SOPHOS ENGINEER STUDY GUIDE 2025/2026 QUESTIONS
WITH ANSWERS RATED A+
✔✔Tamper Protection is enabled - ✔✔The option to stop the AutoUpdate service is
greyed out in Windows Services. What is the most likely reason for this?
✔✔Encryption - ✔✔Which Sophos Central manage product protects the data on a lost
or stolen laptop?
✔✔False - ✔✔TRUE or FALSE: The security VM installer is linked to your Sophos
Central account.
✔✔That you have the correct role assigned - ✔✔You are unable to edit policies in
Sophos Central. What do you check in Sophos Central?
✔✔Master Licensing, Individual Licensing - ✔✔In which 2 ways can you license the
Enterprise Dashboard?
✔✔Prevents a user from uninstalling the Sophos agent software - ✔✔What does tamper
protection prevent a user from doing on their endpoint with Sophos Central agent
installed
✔✔Events report - ✔✔Which report will give you information across all protected
endpoints?
✔✔The Self-Service Portal - ✔✔How do users view quarantined emails and manage
device encryption for their protected endpoints
✔✔SUMMARY - ✔✔Which tab on the device details page displays the tamper
protection information
✔✔Failed to protect an endpoint - ✔✔Which of the following alerts is categorized as a
high alert?
✔✔Failed to protect an endpoint - ✔✔Which of the following alerts is categorized as a
high alert?
✔✔False - ✔✔TRUE or FALSE: All Endpoints have the same tamper protection
password.
✔✔In the sub-estate Central Admin Console, In the Enterprise Dashboard - ✔✔Your
Enterprise Dashboard has been configured with multiple sub-estates. In which 2 ways
can you manage the licenses associated with the sub-estates?
, ✔✔By Severity - ✔✔Which of the following is a configuration option for setting the
frequency of email alerts from the Partner Dashboard?
✔✔90 days - ✔✔How long are activities stored for in the Enterprise Dashboard?
✔✔POLICY BYPASSED - ✔✔You have created a new policy. Which tab do you select
to enable the policy?
✔✔True - ✔✔True or False: The Sophos Central Partner Portal can be used to manage
customers' XG Firewalls.
✔✔To monitor and restrict file transfers containing sensitive data - ✔✔What is the
function of Data Loss Prevention?
✔✔Read Only - ✔✔Which is the minimum administrative role that will allow a user to
view alerts and logs?
✔✔Admin - ✔✔What is the minimum administrative role that will allow a user to create
and edit policies?
✔✔Once a day - ✔✔What is the Sophos recommended Active Directory sync interval?
✔✔True - ✔✔True or False: Multi-factor authentication is enabled by default for all
Enterprise Administrators.
✔✔Multi-factor Authentication - ✔✔You want to configure the login settings for all
administrators to require two factors of authentication. Which global setting do you
enable?
✔✔False - ✔✔True or False: Marking an alert as acknowledge will resolve the threat on
the endpoint.
✔✔WipeGuard - ✔✔Which detection feature can prevent attacks on the master boot
record?
✔✔Threat Protection - ✔✔In which policy do you configure anti-virus scanning?
✔✔Scans for potentially malicious behaviour - ✔✔What does HIPS do on a protected
endpoint?
✔✔Sophos' recommended settings - ✔✔The default protection base policy is configured
with...
WITH ANSWERS RATED A+
✔✔Tamper Protection is enabled - ✔✔The option to stop the AutoUpdate service is
greyed out in Windows Services. What is the most likely reason for this?
✔✔Encryption - ✔✔Which Sophos Central manage product protects the data on a lost
or stolen laptop?
✔✔False - ✔✔TRUE or FALSE: The security VM installer is linked to your Sophos
Central account.
✔✔That you have the correct role assigned - ✔✔You are unable to edit policies in
Sophos Central. What do you check in Sophos Central?
✔✔Master Licensing, Individual Licensing - ✔✔In which 2 ways can you license the
Enterprise Dashboard?
✔✔Prevents a user from uninstalling the Sophos agent software - ✔✔What does tamper
protection prevent a user from doing on their endpoint with Sophos Central agent
installed
✔✔Events report - ✔✔Which report will give you information across all protected
endpoints?
✔✔The Self-Service Portal - ✔✔How do users view quarantined emails and manage
device encryption for their protected endpoints
✔✔SUMMARY - ✔✔Which tab on the device details page displays the tamper
protection information
✔✔Failed to protect an endpoint - ✔✔Which of the following alerts is categorized as a
high alert?
✔✔Failed to protect an endpoint - ✔✔Which of the following alerts is categorized as a
high alert?
✔✔False - ✔✔TRUE or FALSE: All Endpoints have the same tamper protection
password.
✔✔In the sub-estate Central Admin Console, In the Enterprise Dashboard - ✔✔Your
Enterprise Dashboard has been configured with multiple sub-estates. In which 2 ways
can you manage the licenses associated with the sub-estates?
, ✔✔By Severity - ✔✔Which of the following is a configuration option for setting the
frequency of email alerts from the Partner Dashboard?
✔✔90 days - ✔✔How long are activities stored for in the Enterprise Dashboard?
✔✔POLICY BYPASSED - ✔✔You have created a new policy. Which tab do you select
to enable the policy?
✔✔True - ✔✔True or False: The Sophos Central Partner Portal can be used to manage
customers' XG Firewalls.
✔✔To monitor and restrict file transfers containing sensitive data - ✔✔What is the
function of Data Loss Prevention?
✔✔Read Only - ✔✔Which is the minimum administrative role that will allow a user to
view alerts and logs?
✔✔Admin - ✔✔What is the minimum administrative role that will allow a user to create
and edit policies?
✔✔Once a day - ✔✔What is the Sophos recommended Active Directory sync interval?
✔✔True - ✔✔True or False: Multi-factor authentication is enabled by default for all
Enterprise Administrators.
✔✔Multi-factor Authentication - ✔✔You want to configure the login settings for all
administrators to require two factors of authentication. Which global setting do you
enable?
✔✔False - ✔✔True or False: Marking an alert as acknowledge will resolve the threat on
the endpoint.
✔✔WipeGuard - ✔✔Which detection feature can prevent attacks on the master boot
record?
✔✔Threat Protection - ✔✔In which policy do you configure anti-virus scanning?
✔✔Scans for potentially malicious behaviour - ✔✔What does HIPS do on a protected
endpoint?
✔✔Sophos' recommended settings - ✔✔The default protection base policy is configured
with...