A DLP administrator determines that the \SymantecDLP\Protect\Incidents folder on the Enforce server contains. BAD files dated today, while other. IDC files are flowing in and out of the \Incidents directory. Only .IDC files larger than 1MB are turning to .BAD files.
What could be causing only incident data smaller than 1MB to persist while incidents larger than 1MB change to .BAD files?
Which two components can perform a file system scan of a workstation? (Choose two.)
What detection server is used for Network Discover, Network Protect, and Cloud Storage?
What are two reasons an administrator should utilize a manual configuration to determine the endpoint location? (Choose two.)
What should an incident responder select in the Enforce management console to remediate multiple incidents simultaneously?
When managing an Endpoint Discover scan, a DLP administrator notices some endpoint computers are NOT completing their scans.
When does the DLP agent stop scanning?
What is the correct configuration for “BoxMonitor.Channels” that will allow the server to start as a Network Monitor server?
A compliance officer needs to understand how the company is complying with its data security policies over time.
Which report should be compliance officer generate to obtain the compliance information?
Which Network Prevent action has taken place when a Network incident snapshot indicates the message has been “Modified”?
What is the correct installation sequence for the components shown here, according to the Symantec Installation Guide?
Place the options in the correct installation sequence.
Which two (2) technologies should an organization utilize for integration with the Network Prevent products? (Choose two.)
What is the correct order for data in motion when a customer has integrated their CloudSOC and DLP solutions?
Which two Network Discover/Cloud Storage targets apply Information Centric Encryption as policy response rules?
A DLP administrator needs to remove an agent and its associated events from an Endpoint server.
Which Agent Task should the administrator perform to disable the agent’s visibility in the Enforce management console?
Which tool must a DLP administrator run to certify the database prior to upgrading DLP?
Which two factors are common sources of data leakage where the main actor is well-meaning insider? (Choose two.)
A company needs to implement Data Owner Exception so that incidents when employees send or receive their own personal information.
What detection method should the company use?
Which two actions are available for a “Network Prevent: Remove HTTP/HTTPS content” response rule when the content is unable to be removed? (Choose two.)
A DLP administrator created a new agent configuration for an Endpoint server. However, the endpoint agents fail to receive the new configuration.
What is one possible reason that the agent fails to receive the new configuration?
How should a DLP administrator change a policy that it retains the original file when an endpoint incident has detected a “copy to USB device” operation?
What are two (2) reasons an administrator should utilize a manual configuration to determine the endpoint location? (Choose two.)
Which option correctly describes the two-tier installation type for Symantec DLP?
How should a DLP administrator exclude a custom endpoint application named “custom_app.exe” from being monitored by Application File Access Control?
When troubleshooting Enforce issues, what should be considered regarding server resources?