Administration of Symantec Secure Sockets Layer Visibility 5.0 Exam Prep
Free practice questions

Free 250-444 Practice Questions

10 exam-style questions with answers and explanations, straight from our 1,030-question bank. Tap an answer to check yourself. When you're ready, take the scored version in the free practice test.

Start the free practice test → ★★★★★4.9/5 from 2,400+ candidates · No signup

These 10 free 250-444 questions are organized by exam domain, so you can see how each part of the Administration of Symantec Secure Sockets Layer Visibility 5.0 blueprint is tested. Reveal the answer and explanation under each question.

Domain 1: Introduction to Encrypted Traffic Management

Question 1

SSLV has been passively decrypting a hosted application's traffic with the server's RSA private key. After a server-side cipher change, new full TLS 1.2 handshakes negotiate ECDHE_RSA. The server certificate and key pair are unchanged, and captures contain both directions without packet loss. Why is the installed private key now insufficient to recover the plaintext?

Show answer & explanation

Correct answer: B - RSA authenticates the exchange, but the session secrets depend on ephemeral key agreement.

Question 2

An origin-certificate validation record contains these results: Evaluation time: July 20, 2026, 12:00 UTC; appliance clock verified correct. Certificate validity ended: July 16, 2026, 23:59 UTC. Hostname match and trusted issuer chain: passed. OCSP: fresh, valid response reporting "good". No certificate-validation exception is authorized. Which handling is appropriate?

Show answer & explanation

Correct answer: B - Reject it because good revocation status does not override the expired validity period.

Domain 2: Introduction to SSLV Virtual Appliance

Question 3

A virtual switch supports port mirroring, but the SSLV VM receives only a mirror of the host's physical uplink. North-south sessions appear normally. Two application VMs on that host exchange TLS traffic entirely through the local virtual switch, and none of their packets reaches SSLV. Mirror-drop counters remain zero. Which change supplies the missing traffic without moving the applications?

Show answer & explanation

Correct answer: C - Mirror both directions of the application VMs' virtual-switch traffic to SSLV's monitoring vNIC.

Domain 3: Introducing Encrypted Traffic Management with SSL

Question 4

During a cabling change, an optional SSLV decrypted-copy output is accidentally connected to an office VLAN. An office host can now capture readable session tokens. The production inline IPS uses separate, correctly isolated links and must remain enforcing. The copy output has no return-path or forwarding dependency, and the engineer is authorized to disconnect it immediately. Which action contains the exposure while preserving required protection?

Show answer & explanation

Correct answer: D - Disconnect the mispatched copy cable from the office switch, leaving the inline IPS path intact.

Domain 4: Deploying the SSL Visibility Appliance

Question 5

A company wants a passive IDS to examine outbound TLS payloads without becoming a production-forwarding dependency. The IDS has no inline return interface. Managed clients trust the SSLV inspection CA. The installed SSLV supports active interception of the external servers' TLS 1.2/ECDHE connections with a decrypted copy output; those servers' private keys are unavailable. Select the arrangement that meets these constraints.

Show answer & explanation

Correct answer: A - Place SSLV inline for active decryption and send a plaintext copy to the passive IDS.

Domain 5: Migrating and Upgrading the SSLV

Question 6

Following an approved SSLV 3.9-to-4.3 migration, platform settings, policy activation, and list references verify correctly. Inbound inspection fails for a service whose required private key is absent. A verified, compatible PKI-only backup contains that key, and its restore password is available. Recovery must retain the new management address and inspection policy, which differ from the pre-migration configuration. How should the administrator restore the missing capability?

Show answer & explanation

Correct answer: A - Restore the compatible PKI-only backup and verify the service's certificate/private-key pair.

Domain 6: Exposing Encrypted Inbound SSL Traffic

Question 7

Inbound HTTPS terminates at a load balancer, which establishes a separate TLS connection to an application server. SSLV sits on the client-facing side of the load balancer and uses a supported active inbound mode requiring the service certificate and private key. Only the application server's credentials have been imported. The two TLS endpoints use different key pairs. For this inspection point, which credentials are missing?

Show answer & explanation

Correct answer: C - The load balancer's client-facing certificate and its matching private key.

Domain 7: Exposing Encrypted Outbound SSL Traffic

Question 8

On the same managed laptop, a browser successfully accesses an inspected HTTPS service, but an inventory client fails. Both use the same SSLV segment. The inventory client uses its own CA bundle and does not pin certificates. SSLV validates the origin successfully, but its session log records "Alert[C]: unknown CA" for the inventory connection. What change addresses the failed trust relationship?

Show answer & explanation

Correct answer: D - Add the inspection CA's public certificate to the inventory client's CA bundle.

Domain 8: Exposing Encrypted Threats for Forensic Analysis While Complying with Privacy Regulations

Question 9

Employees must retain access to benefits.example without decryption or plaintext recording. The host belongs to an approved private-host list and also to the Business Services inspection category. SSLV evaluates these rules by first match: the category decrypt rule currently precedes the private-host cut-through rule. Business Services hosts outside the private-host list must remain inspected. Choose the narrowest correction that satisfies all requirements.

Show answer & explanation

Correct answer: B - Move the approved private-host cut-through rule above the Business Services decrypt rule.

Domain 9: Offloading SSL Decryption for ProxySG Efficiency

Question 10

During a supported SSLV-ProxySG offload deployment, SSLV exposes selected outbound content and sends plaintext over the dedicated inspection link. A capture confirms that plaintext reaches ProxySG, but its receiving service still expects ordinary TLS handshakes. No matching proxy transaction completes. Client-facing and origin-facing TLS validation on SSLV both pass. Which change corrects the mismatch while retaining SSLV as the decryption offload engine?

Show answer & explanation

Correct answer: D - Configure the ProxySG receiving service for the supported SSLV offload handling.

The rest of the 250-444 blueprint

The 250-444 exam also covers these domains. Drill them in the full free practice test:

That's 10 of 1,030

The full bank has 1,020 more 250-444 questions with explanations.

Continue in the free practice test →

View plans