Administration of Symantec Security Analytics 8.0 Exam Prep
Free practice questions

Free ASSA80 Practice Questions

10 exam-style questions with answers and explanations, straight from our 1,030-question bank. Tap an answer to check yourself. When you're ready, take the scored version in the free practice test.

Start the free practice test → ★★★★★4.9/5 from 2,400+ candidates · No signup

The ASSA80 exam has 75 questions and runs 1 hours 30 minutes.

These 10 free ASSA80 questions are organized by exam domain, so you can see how each part of the Administration of Symantec Security Analytics 8.0 blueprint is tested. Reveal the answer and explanation under each question.

Domain 2: Describe the core architecture of Security Analytics, including virtual and hardware appliances

Question 1

A Security Analytics virtual appliance receives a physical-switch SPAN feed and captures Internet-bound traffic. Two application VMs on the same hypervisor exchange files entirely within a virtual switch, without using the physical uplink. The monitoring adapter already accepts delivered frames addressed to other MAC addresses. To observe this exchange without changing the applications' forwarding path, the administrator should:

Show answer & explanation

Correct answer: D - Mirror the internal virtual-switch traffic to the appliance's assigned capture adapter.

Domain 3: Describe the Symantec Security Analytics network architecture requirements, including the differences between network TAPs and SPAN ports

Question 2

After a routing change, Security Analytics shows client SYNs, subsequent client ACKs, and HTTP requests, but no server packets for the same connections. Application logs confirm successful responses. The SPAN session mirrors both directions of the monitored link, and no capture or search filter excludes the replies. Which explanation fits this combination of findings?

Show answer & explanation

Correct answer: B - The return traffic is taking a route that bypasses the monitored link.

Question 3

During a sustained replication job, a full-duplex link carries 700 Mb/s in one direction and 600 Mb/s in the other. SPAN copies both directions into a single 1 Gb/s monitor output feeding Security Analytics. Buffers cannot absorb sustained excess traffic. The sensor reports zero local packet drops. Which capacity assessment should govern the capture design?

Show answer & explanation

Correct answer: B - 1.3 Gb/s is offered; the mirror output cannot preserve every copied byte.

Domain 4: Describe how to configure Security Analytics deployment, including key options within both the CLI and web interface

Question 4

External sign-in to a Security Analytics deployment fails with a TLS certificate error: 'not yet valid.' Local sign-in works. The actual date is September 11, 2026. The identity service's certificate is valid from September 1, 2026, through August 31, 2027; its hostname and trust chain check out. The appliance console reports August 12, 2026. Which repair addresses the demonstrated cause?

Show answer & explanation

Correct answer: A - Correct the appliance clock and restore synchronization with its NTP source.

Question 5

HTTPS access to a Security Analytics appliance at 198.51.100.20 fails from an authorized Linux administration workstation. Another workstation on 192.0.2.0/24 can reach it. The affected workstation can reach router 192.0.2.1, which provides access to the appliance's subnet. The entire output of 'ip route show' is: 192.0.2.0/24 dev eth0 proto kernel scope link src 192.0.2.25 No policy routing is configured. Which correction addresses the fault shown?

Show answer & explanation

Correct answer: A - Configure a route to 198.51.100.0/24 via 192.0.2.1 on the affected workstation.

Domain 5: Describe how to perform basic and advanced filtering, create indicators, and apply recommended filtering best practices

Question 6

An analyst needs records from sensor Branch-2 with either of two destination IP addresses. The Boolean logic is written as: (sensor = Branch-2 AND destination = 198.51.100.10) OR destination = 198.51.100.20 Records for 198.51.100.20 are appearing from other sensors. Which replacement preserves both destinations while restricting every result to Branch-2?

Show answer & explanation

Correct answer: D - sensor = Branch-2 AND (destination = 198.51.100.10 OR destination = 198.51.100.20)

Question 7

A threat-intelligence notice identifies malware at https://updates.example.test/download/agent.exe. An IP-only indicator in Security Analytics also flags legitimate sites sharing that server address. An authorized decrypted feed exposes the hostname and full request path for the HTTPS requests. Which matching criterion stays closest to the specific evidence in the notice?

Show answer & explanation

Correct answer: B - Require the hostname updates.example.test and the exact request path /download/agent.exe to match together.

Domain 6: Describe the file extraction process, the resulting artifacts, and the purposes they serve

Question 8

A fully captured HTTP GET response contains these headers: HTTP/1.1 206 Partial Content Content-Range: bytes 4096-8191/32768 Content-Length: 4096 There is no content encoding or body transformation. Security Analytics recovers all 4,096 response-body bytes, but no other ranges are available. Their SHA-256 digest differs from the published digest of a complete 32,768-byte malicious file. What does this comparison establish?

Show answer & explanation

Correct answer: C - A fragment's digest cannot rule out a match between the complete original file and the malicious sample.

Domain 7: Describe the anatomy of a cyber-attack, the steps of the Cyber Kill Chain, and what makes up an Indicator of Compromise (IoC)

Question 9

An intrusion timeline shows a malicious executable downloaded at 09:10 and an unauthorized startup entry created at 09:12. At 09:14, Security Analytics captures the host retrieving attacker-issued instructions and acknowledging receipt. No data theft or destructive operation has yet been observed. In the seven-stage Cyber Kill Chain, the 09:14 exchange specifically demonstrates which stage?

Show answer & explanation

Correct answer: C - Command and Control

Domain 8: Describe threat hunting and incident response frameworks and procedures

Question 10

Security Analytics captures an ongoing transfer of payroll records from a workstation to an external server. The incident lead confirms that the transfer is unauthorized and approves endpoint isolation, which will block the workstation's network traffic without powering it off. The workstation has no safety-critical function. A complete packet export will take another 30 minutes. What should happen next?

Show answer & explanation

Correct answer: A - Isolate the workstation now and preserve the captured evidence in parallel.

The rest of the ASSA80 blueprint

The ASSA80 exam also covers these domains. Drill them in the full free practice test:

That's 10 of 1,030

The full bank has 1,020 more ASSA80 questions with explanations.

Continue in the free practice test →

View plans