SOPHOS ENGINEER FINAL PAPER 2025/2026 QUESTIONS
WITH ANSWERS RATED A+
✔✔To connect Sophos security solutions in real time - ✔✔What is the function of
Sophos Synchronized Security?
✔✔Control access to websites based on their category - ✔✔What is the function of Web
Control?
✔✔To detect and stop compromised vulnerable applications - ✔✔What is the function of
anti-exploit technology?
✔✔Exploit technique detection - ✔✔Which feature of intercept X is designed to detect
malware before it can execute?
✔✔Data loss prevention rule - ✔✔You want to change an action for 'confidential'
content. Where in Sophos Central do you make this change
✔✔False - ✔✔Base policies can be disabled in Sophos Central.
✔✔Threat Protection - ✔✔You are detecting low-reputation files and want to change the
reputation level from recommended to strict. Which policy do you edit to make this
change?
✔✔Threat protection - ✔✔Which endpoint protection policy protects users against
malicious network traffic?
✔✔True - ✔✔TRUE or FALSE: Tamper protection must be disabled before removing
Endpoint protection.
✔✔Web Control - ✔✔Which endpoint protection policy do you edit to block users from
visiting a specific website category?
✔✔Threat Protection - ✔✔Which endpoint protection policy block access to malicious
websites?
✔✔False - ✔✔TRUE or FALSE: All Endpoints have the same endpoint password.
✔✔Application Control - ✔✔Which feature allows you to restrict application?
✔✔Check system requirement - ✔✔What is the first step you must take when deploying
virtual environments?
✔✔Servers or server group - ✔✔Server policies are only applied to ....
, ✔✔Files and registry entries - ✔✔Which 2 of the following are monitored when File
Integrity Monitoring is enabled?
✔✔SVM (Security Virtual Machine) & Guest Virtual Machine (GVM) - ✔✔Which 2
components are required for protecting virtual environments?
✔✔Avremove.log - ✔✔A Windows endpoint installation is failing. It is detecting
competitor software. Which log file do you check to investigate this issue?
✔✔Audit log - ✔✔Which log provides a record of all activities?
✔✔Automatic Clean up - ✔✔For most detections, which clean-up process is used to
clean up the detection?
✔✔Isolate the computer - ✔✔A malicious file has been detected on an endpoint and
you want to prevent lateral movement through your network. From the threat case,
which action do you take?
✔✔Management Communications - ✔✔You want to check an endpoint has received the
latest policy updates from Sophos Central. Which tab do you select in the Endpoint Self-
Help tool to view the last communication date and time?
✔✔Files, network - ✔✔threat search results are split into which 2 of the following?
✔✔Tool that identified where malicious files are written from - ✔✔The source of
infection clean up tool is..
✔✔Modifying protection settings, uninstalling the endpoint agent - ✔✔Which 2 of the
following does tamper protection prevent users from doing?
✔✔Installed Components - ✔✔An endpoint is reporting that Sophos AutoUpdate is not
installed. In the Self-Help Tool which tab do you check to view whether AutoUpdate is
listed as installed?
✔✔Super Admin - ✔✔What is the minimum administrative role that will allows a user to
manage roles and role assignments?
✔✔previously detected malware characteristics - ✔✔Signature-based file scanning
relies on...
✔✔Help Desk - ✔✔Which is the minimum administrative role that will allow a user to
view alerts, perform updates and scan endpoints
WITH ANSWERS RATED A+
✔✔To connect Sophos security solutions in real time - ✔✔What is the function of
Sophos Synchronized Security?
✔✔Control access to websites based on their category - ✔✔What is the function of Web
Control?
✔✔To detect and stop compromised vulnerable applications - ✔✔What is the function of
anti-exploit technology?
✔✔Exploit technique detection - ✔✔Which feature of intercept X is designed to detect
malware before it can execute?
✔✔Data loss prevention rule - ✔✔You want to change an action for 'confidential'
content. Where in Sophos Central do you make this change
✔✔False - ✔✔Base policies can be disabled in Sophos Central.
✔✔Threat Protection - ✔✔You are detecting low-reputation files and want to change the
reputation level from recommended to strict. Which policy do you edit to make this
change?
✔✔Threat protection - ✔✔Which endpoint protection policy protects users against
malicious network traffic?
✔✔True - ✔✔TRUE or FALSE: Tamper protection must be disabled before removing
Endpoint protection.
✔✔Web Control - ✔✔Which endpoint protection policy do you edit to block users from
visiting a specific website category?
✔✔Threat Protection - ✔✔Which endpoint protection policy block access to malicious
websites?
✔✔False - ✔✔TRUE or FALSE: All Endpoints have the same endpoint password.
✔✔Application Control - ✔✔Which feature allows you to restrict application?
✔✔Check system requirement - ✔✔What is the first step you must take when deploying
virtual environments?
✔✔Servers or server group - ✔✔Server policies are only applied to ....
, ✔✔Files and registry entries - ✔✔Which 2 of the following are monitored when File
Integrity Monitoring is enabled?
✔✔SVM (Security Virtual Machine) & Guest Virtual Machine (GVM) - ✔✔Which 2
components are required for protecting virtual environments?
✔✔Avremove.log - ✔✔A Windows endpoint installation is failing. It is detecting
competitor software. Which log file do you check to investigate this issue?
✔✔Audit log - ✔✔Which log provides a record of all activities?
✔✔Automatic Clean up - ✔✔For most detections, which clean-up process is used to
clean up the detection?
✔✔Isolate the computer - ✔✔A malicious file has been detected on an endpoint and
you want to prevent lateral movement through your network. From the threat case,
which action do you take?
✔✔Management Communications - ✔✔You want to check an endpoint has received the
latest policy updates from Sophos Central. Which tab do you select in the Endpoint Self-
Help tool to view the last communication date and time?
✔✔Files, network - ✔✔threat search results are split into which 2 of the following?
✔✔Tool that identified where malicious files are written from - ✔✔The source of
infection clean up tool is..
✔✔Modifying protection settings, uninstalling the endpoint agent - ✔✔Which 2 of the
following does tamper protection prevent users from doing?
✔✔Installed Components - ✔✔An endpoint is reporting that Sophos AutoUpdate is not
installed. In the Self-Help Tool which tab do you check to view whether AutoUpdate is
listed as installed?
✔✔Super Admin - ✔✔What is the minimum administrative role that will allows a user to
manage roles and role assignments?
✔✔previously detected malware characteristics - ✔✔Signature-based file scanning
relies on...
✔✔Help Desk - ✔✔Which is the minimum administrative role that will allow a user to
view alerts, perform updates and scan endpoints