How should a DLP administrator change a policy so that it retains the original file when an endpoint incident has detected a ג€copy to USB deviceג€ operation?
Answer : A
What is the correct configuration for ג€BoxMonitor.Channelsג€ that will allow the server to start as a Network Monitor server?
Answer : C
Reference:
https://support.symantec.com/en_US/article.TECH218980.html
Under the ג€System Overviewג€ in the Enforce management console, the status of a Network Monitor detection server is shown as ג€Running Selected.ג€ The Network
Monitor serverג€™s event logs indicate that the packet capture and filereader processes are crashing.
What is a possible cause for the Network Monitor server being in this state?
Answer : D
Which two Infrastructure-as-a-Service providers are supported for hosting Cloud Prevent for Office 365? (Choose two.)
Answer : BE
Reference:
https://symwisedownload.symantec.com//resources/sites/SYMWISE/content/live/DOCUMENTATION/8000/DOC8244/en_US/
Symantec_DLP_15.0_Cloud_Prevent_O365.pdf?__gda__=1554430310_584ffada3918e15ced8b6483a2bfb6fb
(14)
A DLP administrator has enabled and successfully tested custom attribute lookups for incident data based on the Active Directory LDAP plugin. The Chief
Information Security Officer (CISO) has attempted to generate a User Risk Summary report, but the report is empty. The DLP administrator confirms the Ciscoג€™s role has the ג€User Reportingג€ privilege enabled, but User Risk reporting is still not working.
What is the probable reason that the User Risk Summary report is blank?
Answer : D