Broadcom 250-580 Practice Exams
Last updated on Oct 01,2026- Exam Code: 250-580
- Exam Name: Endpoint Security Complete - R2 Technical Specialist
- Certification Provider: Broadcom
- Latest update: Oct 01,2026
Which term or expression is utilized when adversaries leverage existing tools in the environment?
- A . opportunistic attack
- B . file-less attack
- C . script kiddies
- D . living off the land
D
Explanation:
Living off the land (LOTL) is a tactic where adversaries leverage existing tools and resources within the environment for malicious purposes. This approach minimizes the need to introduce new, detectable malware, instead using trusted system utilities and software already present on the network.
Characteristics of Living off the Land:
LOTL attacks make use of built-in utilities, such as PowerShell or Windows Management Instrumentation (WMI), to conduct malicious operations without triggering traditional malware defenses.
This method is stealthy and often bypasses signature-based detection, as the tools used are legitimate components of the operating system.
Why Other Options Are Incorrect:
Opportunistic attack (Option A) refers to attacks that exploit easily accessible vulnerabilities rather than using internal resources.
File-less attack (Option B) is a broader category that includes but is not limited to LOTL techniques. Script kiddies (Option C) describes inexperienced attackers who use pre-made scripts rather than sophisticated, environment-specific tactics.
Reference: Living off the land tactics leverage the environment’s own tools, making them difficult to detect and prevent using conventional anti-malware strategies.
Why is Active Directory a part of nearly every targeted attack?
- A . AD administration is managed by weak legacy APIs.
- B . AD is, by design, an easily accessed flat file name space directory database
- C . AD exposes all of its identities, applications, and resources to every endpoint in the network
- D . AD user attribution includes hidden elevated admin privileges
C
Explanation:
Active Directory (AD) is commonly targeted in attacks because it serves as a central directory for user identities, applications, and resources accessible across the network. This visibility makes it an attractive target for attackers to exploit for lateral movement, privilege escalation, and reconnaissance. Once compromised, AD provides attackers with significant insight into an organization’s internal structure, enabling further exploitation and access to sensitive data.
Performance on a SEPM is less than expected and generates intermittent errors.
How could the system administrators be notified of performance issues?
- A . Add a System event alert and specify how often the notifications need to be raised. Specify the e-mail address that needs to be notified and the action when the server health becomes poor.
- B . Add an Authentication alert and specify how often the notifications need to be raised. Specify the e-mail address that needs to be notified and the action when the server health becomes poor.
- C . Add a Client security alert and specify how often the notifications need to be raised. Specify the e-mail address that needs to be notified and the action when the server health becomes poor.
- D . Add a Server health alert and specify how often the notifications need to be raised. Specify the e-mail address that needs to be notified and the action when the server health becomes poor.
D
Explanation:
To notify administrators of performance issues on the SEPM, they should add a Server health alert.
This type of alert is specifically designed to monitor the health of the SEPM, triggering notifications when performance drops or errors occur.
Configuration Steps:
Set up a Server health alert in the SEPM, specifying the conditions that define poor server health.
Configure the alert frequency and designate an email address for notifications, ensuring that administrators receive timely updates.
Why Other Options Are Incorrect:
System event alerts (Option A) cover general system events but are less specific to performance.
Authentication alerts (Option B) focus on login and access issues.
Client security alerts (Option C) are related to endpoint security rather than SEPM server performance.
Reference: Server health alerts are tailored for monitoring SEPM’s performance, making them the ideal choice for tracking server health.
Which security control is complementary to IPS, providing a second layer of protection against network attacks?
- A . Host Integrity
- B . Network Protection
- C . Antimalware
- D . Firewall
D
Explanation:
The Firewall provides a complementary layer of protection to Intrusion Prevention System (IPS) in Symantec Endpoint Protection.
Firewall vs. IPS:
While IPS detects and blocks network-based attacks by inspecting traffic for known malicious patterns, the firewall controls network access by monitoring and filtering inbound and outbound traffic based on policy rules.
Together, these tools protect against a broader range of network threats. IPS is proactive in identifying malicious traffic, while the firewall prevents unauthorized access.
Two-Layer Defense Mechanism:
The firewall provides control over which ports, protocols, and applications can access the network, reducing the attack surface.
When combined with IPS, the firewall blocks unauthorized connections, while IPS actively inspects and prevents malicious content within allowed traffic.
Why Other Options Are Not Complementary:
Host Integrity focuses on compliance and configuration validation rather than direct network traffic protection.
Network Protection and Antimalware are essential but do not function as second-layer defenses for IPS within network contexts.
Reference: Symantec Endpoint Protection’s network protection strategies outline the importance of firewalls in conjunction with IPS for comprehensive network defense.
An administrator is troubleshooting a Symantec Endpoint Protection (SEP) replication.
Which component log should the administrator check to determine whether the communication between the two sites is working correctly?
- A . Apache Web Server
- B . Tomcat
- C . SQL Server
- D . Group Update Provider (GUP)
B
Explanation:
For troubleshooting Symantec Endpoint Protection (SEP) replication, the administrator should check the Tomcat logs. Tomcat handles the SEP management console’s web services, including replication communication between different SEP sites.
Role of Tomcat in SEP Replication:
Tomcat provides the HTTP/S services used for SEP Manager-to-Manager communication during replication. Checking these logs helps verify if there are issues in the web services layer that might prevent replication.
Why Other Logs Are Less Relevant:
Apache Web Server is not typically involved in SEP’s internal replication.
SQL Server manages data storage but does not handle the replication communications directly. Group Update Provider (GUP) is related to client content distribution, not site-to-site replication.
Reference: Tomcat logs are critical for diagnosing SEP replication issues, as they reveal HTTP/S communication errors between SEP sites.
Which report template type should an administrator utilize to create a daily summary of network threats detected?
- A . Intrusion Prevention Report
- B . Blocked Threats Report
- C . Network Risk Report
- D . Access Violation Report
C
Explanation:
To create a daily summary of network threats detected, an administrator should use the Network Risk Report template. This report template provides a comprehensive overview of threats within the network, including:
Summary of Threats Detected: It consolidates data on threats, providing a summary of recent detections across the network.
Insight into Network Security Posture: The report helps administrators understand the types and frequency of network threats, enabling them to make informed decisions on security measures. Daily Monitoring: Using this report on a daily basis allows administrators to maintain an up-to-date view of the network’s risk profile and respond promptly to emerging threats.
The Network Risk Report template is ideal for regular monitoring of network security events.
Which type of activity recorder does EDR provide?
- A . Virtual
- B . Endpoint
- C . Email
- D . Temporary
B
Explanation:
Symantec Endpoint Detection and Response (EDR) provides an Endpoint activity recorder to monitor, log, and analyze behaviors on endpoints. This feature captures various endpoint activities such as process execution, file modifications, and network connections, which are essential for detecting and investigating potential security incidents.
Purpose of Endpoint Activity Recorder:
The endpoint activity recorder helps track specific actions and behaviors on endpoints, providing insights into potentially suspicious or malicious activity.
This data is valuable for incident response and for understanding how threats may have propagated across the network.
Why Other Options Are Not Suitable:
Virtual (Option A), Email (Option C), and Temporary (Option D) do not accurately represent the continuous and comprehensive nature of endpoint activity monitoring.
Reference: The endpoint activity recorder in EDR is a core feature for tracking and analyzing endpoint events for enhanced security.
What Symantec Best Practice is recommended when setting up Active Directory integration with the Symantec Endpoint Protection Manager?
- A . Ensure there is more than one Active Directory Server listed in the Server Properties.
- B . Link the built-in Admin account to an Active Directory account.
- C . Import the existing AD structure to organize clients in user mode.
- D . Secure the management console by denying access to certain computers.
C
Explanation:
When setting up Active Directory (AD) integration with Symantec Endpoint Protection Manager (SEPM), Symantec’s best practice is to import the existing AD structure to manage clients in user mode.
This approach offers several benefits:
Simplified Client Management: By importing the AD structure, SEPM can mirror the organizational structure already defined in AD, enabling easier management and assignment of policies to groups or organizational units.
User-Based Policies: Organizing clients in user mode allows policies to follow users across devices, providing consistent protection regardless of where the user logs in.
Streamlined Updates and Permissions: Integration with AD ensures that any changes in user accounts or groups are automatically reflected within SEPM, reducing administrative effort and potential errors in client organization.
This best practice enhances SEPM’s functionality by leveraging the established structure in AD.
What feature is used to get a comprehensive picture of infected endpoint activity?
- A . Entity View
- B . Process View
- C . Full Dump
- D . Endpoint Dump
B
Explanation:
The Process View feature in Symantec Endpoint Detection and Response (EDR) provides a detailed and comprehensive view of activities associated with an infected endpoint. It displays a graphical representation of processes, their hierarchies, and interactions, which helps security teams understand the behavior and spread of malware on the system.
Advantages of Process View:
Process View shows the relationship between different processes, including parent-child structures, which can reveal how malware propagates or persists on an endpoint.
This visualization is instrumental in tracking the full impact of an infection, helping administrators
identify malicious activities linked to specific processes.
Why Other Options Are Less Suitable:
Entity View is more focused on broader data relationships, not specific infected process activities. Full Dump and Endpoint Dump refer to memory or system dumps, which are useful for in-depth forensic analysis but do not provide an immediate, clear picture of endpoint activity.
Reference: Process View is designed within EDR for tracking endpoint infection paths and behavioral analysis.
Which Firewall rule components should an administrator configure to block facebook.com use during business hours?
- A . Host(s), Network Interface, and Network Service
- B . Application, Host(s), and Network Service
- C . Action, Hosts(s), and Schedule
- D . Action, Application, and Schedule
C
Explanation:
To block facebook.com use during business hours, the SEP administrator should configure the Action, Hosts(s), and Schedule components within the Firewall rule. Explanation of Each Component:
Action: Set to "Block" to deny access to the specified site.
Hosts(s): Specify facebook.com as the target host, ensuring that all traffic to this domain is blocked.
Schedule: Define the rule to apply only during business hours, ensuring that access is restricted
within the designated time frame.
Why Other Options Are Incorrect:
Network Interface and Network Service (Options A and B) are not specific to blocking domain access. Application (Options B and D) is unnecessary if the goal is to block access based on domain and schedule.
Reference: Configuring Action, Hosts, and Schedule within SEP firewall rules enables precise access control based on time and target domain.