Key details for this exam, checked against the published exam outline
Each question shows the correct answer and an explanation of why it is right
Which type of security threat continues to threaten endpoint security after a system reboot?
A Rootkit is a type of security threat that can persist across system reboots, making it difficult to detect and remove. Rootkits operate by embedding themselves deep within the operating system, often at the kernel level, and they can disguise their presence by intercepting and modifying standard operating system functionality. Here's how they maintain persistence:
Kernel-Level Integration: Rootkits modify core operating system files, allowing them to load during the boot process and remain active after reboots.
Stealth Techniques: By hiding from regular security checks, rootkits avoid detection by conventional anti-virus and anti-malware tools.
Persistence Mechanism: The modifications rootkits make ensure they start up again after each reboot, enabling continuous threat activity on the compromised system.
Due to their persistence and stealth, rootkits present significant challenges for endpoint security.
When configuring Network Integrity, why is it a requirement to add trusted certificates?
When configuring Network Integrity in Symantec Endpoint Security, it is essential to add trusted certificates to allow enterprise SSL decryption for security scanning. This enables the inspection of encrypted traffic, which is critical for identifying threats or anomalies in SSL/TLS communications.
Purpose of Trusted Certificates:
Adding trusted certificates facilitates SSL decryption, allowing the security system to analyze encrypted data streams for potential threats without triggering security warnings or connection issues.
Why Other Options Are Less Applicable:
Securing connections to ICDm (Option B) and VPN connections (Option C) are not directly related to Network Integrity's focus on SSL decryption.
Bypassing an attacker's MITM proxy (Option D) does not directly address the function of trusted certificates within Network Integrity.
Files are blocked by hash in the deny list policy. Which algorithm is supported, in addition to MD5?
In Symantec Endpoint Protection (SEP), when files are blocked by hash in the deny list policy, SHA256 is supported in addition to MD5. SHA256 provides a more secure hashing algorithm compared to MD5 due to its longer hash length and higher resistance to collisions, making it effective for uniquely identifying and blocking malicious files based on their fingerprint.
An organization has a virtualized environment that is utilized by a group of Developers for testing. What feature can this organization utilize to optimize performance when running scheduled scans?
In virtualized environments, Symantec Endpoint Protection (SEP) offers Shared Insight Cache (SIC) as a feature to improve performance by reducing redundant scanning.
Shared Insight Cache Functionality:
SIC allows SEP clients in a virtual environment to share scan results. Once a file is scanned and deemed safe, that result is cached and shared across other SEP clients, preventing duplicate scans of the same file on different virtual machines (VMs).
This caching mechanism is especially beneficial in environments where multiple VMs frequently use identical files, such as software libraries or system files.
Optimized Performance:
By reducing repetitive scanning, SIC minimizes CPU and disk usage, allowing virtualized environments to maintain performance even during scheduled scans.
This approach is ideal for development and testing environments, where VM efficiency is crucial for productivity.
Why Other Options Are Less Suitable:
Disabling ELAM or adjusting Auto-Protect settings may reduce security or have limited impact on overall performance in a virtualized environment.
Randomizing scheduled scans could help distribute resource load but does not prevent redundant scans across VMs.
An organization is considering a single site for their Symantec Endpoint Protection environment. What are two (2) reasons that the organization should consider? (Select two)
When considering a single-site deployment for Symantec Endpoint Protection (SEP), the following two factors support this architecture:
Sufficient WAN Bandwidth (B):
A single-site SEP environment relies on robust WAN bandwidth to support endpoint communication, policy updates, and threat data synchronization across potentially distant locations.
High bandwidth ensures that endpoints remain responsive to management commands and receive updates without significant delays.
Delay-free, Centralized Reporting (C):
A single-site architecture enables all reporting data to be stored and accessed from one location, providing immediate insights into threats and system health across the organization.
Centralized reporting is ideal when administrators need quick access to consolidated data for faster decision-making and incident response.
Why Other Options Are Not As Relevant:
Organizational mergers (A) and legal constraints (E) do not necessarily benefit from a single-site architecture.
24x7 admin availability (D) is more related to staffing requirements rather than a justification for a single-site SEP deployment.
150 questions covering all exam domains, starting from $20
Exam domains verified against: Official Broadcom 250-580 exam guide, last checked September 2026.
Measures skills of Endpoint Security Technical Specialist and covers comprehensive endpoint protection through policy implementation and management. Build expertise in deploying protective measures across enterprise environments and configuring security policies to meet organizational requirements.
Sample question from this domain above: Q5
Measures skills of Endpoint Security IT Professionals and addresses current threat landscape analysis using the MITRE ATT&CK Framework. Understand threat categorization, ICDm security control dashboards, and incident response lifecycles for effective threat management.
Measures skills of Endpoint Security Technical Specialist and focuses on SES Complete architecture and cloud-based management. Learn to deploy detection mechanisms and reduce vulnerability exposure across your infrastructure.
Sample question from this domain above: Q4
Measures skills of Endpoint Security IT Professionals and covers mobile device security requirements and Network Integrity management. Configure security policies for modern devices and ensure secure operations within the ICDm management console.
Measures skills of professionals and explores Threat Defense for Active Directory implementation and policy migration from SEPM to ICDm console. Secure critical organizational assets in hybrid environments and manage legacy system protection.
Measures skills of Endpoint Security IT Professionals and focuses on Symantec Endpoint Protection components and implementation. Understand core SEP infrastructure and deploy solutions that scale across enterprise environments.
Measures skills of Endpoint Security Technical Specialist and addresses implementation of layered security measures. Apply defense-in-depth strategies combining multiple protection technologies for comprehensive threat prevention.
Sample question from this domain above: Q2
Measures skills of Endpoint Security IT Professionals and covers operational aspects of security control dashboards and management interfaces. Monitor and respond to security events using ICDm and related management tools.
Measures skills of Endpoint Security Technical Specialist and addresses design and deployment of endpoint security solutions. Plan and implement security infrastructure that meets organizational scale and performance requirements.
Measures skills of Endpoint Security IT Professional and focuses on policy integration across different security platforms. Execute migrations between security solutions while maintaining protection and minimizing operational disruption.
Common questions about the exam itself