Administration of Symantec Cloud Workload Protection - R1 Exam Prep
Free practice questions

Free ASCWPR Practice Questions

10 exam-style questions with answers and explanations, straight from our 1,030-question bank. Tap an answer to check yourself. When you're ready, take the scored version in the free practice test.

Start the free practice test → ★★★★★4.9/5 from 2,400+ candidates · No signup

These 10 free ASCWPR questions are organized by exam domain, so you can see how each part of the Administration of Symantec Cloud Workload Protection - R1 blueprint is tested. Reveal the answer and explanation under each question.

Domain 1: Introduction to Cloud Workload Protection

Question 1

An audit finds that cloud storage resources allow public reads even though recent malware scans detected no malicious content. The team needs repeatable checks against approved cloud-resource access settings across its AWS and Azure accounts. Which capability fits that requirement?

Show answer & explanation

Correct answer: D - Cloud Workload Assurance, assessing the cloud accounts' resource configurations

Domain 2: Getting Started Using the Wizard

Question 2

The CWP Getting Started Wizard has connected to the intended cloud account and displays the expected instances. Connection permissions have been verified against the deployment requirements. On a target server, the agent installer stops before writing its files because the local operating-system account lacks installation privileges. What access change addresses this failure?

Show answer & explanation

Correct answer: C - Run the installer through an authorized host account with the required operating-system privileges.

Domain 3: Setup and Deployment of Agents

Question 3

Every night, an AWS application replaces its worker instances. Administrators installed CWP agents on Monday, but Tuesday's replacement workers appear in inventory without agents. The machine image contains no CWP agent. What change most directly prevents this recurring deployment gap?

Show answer & explanation

Correct answer: A - Run the supported agent installation during instance launch and verify each new registration.

Question 4

A CWP deployment pilot has two groups of Linux instances with the same distribution release but different kernels. The compatibility check accepts one kernel and rejects the other. Installation and protection tests pass on the accepted group. What is the appropriate rollout decision?

Show answer & explanation

Correct answer: A - Proceed with the accepted group; resolve the rejected group's kernel-agent compatibility.

Domain 4: Managing Policies

Question 5

An approved Windows reporting service can read its data but cannot create D:\Reports\Daily\summary.csv. NTFS permissions permit the service account to write. A CWP event identifies a Prevention rule as the source of the denial. Adding the output directory to malware-scan exclusions has not changed the result. Which correction addresses the blocking control?

Show answer & explanation

Correct answer: B - Amend the matching Prevention rule to permit the approved service's write.

Question 6

During an approved Group Policy release, CWP Detection reports a changed file under SYSVOL on a domain controller. The resulting hash, writer's account, and execution time match the authorized change record. Domain services are operating normally. The integrity baseline still contains the earlier file hash. How should this finding be handled?

Show answer & explanation

Correct answer: C - Update the approved baseline and retain the evidence of the authorized change.

Domain 5: Monitoring Cloud Workload Protection

Question 7

An operational readiness review covers 200 eligible workloads. CWP agents are installed on 180; 160 of those have fresh reports; 150 of the reporting workloads have every required engine active and the approved policies enforced. Launch approval requires at least 90% of all eligible workloads to satisfy every protection check. Which assessment should be presented to the launch owner?

Show answer & explanation

Correct answer: B - 75% are verified; 30 additional workloads must satisfy every protection check.

Question 8

A CWP vulnerability review identifies an installed product with a CVSS v3.0 Base score of 8.6. Investigators have not found evidence of exploitation. How should the finding be described?

Show answer & explanation

Correct answer: C - High severity, with exploitation requiring evidence separate from the score.

Domain 6: Managing Events

Question 9

The operations mailbox has received no CWP messages about repeated authentication failures. An administrator must distinguish a problem in alert evaluation from a problem in notification delivery. Which finding directs the investigation to the notification path?

Show answer & explanation

Correct answer: A - The matching alert exists, and its notification record reports unsuccessful delivery.

Domain 8: Cloud Workload Protection for Storage

Question 10

A document portal uses CWP for Storage near-real-time scanning of an Amazon S3 bucket and must not serve unexamined content. At 09:12, version v1 of contract.pdf receives a clean result. At 09:14, an authorized user uploads replacement content at the same key; version v2 is awaiting examination. A 09:15 download requests v2. Which release decision is supported by the available evidence?

Show answer & explanation

Correct answer: D - Keep v2 unavailable until examination of that version returns a clean result.

The rest of the ASCWPR blueprint

The ASCWPR exam also covers these domains. Drill them in the full free practice test:

That's 10 of 1,030

The full bank has 1,020 more ASCWPR questions with explanations.

Continue in the free practice test →

View plans