2026/2027: 100% Verified Questions &
Correct Answers
Question 1:
A customer’s Windows 11 laptop shows “Last seen 3 days” in Sophos Central. Which built-in
Sophos Central tool should you run first to verify whether the endpoint is online and able to
communicate with the cloud?
A. Enable “Enhanced Logging” on the endpoint
B. Run the “Connectivity Troubleshooter” from the device summary page
C. Push a “Wake-Up” task from Central
D. Re-install the Sophos agent from the deployment wizard
Correct Answer: B
Rationale: The Connectivity Troubleshooter performs cloud reachability, certificate, and proxy
checks directly from the affected endpoint without changing its state.
,Question 2:
During a fresh on-premise Sophos Endpoint installation you receive error 0x80070543. Logs show
the MSI cannot validate the Sophos code-signing certificate. Which certificate store must contain
the required root/intermediate certs?
A. Trusted Root Certification Authorities – Local Computer
B. Third-Party Root Certification Authorities – Current User
C. Personal – Current User
D. Enterprise Trust – Local Computer
Correct Answer: A
Rationale: The Local Computer “Trusted Root” store is queried by SYSTEM-level MSI installs;
missing roots here cause 0x80070543.
Question 3:
A threat detection email lists “Mal/Generic-R + AMSI” with the action “Auto-authorized” on a finance
PC. What is the correct first technician action?
A. Delete the file manually from the endpoint
B. Open the alert in Central, click “Authorize” to reverse, then re-scan
C. Mark the detection as a false positive and add a global exclusion
,D. Collect a sample and escalate to SophosLabs via the Support wizard
Correct Answer: D
Rationale: “Auto-authorized” indicates an admin previously allowed the hash; finance PCs require
SophosLabs review before revocation to avoid business impact.
Question 4:
Which default port must be open outbound for Sophos Central-managed endpoints to successfully
download engine and IDE updates?
A. TCP 443
B. TCP 80
C. UDP 123
D. TCP 4446
Correct Answer: A
Rationale: All update packages are delivered over HTTPS (TCP 443) to d1.sophosupd.com and
related CDNs.
Question 5:
, You need to move 250 endpoints from an old “Trial” tenant into the customer’s new paid Central
tenant. Which built-in feature preserves tamper-protection passwords and group structure?
A. Export/Import CSV with “Include credentials”
B. Tenant-to-Tenant Migration Tool
C. Clone Group wizard
D. Policy Export/Import wizard
Correct Answer: B
Rationale: The Tenant-to-Tenant Migration Tool (under Global Settings) transfers devices, groups,
policies, and tamper passwords in one wizard-driven workflow.
Question 6:
A server protected by Intercept X with EDR shows “Deep Learning analysis: Suspicious” with
confidence 68 %. What is the default Central policy action at this confidence level?
A. Block and clean
B. Allow but create alert only
C. Quarantine until admin review
D. Terminate process and isolate host