Sophos Technician Exam with correct
answers
Where can the AD Sync tool be obtained from? - correct answer -Global Settings
Which of the following statements is TRUE for a C2/Generic-C detection? - correct
answer -The connection was blocked but the root cause has NOT been cleaned up
Where in the Endpoint Self Help Tool will show if an endpoint is using a proxy for
updating? - correct answer -Update > Update configuration
When configuring AD synchronization, what location was defined by default in filters
under the User Discovery Filters tab? - correct answer -DC=SOPHOS,DC=LOCAL
Enter the command you would use to test IP network connectivity to the address
172.16.2.20. _____ - correct answer -ping 172.16.2.20
Which feature would protect the Sophos installation from becoming disabled by
malware? - correct answer -Tamper Protection
AD Sync is not working, you have successfully pinged the DC by both name and IP
address. Which port do you use with telnet to confirm the LDAP port is accessible? -
correct answer -389
Enter the command you would use to remove the currently configured system
proxy. - correct answer -netsh winhttp reset proxy
Where is the 'SophosCloudInstaller_<time_and_date_stamp>.log' found? - correct
answer -%ProgramData%\Sophos\CloudInstaller\Logs
What is the function of application lockdown in Intercept X? - correct answer -To
prevent malicious behavior in software
, Which of these cleanup tools will scan for root kits? - correct answer -Virus Removal
tool
What is the minimum type of user required to connect to AD to gather the user and
group information? - correct answer -Domain user
TRUE or FALSE: Sophos recommends disabling HTTPS inspection for Sophos
updating traffic. - correct answer -True
On a Windows computer, which component logs information to the 'Sophos.log' file?
- correct answer -Sophos Intercept X
The Central Admin Dashboard shows that none of your endpoints are using one of
your update caches. When pinging the update cache by name it fails. What
command do you use to investigate this further? - correct answer -nslookup
What is the third step of the troubleshooting process? - correct answer -Resolve and
verify
By default, computers get the latest Sophos product updates automatically, where
can an admin change this to allow control over updates? - correct answer -Global
settings > Controlled Updates
In which 3 ways can you allow a quarantined file to be restored? - correct answer -
SHA-256
The file paths
The certificate
When investigating an updating issue on one of your endpoints, you used the telnet
command to connect to dci.sophosupd.com on port 443. This confirmed that there
is a problem using a direct connection. What is most likely to be causing this? -
correct answer -Windows client firewall blocking traffic
Which 3 of the following are required to perform troubleshooting on an endpoint?
Choose three (3). - correct answer -Ability to disable Tamper Protection
The benefits of buying summaries with Stuvia:
Guaranteed quality through customer reviews
Stuvia customers have reviewed more than 700,000 summaries. This how you know that you are buying the best documents.
Quick and easy check-out
You can quickly pay through credit card or Stuvia-credit for the summaries. There is no membership needed.
Focus on what matters
Your fellow students write the study notes themselves, which is why the documents are always reliable and up-to-date. This ensures you quickly get to the core!
Frequently asked questions
What do I get when I buy this document?
You get a PDF, available immediately after your purchase. The purchased document is accessible anytime, anywhere and indefinitely through your profile.
Satisfaction guarantee: how does it work?
Our satisfaction guarantee ensures that you always find a study document that suits you well. You fill out a form, and our customer service team takes care of the rest.
Who am I buying these notes from?
Stuvia is a marketplace, so you are not buying this document from us, but from seller Lectphilip. Stuvia facilitates payment to the seller.
Will I be stuck with a subscription?
No, you only buy these notes for $13.99. You're not tied to anything after your purchase.