SOPHOS CERTIFIED ENGINEER EXAM
LATEST VERSION 100+ QUESTIONS AND
VERIFIED CORRECT ANSWERS SCORE A+
AT FIRST ATTEMPT
A malicious file has been detected on an endpoint and you want to prevent lateral movement through your network. From the threat case, which action do you take? - Correct AnswerIsolate the computer
A Windows endpoint installation is failing. It is detecting competitor software. Which log file do you check to investigate this issue? - Correct Answeravremove.log
An endpoint is reporting that Sophos AutoUpdate is not installed. In the Self-Help Tool which tab do you check to view whether AutoUpdate is listed as installed? - Correct AnswerInstalled components
Complete the following sentence: The default protection base policy is configured with... - Correct AnswerSophos' recommended settings
Complete the sentence: Server policies are only applied to... - Correct AnswerServers or server groups
Complete the sentence: Signature-based file scanning relies on... - Correct
Answerpreviously detected malware characteristics
Complete the sentence: The SAV32CLI clean-up tool is a... - Correct AnswerCommand line tool included in Sophos Central installation
Complete the sentence: The Source of Infection clean up tool is a... - Correct
AnswerTool that identified where malicious files are written from
Complete the sentence: The Virus Removal clean up tool is a... - Correct
AnswerSeparate download that detects and removes malware
For most detections, which clean-up process is used to clean up the detection? - Correct AnswerAutomatic Clean Up
How do users view quarantined emails and manage device encryption for their protected endpoints? - Correct AnswerThe Self-Service Portal
How do you access a managed Sophos Central account to resolve alerts for your customer? - Correct AnswerLogin using the Launch Sophos Central Admin button in the Partner Dashboard
- / 2
How long are activities stored for in the Enterprise Dashboard? - Correct Answer90 days
In which 2 ways can you license the Enterprise Dashboard? - Correct Answer(1) Master Licensing (2) Individual Licensing
In which policy do you configure anti-virus scanning? - Correct AnswerThreat Protection
In which policy do you enable deep learning? - Correct AnswerThreat Protection
In which policy do you enable device isolation? - Correct AnswerThreat Protection
The option to stop the AutoUpdate service is greyed out in Windows Services. What is the most likely reason for this? - Correct AnswerTamper Protection is enabled
Threat search results are split into which 2 of the following. - Correct Answer(1) Files (2) Network
TRUE or FALSE: A Message Relay can be configured on a Server without an Update
Cache. - Correct AnswerFALSE
TRUE or FALSE: All Endpoints have the same endpo password. - Correct
AnswerFALSE
TRUE or FALSE: All Endpoints have the same tamper protection password. - Correct AnswerFALSE
TRUE or FALSE: All server protection features are enabled by default. - Correct
AnswerFALSE
TRUE or FALSE: Base policies can be disabled in Sophos Central. - Correct
AnswerFALSE
TRUE or FALSE: Deleting an endpoint in Sophos Central will remove the Endpoint
agent from the endpoint. - Correct AnswerFALSE
True or False: Marking an alert as acknowledge will resolve the threat on the endpoint.
- Correct AnswerFALSE
True or False: Multi-factor authentication is enabled by default for all Enterprise Administrators. - Correct AnswerTRUE
True or False: Multi-factor authentication is enabled by default for all Enterprise Administrators. - Correct AnswerTRUE
- / 2