MILESTONE CERTIFIED DESIGN ENGINEER
MCDE EXAM 2026 EXAMPREP STUDY GUIDE
WITH COMPLETE Q&A
◉ TRUE or FALSE: All server protection features are enabled by
default. Answer: FALSE
◉ Which endpoint protection policy protects users against malicious
network traffic? Answer: Threat Protection
◉ Which is the minimum administrative role that will allow a user to
view alerts, perform updates and scan endpoints? Answer: Help
Desk
◉ Your Enterprise Dashboard has been configured with multiple
sub-estates. In which 2 ways can you manage the licenses associated
with the sub-estates? Answer: (1) In the sub-estate Central Admin
Console
(2) In the Enterprise Dashboard
◉ Threat search results are split into which 2 of the following.
Answer: (1) Files
(2) Network
, ◉ In which policy do you configure anti-virus scanning? Answer:
Threat Protection
◉ Which feature of Intercept X is designed to detect malware before
it can execute? Answer: Exploit technique detection
◉ True or False: You can choose to send email alerts immediately,
hourly, daily or never. Answer: True
◉ An endpoint is reporting that Sophos AutoUpdate is not installed.
In the Self-Help Tool which tab do you check to view whether
AutoUpdate is listed as installed? Answer: Installed components
◉ A Windows endpoint installation is failing. It is detecting
competitor software. Which log file do you check to investigate this
issue? Answer: avremove.log
◉ How do users view quarantined emails and manage device
encryption for their protected endpoints? Answer: The Self-Service
Portal
◉ Which 2 of the following are the methods for bulk importing
users? Answer: (1) Using the Active Directory Sync Utility
MCDE EXAM 2026 EXAMPREP STUDY GUIDE
WITH COMPLETE Q&A
◉ TRUE or FALSE: All server protection features are enabled by
default. Answer: FALSE
◉ Which endpoint protection policy protects users against malicious
network traffic? Answer: Threat Protection
◉ Which is the minimum administrative role that will allow a user to
view alerts, perform updates and scan endpoints? Answer: Help
Desk
◉ Your Enterprise Dashboard has been configured with multiple
sub-estates. In which 2 ways can you manage the licenses associated
with the sub-estates? Answer: (1) In the sub-estate Central Admin
Console
(2) In the Enterprise Dashboard
◉ Threat search results are split into which 2 of the following.
Answer: (1) Files
(2) Network
, ◉ In which policy do you configure anti-virus scanning? Answer:
Threat Protection
◉ Which feature of Intercept X is designed to detect malware before
it can execute? Answer: Exploit technique detection
◉ True or False: You can choose to send email alerts immediately,
hourly, daily or never. Answer: True
◉ An endpoint is reporting that Sophos AutoUpdate is not installed.
In the Self-Help Tool which tab do you check to view whether
AutoUpdate is listed as installed? Answer: Installed components
◉ A Windows endpoint installation is failing. It is detecting
competitor software. Which log file do you check to investigate this
issue? Answer: avremove.log
◉ How do users view quarantined emails and manage device
encryption for their protected endpoints? Answer: The Self-Service
Portal
◉ Which 2 of the following are the methods for bulk importing
users? Answer: (1) Using the Active Directory Sync Utility