Broadcom 250-580 Practice Exams
Last updated on Oct 01,2026- Exam Code: 250-580
- Exam Name: Endpoint Security Complete - R2 Technical Specialist
- Certification Provider: Broadcom
- Latest update: Oct 01,2026
Which IPS signature type is primarily used to identify specific unwanted network traffic?
- A . Attack
- B . Audit
- C . Malcode
- D . Probe
A
Explanation:
Within Symantec Endpoint Protection’s Intrusion Prevention System (IPS), Attack signatures are specifically designed to identify and block known patterns of malicious network traffic.
Attack signatures focus on:
Recognizing Malicious Patterns: These signatures detect traffic associated with exploitation attempts, such as buffer overflow attacks, SQL injection attempts, or other common attack techniques. Real-Time Blocking: Once identified, the IPS can immediately block the traffic, preventing the attack from reaching its target.
High Accuracy in Targeted Threats: Attack signatures are tailored to match malicious activities precisely, making them effective for detecting and mitigating specific types of unwanted or harmful network traffic.
Attack signatures, therefore, serve as a primary layer of defense in identifying and managing unwanted network threats.
How should an administrator set up an alert to be notified when manual remediation is needed on an endpoint?
- A . Add a Single Risk Event notification and specify "Left Alone" for the action taken. Choose to log the notification and send an e-mail to the system administrators.
- B . Add a Client security alert notification and specify "Left Alone" for the action taken. Choose to log the notification and send an e-mail to the system administrators.
- C . Add a System event notification and specify "Left Alone" for the action taken. Choose to log the notification and send an e-mail to the system administrators.
- D . Add a New risk detected notification and specify "Left Alone" for the action taken. Choose to log the notification and send an email to the system administrators.
A
Explanation:
To notify administrators when manual remediation is required on an endpoint, the administrator should set up a Single Risk Event notification in SEP, with the action specified as "Left Alone". This configuration allows SEP to alert administrators only when the system does not automatically handle a detected risk, indicating that further manual intervention is required.
Setting Up the Notification:
Navigate to Notifications in the SEP management console.
Select Single Risk Event as the notification type and specify "Left Alone" for the action taken. Enable options to log the notification and send an email alert to system administrators. Rationale:
This approach ensures that administrators are only alerted when SEP detects a threat but cannot automatically remediate it, signaling a need for manual review and action.
Other options (e.g., System event notification, New risk detected) are broader and may trigger alerts unnecessarily, rather than focusing on cases needing manual attention.
Reference: Setting up targeted notifications, such as Single Risk Event with “Left Alone” action, is a best practice in SEP for efficient incident management.
Which SES feature helps to ensure that devices are compliant with a company’s security standards?
- A . Host Integrity
- B . Intensive Protection
- C . Trusted Updater
- D . Adaptive Protection
A
Explanation:
Host Integrity is a Symantec Endpoint Security (SES) feature that ensures devices are compliant with a company’s security standards. It does this by verifying system configurations, checking for required software (like antivirus or firewall settings), and validating other compliance criteria specified by the organization.
Functionality of Host Integrity:
Host Integrity checks are designed to ensure that each endpoint meets the necessary security configurations before granting it network access.
If a device is non-compliant, Host Integrity can enforce remediation steps, such as updating software or alerting administrators, to bring the device into compliance.
Why Other Options Are Less Suitable:
Intensive Protection (Option B) and Adaptive Protection (Option D) focus on active threat detection but not compliance enforcement.
Trusted Updater (Option C) is for allowing specific software updates without triggering alerts, not for overall compliance checking.
Reference: Host Integrity is a key feature in SES that promotes adherence to security policies across devices, ensuring network-wide compliance.
What does the Endpoint Communication Channel (ECC) 2.0 allow Symantec EDR to directly connect to?
- A . SEDR Cloud Console
- B . Synapse
- C . SEP Endpoints
- D . SEPM
D
Explanation:
The Endpoint Communication Channel (ECC) 2.0 enables Symantec Endpoint Detection and Response (EDR) to establish a direct connection with the Symantec Endpoint Protection Manager (SEPM).
This connection allows for:
Efficient Data Exchange: ECC 2.0 facilitates real-time communication and data exchange between SEPM and Symantec EDR.
Enhanced Endpoint Visibility: By directly connecting with SEPM, Symantec EDR can monitor endpoint activity more closely, improving threat detection and response.
Integrated Threat Management: ECC 2.0 supports coordinated efforts between SEPM and EDR, allowing for more effective containment and mitigation of threats.
This direct communication with SEPM enhances EDR’s capability to manage and protect endpoints effectively.
Which two (2) criteria are used by Symantec Insight to evaluate binary executables? (Select two.)
- A . Sensitivity
- B . Prevalence
- C . Confidentiality
- D . Content
- E . Age
BE
Explanation:
Symantec Insight uses Prevalence and Age as two primary criteria to evaluate binary executables. These metrics help determine the likelihood that a file is either benign or malicious based on its behavior across a broad user base:
Prevalence: This metric assesses how widely a file is used across Symantec’s global community. Files with higher prevalence are generally more likely to be safe, while rare files may pose higher risks. Age: The age of a file is also considered. Older files with a stable reputation are less likely to be malicious, whereas newer, unverified files are scrutinized more closely.
Using these criteria, Symantec Insight provides reliable reputation ratings for binary files, enhancing endpoint security by preemptively identifying potential threats.
Which Symantec Endpoint Protection technology blocks a downloaded program from installing browser plugins?
- A . Intrusion Prevention
- B . SONAR
- C . Application and Device Control
- D . Tamper Protection
C
Explanation:
The Application and Device Control technology within Symantec Endpoint Protection (SEP) is responsible for blocking unauthorized software behaviors, such as preventing a downloaded program from installing browser plugins. This feature is designed to enforce policies that restrict specific actions by applications, which includes controlling program installation behaviors, access to certain system components, and interactions with browser settings. Application and Device Control effectively safeguards endpoints by stopping potentially unwanted or malicious modifications to the browser, thus protecting users from threats that may arise from unverified or harmful plugins.
What happens when an administrator adds a file to the deny list?
- A . The file is assigned to a chosen Deny List policy
- B . The file is assigned to the Deny List task list
- C . The file is automatically quarantined
- D . The file is assigned to the default Deny List policy
D
Explanation:
When an administrator adds a file to the deny list in Symantec Endpoint Protection, the file is automatically assigned to the default Deny List policy. This action results in the following: Immediate Blocking: The file is blocked from executing on any endpoint where the Deny List policy is enforced, effectively preventing the file from causing harm.
Consistent Enforcement: Using the default Deny List policy ensures that the file is denied access across all relevant endpoints without the need for additional customization.
Centralized Management: Administrators can manage and review the default Deny List policy within SEPM, providing an efficient method for handling potentially harmful files across the network. This default behavior ensures swift response to threats by leveraging a centralized deny list policy.
Which action does SONAR take before convicting a process?
- A . Quarantines the process
- B . Blocks suspicious behavior
- C . Restarts the system
- D . Checks the reputation of the process
D
Explanation:
SONAR (Symantec Online Network for Advanced Response) checks the reputation of a process before convicting it. This reputation-based approach evaluates the trustworthiness of the process by referencing Symantec’s database, which is compiled from millions of endpoints, allowing SONAR to make informed decisions about whether the process is likely benign or malicious.
Reputation Checking in SONAR:
Before taking action, SONAR uses reputation data to reduce the likelihood of false positives, which ensures that legitimate processes are not incorrectly flagged as threats.
This check provides an additional layer of accuracy to SONAR’s behavioral analysis.
Why Other Options Are Incorrect:
Quarantining (Option A) and blocking behavior (Option B) occur after SONAR has convicted a process, not before.
Restarting the system (Option C) is not part of SONAR’s process analysis workflow.
Reference: SONAR’s reliance on reputation checks as a preliminary step in process conviction enhances its accuracy in threat detection.
The LiveUpdate Download Schedule is set to the default on the Symantec Endpoint Protection Manager (SEPM).
How many content revisions must the SEPM keep to ensure clients that check in to the SEPM every 10 days receive xdelta content packages instead of full content packages?
- A . 10
- B . 20
- C . 30
- D . 60
C
Explanation:
To ensure that clients checking in every 10 days receive xdelta content packages instead of full content packages, 30 content revisions must be retained on the Symantec Endpoint Protection Manager (SEPM). Here’s why:
Incremental Updates: xdelta packages are incremental updates that only download changes since the last update, conserving bandwidth and speeding up client updates.
Content Revision Retention: SEPM needs to retain a sufficient number of content revisions to allow clients that check in intermittently (such as every 10 days) to download incremental rather than full content packages.
Default Retention Recommendation: Retaining 30 content revisions ensures that clients are covered for up to 10 days of updates, meeting the requirement for xdelta delivery.
This setup optimizes resource usage by reducing the load on network and client systems.
What must be entered before downloading a file from ICDm?
- A . Name
- B . Password
- C . Hash
- D . Date
C
Explanation:
Before downloading a file from the Integrated Cyber Defense Manager (ICDm), the hash of the file must be entered. The hash serves as a unique identifier for the file, ensuring that the correct file is downloaded and verifying its integrity. Here’s why this is necessary:
File Verification: By entering the hash, users confirm they are accessing the correct file, which prevents accidental downloads of unrelated or potentially harmful files.
Security Measure: The hash requirement adds an additional layer of security, helping to prevent unauthorized downloads or distribution of sensitive files.
This practice ensures accurate and secure file management within ICDm.