QUESTIONS WITH ANSWERS RATED A+
✔✔What does HIPS do on a protected endpoint? - ✔✔Scans for potentially malicious
behaviour
✔✔You have cloned the threat protection base policy, applied the policy to a group and
saved it. When checking the endpoint, the policy changes have not taken effect. What
do you check in the policy? - ✔✔That the cloned policy has been enforced
✔✔In which 2 ways can you license the Enterprise Dashboard? - ✔✔(1) Master
Licensing
(2) Individual Licensing
✔✔What is the minimum administrative role that will allow a user to create and edit
policies? - ✔✔Admin
✔✔Complete the following sentence: The default protection base policy is configured
with... - ✔✔Sophos' recommended settings
✔✔Which section in the Self-Help tool should be checked to start investigating an
updating issue on an endpoint - ✔✔System
✔✔What does tamper protection prevent a user from doing on their endpoint with
Sophos Central agent installed? - ✔✔Prevents a user from uninstalling the Sophos
agent software
✔✔TRUE or FALSE: All server protection features are enabled by default. - ✔✔FALSE
✔✔Which endpoint protection policy protects users against malicious network traffic? -
✔✔Threat Protection
✔✔Which is the minimum administrative role that will allow a user to view alerts,
perform updates and scan endpoints? - ✔✔Help Desk
✔✔Your Enterprise Dashboard has been configured with multiple sub-estates. In which
2 ways can you manage the licenses associated with the sub-estates? - ✔✔(1) In the
sub-estate Central Admin Console
(2) In the Enterprise Dashboard
✔✔Threat search results are split into which 2 of the following. - ✔✔(1) Files
(2) Network
, ✔✔In which policy do you configure anti-virus scanning? - ✔✔Threat Protection
✔✔Which feature of Intercept X is designed to detect malware before it can execute? -
✔✔Exploit technique detection
✔✔True or False: You can choose to send email alerts immediately, hourly, daily or
never. - ✔✔True
✔✔An endpoint is reporting that Sophos AutoUpdate is not installed. In the Self-Help
Tool which tab do you check to view whether AutoUpdate is listed as installed? -
✔✔Installed components
✔✔A Windows endpoint installation is failing. It is detecting competitor software. Which
log file do you check to investigate this issue? - ✔✔avremove.log
✔✔How do users view quarantined emails and manage device encryption for their
protected endpoints? - ✔✔The Self-Service Portal
✔✔Which 2 of the following are the methods for bulk importing users? - ✔✔(1) Using
the Active Directory Sync Utility
(2) Import using a CSV file
✔✔You want to configure the login settings for all administrators to require two factors
of authentication. Which global setting do you enable? - ✔✔Multi-factor Authentication
✔✔When protecting a Mac client, you must know the password of the administrator. -
✔✔TRUE
✔✔What is the function of Data Loss Prevention? - ✔✔To monitor and restrict file
transfers containing sensitive data
✔✔For most detections, which clean-up process is used to clean up the detection? -
✔✔Automatic Clean Up
✔✔Which endpoint protection policy block access to malicious websites? - ✔✔Threat
Protection
✔✔What is the recommended way to allow a new application to a locked down server?
- ✔✔Add the path of the application to the server lockdown policy
✔✔Which security threat does Intercept X protect against? - ✔✔Ransomware