SOPHOS ENGINEER COMPREHENSIVE
EXAMINATION 2026 FULL QUESTIONS AND
CORRECT ANSWERS
◉ TRUE or FALSE: The security VM installer is linked to your Sophos
Central account. Answer: FALSE
◉ TRUE or FALSE: You can deploy an update cache without a
Message Relay. Answer: TRUE
◉ You want to change an action for 'confidential' content. Where in
Sophos Central do you make this change? Answer: In the Data Loss
Prevention Rule
◉ What does HIPS do on a protected endpoint? Answer: Scans for
potentially malicious behaviour
◉ You have cloned the threat protection base policy, applied the
policy to a group and saved it. When checking the endpoint, the
policy changes have not taken effect. What do you check in the
policy? Answer: That the cloned policy has been enforced
, ◉ In which 2 ways can you license the Enterprise Dashboard?
Answer: (1) Master Licensing
(2) Individual Licensing
◉ What is the minimum administrative role that will allow a user to
create and edit policies? Answer: Admin
◉ Complete the following sentence: The default protection base
policy is configured with... Answer: Sophos' recommended settings
◉ Which section in the Self-Help tool should be checked to start
investigating an updating issue on an endpoint Answer: System
◉ What does tamper protection prevent a user from doing on their
endpoint with Sophos Central agent installed? Answer: Prevents a
user from uninstalling the Sophos agent software
◉ TRUE or FALSE: All server protection features are enabled by
default. Answer: FALSE
◉ Which endpoint protection policy protects users against malicious
network traffic? Answer: Threat Protection
EXAMINATION 2026 FULL QUESTIONS AND
CORRECT ANSWERS
◉ TRUE or FALSE: The security VM installer is linked to your Sophos
Central account. Answer: FALSE
◉ TRUE or FALSE: You can deploy an update cache without a
Message Relay. Answer: TRUE
◉ You want to change an action for 'confidential' content. Where in
Sophos Central do you make this change? Answer: In the Data Loss
Prevention Rule
◉ What does HIPS do on a protected endpoint? Answer: Scans for
potentially malicious behaviour
◉ You have cloned the threat protection base policy, applied the
policy to a group and saved it. When checking the endpoint, the
policy changes have not taken effect. What do you check in the
policy? Answer: That the cloned policy has been enforced
, ◉ In which 2 ways can you license the Enterprise Dashboard?
Answer: (1) Master Licensing
(2) Individual Licensing
◉ What is the minimum administrative role that will allow a user to
create and edit policies? Answer: Admin
◉ Complete the following sentence: The default protection base
policy is configured with... Answer: Sophos' recommended settings
◉ Which section in the Self-Help tool should be checked to start
investigating an updating issue on an endpoint Answer: System
◉ What does tamper protection prevent a user from doing on their
endpoint with Sophos Central agent installed? Answer: Prevents a
user from uninstalling the Sophos agent software
◉ TRUE or FALSE: All server protection features are enabled by
default. Answer: FALSE
◉ Which endpoint protection policy protects users against malicious
network traffic? Answer: Threat Protection