Page | 1
Sophos Engineer Exam Questions
With Complete Solutions
That the cloned policy has been enforced - correct answer-You
have cloned the threat protection base policy, applied the policy to
a group and saved it. When checking the endpoint, the policy
changes have not taken effect. What do you check in the policy
8190 - correct answer-Which TCP port is used to communicate
policies to endpoint?
To download updates from Sophos Central and store them on a
dedicated server on your network - correct answer-What is the
function of an update cache?
Download and run the installer from Sophos Central - correct
answer-Which of the following is a method of deploying endpoint
protection?
8191 - correct answer-Which TCP port is used to communicate
Updates on endpoint?
, Page | 2
False - correct answer-A message relay can be configured on a
Server without an Update Cache.
True - correct answer-When protecting a MAC client, you must
know the password of the administrator.
Connects to a cloud server to check for the latest information
about a file - correct answer-What is the function of live
protection?
To block specific applications from running on protected
endpoints - correct answer-Which is the function of Application
control?
To connect Sophos security solutions in real time - correct
answer-What is the function of Sophos Synchronized Security?
, Page | 3
Control access to websites based on their category - correct
answer-What is the function of Web Control?
To detect and stop compromised vulnerable applications - correct
answer-What is the function of anti-exploit technology?
Exploit technique detection - correct answer-Which feature of
intercept X is designed to detect malware before it can execute?
Data loss prevention rule - correct answer-You want to change an
action for 'confidential' content. Where in Sophos Central do you
make this change
False - correct answer-Base policies can be disabled in Sophos
Central.
Threat Protection - correct answer-You are detecting low-
reputation files and want to change the reputation level from
recommended to strict. Which policy do you edit to make this
change?
Sophos Engineer Exam Questions
With Complete Solutions
That the cloned policy has been enforced - correct answer-You
have cloned the threat protection base policy, applied the policy to
a group and saved it. When checking the endpoint, the policy
changes have not taken effect. What do you check in the policy
8190 - correct answer-Which TCP port is used to communicate
policies to endpoint?
To download updates from Sophos Central and store them on a
dedicated server on your network - correct answer-What is the
function of an update cache?
Download and run the installer from Sophos Central - correct
answer-Which of the following is a method of deploying endpoint
protection?
8191 - correct answer-Which TCP port is used to communicate
Updates on endpoint?
, Page | 2
False - correct answer-A message relay can be configured on a
Server without an Update Cache.
True - correct answer-When protecting a MAC client, you must
know the password of the administrator.
Connects to a cloud server to check for the latest information
about a file - correct answer-What is the function of live
protection?
To block specific applications from running on protected
endpoints - correct answer-Which is the function of Application
control?
To connect Sophos security solutions in real time - correct
answer-What is the function of Sophos Synchronized Security?
, Page | 3
Control access to websites based on their category - correct
answer-What is the function of Web Control?
To detect and stop compromised vulnerable applications - correct
answer-What is the function of anti-exploit technology?
Exploit technique detection - correct answer-Which feature of
intercept X is designed to detect malware before it can execute?
Data loss prevention rule - correct answer-You want to change an
action for 'confidential' content. Where in Sophos Central do you
make this change
False - correct answer-Base policies can be disabled in Sophos
Central.
Threat Protection - correct answer-You are detecting low-
reputation files and want to change the reputation level from
recommended to strict. Which policy do you edit to make this
change?