- Home
- Symantec Certification
- 250-441 Exam
- Symantec.250-441.dumpsfiles Dumps
Free Symantec 250-441 Exam Dumps Questions & Answers
| Exam Code/Number: | 250-441Join the discussion |
| Exam Name: | Administration of Symantec Advanced Threat Protection 3.0 |
| Certification: | Symantec |
| Question Number: | 96 |
| Publish Date: | Jun 02, 2026 |
|
Rating
100%
|
|
Total 96 questions
Which two steps must an Incident Responder take to isolate an infected computer in ATP? (Choose two.)
What are two policy requirements for using the Isolate and Rejoin features in ATP? (Choose two.)
Which two user roles allow an Incident Responder to blacklist or whitelist files using the ATP manager?
(Choose two.)
An Incident Responder launches a search from ATP for a file hash. The search returns the results immediately. The responder reviews the Symantec Endpoint Protection Manager (SEPM) command status and does NOT see an indicators of compromise (IOC) search command.
How is it possible that the search returned results?
An Incident Responder wants to use a STIX file to run an indicate of components (IOC) search.
Which format must the administrator use for the file?