer needs to integrate information from DLP incidents into external Governance, Risk and Compliance dashboards. Which feature should a third party component integrate with to provide dynamic reporting, create custom incident remediation processes, or support business processes?
  • Which detection server is available from Symantec as a hardware appliance?
  • Which statement best contrasts data discovery with DLP?
  • Which statement best describes how fingerprints and regex differ in DLP detection?
  • In the Enforce management console, detection servers show 'unknown'. Which service on the Enforce server should be started to bring them to a running state?
  • Which statement about ticketing system integrations in DLP incident management is most accurate?
  • Which sequence best represents a typical DLP incident lifecycle?
  • In the data in motion flow, which component comes immediately after User when CloudSOC is integrated?
  • Which statement best describes the use of policy packs in deployment to groups or environments?
  • Which capability should a third-party system integrate with to receive DLP incident data and drive custom workflows?
  • What detection technology supports partial contents matching?
  • What does ICE stand for in Symantec DLP?
  • Which two technologies should an organization utilize for integration with the Network Prevent products? (Choose two)
  • How does DLP handle data at rest within file servers and endpoints?
  • How should GDPR data subjects' rights requests be reflected in DLP workflows?
  • What is Application Detection Configuration?
  • A Network Monitor detection server shows as Running Selected, but its event logs show that the packet capture and file reader processes are crashing. What is a possible cause?
  • Where in the Enforce management console can a DLP administrator change the 'UI.NO_SCAN.int' setting to disable the 'Inspecting data' pop-up?
  • How would you describe DLP enforcement at web gateways?
  • In privacy-by-design, what principle focuses on restricting access to the minimum necessary to perform duties?
  • What does IDM stand for in Symantec DLP?
  • What is data tokenization and when would you use it in DLP?
  • What is the role of ticketing systems in DLP incident management, and which integrations are common?
  • Which components can perform a file system scan of a workstation?
  • During the baseline phase, what is the expected outcome related to metrics and reporting?
  • Which of the following is a reason to manually configure the endpoint location by domain names?
  • What is the purpose of content fingerprinting in DLP, in practical terms?
  • In the recommended Windows Enforce stop order, which service is stopped second?
  • How do you manage and update detection orders and priority when multiple rules trigger simultaneously?
  • What is the role of cloud DLP connectors in enforcement?
  • In the DLP incident lifecycle, what is the primary purpose of the evidence collection step?
  • What is a primary reason to prepare a rollback plan when staging a DLP deployment to production?
  • Which of the following is a valid location where Symantec DLP can scan and apply Information Centric Encryption actions?
  • Which are the primary deployment options for Symantec DLP?
  • Which endpoint response rule would block an action on the endpoint?
  • An Endpoint agent fails to receive a new configuration. What is one possible reason for this failure?
  • Where must OCR components be installed?
  • To exclude standard boilerplate text from IDM detection, which file should be created before creating the IDM profile?
  • What is a data identifier in DLP and how is it used to classify content?
  • Which detection technology supports partial row matching?
  • A company needs to implement Data Owner Exception so that incidents are avoided when employees send or receive their own personal information. What detection method should the company use?
  • Which detection method helps avoid incidents involving employees' own personal information?
  • Which port is used for Cloud Detection Service communications with the Enforce server?
  • Which two DLP products support the new OCR engine in Symantec DLP 15.0?
  • How does privacy-by-design relate to DLP policy development?
  • Which notification option is documented as a method for alerting after a policy match?
  • How does Symantec DLP integrate with email servers to enforce data protection?
  • What does data in motion refer to in DLP, and how does Symantec DLP protect it?
  • A software company wants to protect its source code, including new source code created between scheduled indexing runs. Which detection method should the company use to meet this requirement?
  • When protecting data in cloud apps with DLP, why is user behavior a factor?
  • Which tools support testing a DLP policy?
  • Where in the Enforce management console is the status of a Network Monitor detection server displayed as Running Selected?
  • Which aspects are included in a DLP policy for testing/validation and incident handling?
  • In policies that include Exact Data Matching, which action is performed by Endpoint Discover?
  • How is DLP data stored in its database and what performance considerations exist?
  • Where is the Advanced Process Control setting located in the DLP console?
  • How does data classification integrate with DLP policies and why is it important?
  • Before deploying a DLP policy, which practice helps ensure changes are safe?
  • Which items are typically included in DLP audit trails and evidence for compliance?
  • What is the Symantec recommended order for stopping Symantec DLP services on a Windows Enforce server?
  • Which data types are commonly mapped to PII, PHI, and PCI categories in DLP, and why mapping is important?
  • In the Enforce server, which file extension represents normal incident data?
  • How do Cloud Detection Service and the Enforce server communicate with each other?
  • Describe the typical incident workflow from detection to closure in Symantec DLP.
  • Which two automated response rules will be active in policies that include Exact Data Matching detection rule?
  • What must be configured to generate a report of incidents by region and department?
  • How do you approach false positives and false negatives in DLP tuning?
  • Which service encrypts the message when using a Modify SMTP Message response rule?
  • In the installation sequence Oracle Database/Enforce Server/Solution Pack/Detection Server, which component is installed last?
  • Which statement about ICE is correct?
  • A DLP administrator is attempting to add a new Network Discover detection server from the Enforce management console, but only Network Monitor and Endpoint servers are shown. What should the administrator do to enable Network Discover?
  • Which action should you perform to make the endpoint agent's events invisible in Enforce?
  • In a Network Prevent content response rule, which action is appropriate when the content cannot be removed?
  • Why are phased rollouts recommended in DLP deployments?
  • Which statement about deployment components sharing policy packs and incident data is true?
  • What does EDM stand for in Symantec DLP?
  • In which scenarios would you choose Block vs Monitor as an enforcement action per channel?
  • Where can the detection servers be hosted in a deployment?
  • What is the name of the rule that retains the original message during incident data retention?
  • Which statement best describes the difference between a content fingerprint and a regular expression for data detection?
  • Which option is an accurate use case for Information Centric Encryption (ICE)?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy