SOPHOS ENDPOINT AND SERVER 2025/2026 QUESTIONS
WITH ANSWERS RATED A+
✔✔Add the path of the application to the server lockdown policy - ✔✔What is the
recommended way to allow a new application to a locked down server?
✔✔Update - ✔✔Which section in the self-help tool should be chhecked to starting
investigating an updating issue on an endpoint
✔✔False - ✔✔All Endpoints have the same tamper protection password.
✔✔Isolate the computer - ✔✔A malicious file has been detected on an endpoint and
you want to prevent lateral movement through your network.
From the threat case, which action do you take?
✔✔Servers or server groups - ✔✔Server policies are only applied to....
✔✔The base policy is bypassed - ✔✔You have cloned the threat protection base policy,
applied the policy to a group and saved it.
When checking the endpoint, the policy changes have not taken effect. What do you
check in policy?
✔✔Separate download that detects and removes malware - ✔✔The virus removal clean
up tool is a...
✔✔Management Communication - ✔✔You want to check an endpoint has received the
latest policy updates from Sophos Central.
Which tab do you select in the Endpoint Self-Help Tool to view the last communication
date and time?
✔✔avremove log - ✔✔A Windows endpoint installation is falling. It is detecting
competitor software.
Which log file do you check to investigate this issue?
✔✔Management Communications System - ✔✔All endpoints communicate with the
Sophos Central Console via?
✔✔Manage endpoint software - ✔✔Components can be assisned to or removed from
endpoints by selecting the endpoint(s) from the list and selecting
, ✔✔Policies - ✔✔Are used in Sophos Central to define the security measures that will be
applied to protected endpoints.
✔✔Users tab - ✔✔Tab where you can apply the policy to the required users
✔✔Groups tab - ✔✔If your are creating a policy to be deployed to multiple users, you
can use____ to apply to it specific groups.
✔✔Settings tab - ✔✔Where you will see an Active Adversary Mitigation drop down
menu.
✔✔Live protection - ✔✔Checks suspicious files against the latest information in Sophos
Labs.
You can select to enable this during scheduled scans and automatically submit samples
to Sophos.
✔✔Deep learning - ✔✔Uses advance machine learning to detect threats. It can identify
known and previously unknown malware and potentially unwanted applications without
using signatures.
✔✔Real time scanning - ✔✔Scans files as users attempt to access them, denies access
unless the file is clean.
✔✔Remediation - ✔✔Sophos Central will attempt to clean up detected malware
automatically. If this is successful, the alert in Sophos Central against the compromised
endpoint is deleted. The detection and clean up are displayed in the events list.
✔✔Runtime Protection - ✔✔Protects threats by detecting suspicious or malicious
behaviour or traffic
✔✔Device Isolation - ✔✔when enabled, allows computers to isolate themselves if they
have a red health status.
✔✔Peripheral control policies - ✔✔Policy that let you both monitor and block the use of
removable devices and other peripherals on your endpoints
✔✔Application Control - ✔✔lets you monitor and manage the applications that your
users have access to.
✔✔Data loss prevention - ✔✔is part of endpoint protection and controls accidental data
loss by monitoring and restricting the transfer of files containing sensitive date.
WITH ANSWERS RATED A+
✔✔Add the path of the application to the server lockdown policy - ✔✔What is the
recommended way to allow a new application to a locked down server?
✔✔Update - ✔✔Which section in the self-help tool should be chhecked to starting
investigating an updating issue on an endpoint
✔✔False - ✔✔All Endpoints have the same tamper protection password.
✔✔Isolate the computer - ✔✔A malicious file has been detected on an endpoint and
you want to prevent lateral movement through your network.
From the threat case, which action do you take?
✔✔Servers or server groups - ✔✔Server policies are only applied to....
✔✔The base policy is bypassed - ✔✔You have cloned the threat protection base policy,
applied the policy to a group and saved it.
When checking the endpoint, the policy changes have not taken effect. What do you
check in policy?
✔✔Separate download that detects and removes malware - ✔✔The virus removal clean
up tool is a...
✔✔Management Communication - ✔✔You want to check an endpoint has received the
latest policy updates from Sophos Central.
Which tab do you select in the Endpoint Self-Help Tool to view the last communication
date and time?
✔✔avremove log - ✔✔A Windows endpoint installation is falling. It is detecting
competitor software.
Which log file do you check to investigate this issue?
✔✔Management Communications System - ✔✔All endpoints communicate with the
Sophos Central Console via?
✔✔Manage endpoint software - ✔✔Components can be assisned to or removed from
endpoints by selecting the endpoint(s) from the list and selecting
, ✔✔Policies - ✔✔Are used in Sophos Central to define the security measures that will be
applied to protected endpoints.
✔✔Users tab - ✔✔Tab where you can apply the policy to the required users
✔✔Groups tab - ✔✔If your are creating a policy to be deployed to multiple users, you
can use____ to apply to it specific groups.
✔✔Settings tab - ✔✔Where you will see an Active Adversary Mitigation drop down
menu.
✔✔Live protection - ✔✔Checks suspicious files against the latest information in Sophos
Labs.
You can select to enable this during scheduled scans and automatically submit samples
to Sophos.
✔✔Deep learning - ✔✔Uses advance machine learning to detect threats. It can identify
known and previously unknown malware and potentially unwanted applications without
using signatures.
✔✔Real time scanning - ✔✔Scans files as users attempt to access them, denies access
unless the file is clean.
✔✔Remediation - ✔✔Sophos Central will attempt to clean up detected malware
automatically. If this is successful, the alert in Sophos Central against the compromised
endpoint is deleted. The detection and clean up are displayed in the events list.
✔✔Runtime Protection - ✔✔Protects threats by detecting suspicious or malicious
behaviour or traffic
✔✔Device Isolation - ✔✔when enabled, allows computers to isolate themselves if they
have a red health status.
✔✔Peripheral control policies - ✔✔Policy that let you both monitor and block the use of
removable devices and other peripherals on your endpoints
✔✔Application Control - ✔✔lets you monitor and manage the applications that your
users have access to.
✔✔Data loss prevention - ✔✔is part of endpoint protection and controls accidental data
loss by monitoring and restricting the transfer of files containing sensitive date.