Browse all practice questions for the Sophos Certified Technician Practice Exam. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

Ace the 2026 Sophos Certified Technician Challenge – Level Up Your Cybersecurity Skills! course image
More practice questions

These questions are part of the practice quiz. Start practicing

  • When investigating an updating issue on your endpoint, if telnet to dci.sophosupd.com on port 443 shows a problem, what is most likely causing this?
  • How would you test IP network connectivity to the address 172.16.2.20?
  • Is it possible to recover the Tamper Protection password for a deleted endpoint in Sophos Central?
  • What log would you check to confirm that the endpoint is able to reach the update cache during a failed update investigation?
  • What command is entered to run SophosZap?
  • What is the benefit of using Sophos Cloud Optix?
  • What permissions does a user need to connect to Active Directory to gather user and group information?
  • What is the role of the Sophos Security Heartbeat?
  • Which of the following best describes the concept of compliance status reporting?
  • How can an organization monitor its network using Sophos?
  • Which Sophos technology provides visibility over encrypted traffic?
  • What does the error 'copy from upstream failed: Cannot write resource' typically indicate?
  • In case of a failed software update, what is one potential cause to investigate?
  • What is the main purpose of logging features in Sophos Firewall?
  • What is the role of a quarantine in data security?
  • Which of the following is not a part of the compliance reporting in Sophos?
  • Which command tests a connection to srv.sophos.local on TCP port 8191?
  • Why is selecting a datacentre location important when setting up accounts?
  • Which application can be used to disable Tamper Protection?
  • Which of the following statements correctly describes a Message Relay?
  • Which of the following statements is TRUE for a C2/Generic-B detection?
  • When troubleshooting, which step follows verifying the problem?
  • True or False: Sophos recommends disabling HTTPS inspection for MCS traffic.
  • What command would you use to test the default SSL LDAP port for Active Directory synchronization?
  • What type of updates does the Endpoint Self Help Tool manage?
  • Is Tamper Protection enabled by default in Sophos Central?
  • TRUE or FALSE: Only PE files can be restored from SafeStore through the user interface?
  • What feature protects Sophos processes and settings from unauthorized changes?
  • In which two places can you create a forensic snapshot?
  • What command would you use to resolve the IP address of srv.sophos.local and test connectivity simultaneously?
  • What benefits does data encryption offer in Sophos solutions?
  • Which command is used to set the boot mode to safe boot with network on Windows?
  • At what interval does AutoUpdate check for software and updates after its initial check?
  • Which tool is primarily used by Sophos for monitoring endpoint devices?
  • What should you do to disable the new Threat Protection policy you added for testing?
  • If the Windows Firewall service is not active during Update Cache deployment, what needs to be done to resolve the issue?
  • What type of credentials are required for AD Sync in Sophos Central?
  • What is a critical preventive measure for safeguarding the Sophos installation from malware threats?
  • What information is typically configured in the Update section of the Endpoint Self Help Tool?
  • What is the primary function of a Message Relay in a network?
  • In terms of reporting, what does Sophos focus on to ensure operational compliance?
  • Where is automatic self-isolation enabled in Sophos?
  • You have configured and run AD Sync. You notice a user that is present in AD is missing from Central. What is the first step in troubleshooting this issue?
  • Which statement is TRUE about alerts in Sophos?
  • What is the primary function of CryptoGuard?
  • What additional instruction must you add to the command 'ipconfig' to clear the DNS cache?
  • Which technologies are integrated into Sophos Intercept X to stop malware?
  • Enter the additional instruction that must be added to the command 'ipconfig' to view all IP settings for a computer:
  • By default, computers get the latest Sophos product updates automatically, where can an admin change this to allow control over updates?
  • What does the acronym MCS stand for in the context of the Sophos Agent Service?
  • What types of malware does Sophos Antivirus primarily protect against?
  • What is the term for an attack that uses techniques that anti-virus does not yet detect?
  • What key aspect does Sophos emphasize in its endpoint monitoring?
  • Select which 2 of the following statements are TRUE about MCS?
  • What is a potential consequence of disabling Tamper Protection?
  • What action should be taken if Sophos detects unresolved connections?
  • What feature of Sophos Firewall helps in detecting unauthorized access?
  • What capability does improved endpoint detection and response (EDR) provide?
  • What does PUA stand for in the context of cybersecurity?
  • What does Sophos recommend for effective security management?
  • What types of communication protocols can be secured by Sophos?
  • What is the main benefit of selecting a data center close to your location when setting up Sophos Central?
  • Which feature of Sophos is employed to protect against phishing attacks?
  • From where can the Active Directory Sync tool be obtained?
  • How do you implement Sophos updates on endpoints?
  • How can users enable Self-Service features in Sophos?
  • What protocols does Sophos XG Firewall support for VPN services?
  • What is the primary function of the nslookup tool?
  • Which switch can be used with SophosSetup.exe to point to the name and location of a custom catalog file?
  • What command is used to remove the currently configured system proxy?
  • How many executions of SophosZap are required to complete removal of Sophos Endpoint?
  • What functionality does Sophos’ mobile security offer?
  • Can all the default policies in Sophos Central be disabled?
  • What challenges does Sophos Endpoint Detection and Response (EDR) address?
  • What does Sophos’ web filtering feature block?
  • Which tool would you use to remove stubborn malware that is associated with rootkits?
  • Why is it essential to regularly update Sophos components?
  • Which of these is a critical step after modifying the Windows Registry?
  • What is the first step before using SophosZap to uninstall Sophos Endpoint?
  • Should C:\TEMP ever be whitelisted in Sophos Central?
  • What is the benefit of using Sophos Synchronized Security?
  • What is the purpose of the Central Dashboard in Sophos Central?
  • What is the purpose of device control in security settings?
  • What two actions would allow a single user to change protection settings on their endpoint?
  • Which of the following is a feature of Sophos Central?
  • TRUE or FALSE: A single instance of AD Sync can synchronise from multiple domains in a forest?
  • Which statement is true regarding a C2/Generic-A detection?
  • What does Synchronized Security Lateral Movement Protection use to identify endpoints that have a red health status?
  • Which command in the context of network configuration shows the existing proxy settings?
  • In which scenario would you most likely use the 'Diagnose' feature in Sophos?
  • Which cleanup tool is specifically designed to scan for root kits?
  • Which Sophos product is used for web filtering and security?
  • Which additional instruction must be added to the command 'ipconfig' to display the contents of the DNS cache?
  • How does Sophos Intercept X enhance endpoint security?
  • Which of the following statements is TRUE regarding a C2/Generic-C detection?
  • What can be monitored via the Sophos Central API?
  • What does the Virus Removal Tool focus on?
  • What does policy validation in Sophos help to ensure?
  • What kind of reports can be generated through Sophos Central?
  • Is it possible for users to override self-isolation through Sophos Endpoint?
  • Which tool do you use to verify the Active Directory sync schedule?
  • What is a common symptom of rootkit infections?
  • What is the first step of the troubleshooting process?
  • What is the significance of security policies in Sophos?
  • Which tool helps in managing threat cases within Sophos?
  • How does Sophos detect advanced persistent threats (APTs)?
  • Before bulk deploying Sophos Central using a startup script in GPO, what is the necessary step?
  • How does Sophos Central help in managing endpoints?
  • How does Sophos track endpoint devices on a network?
  • Which switch will prevent the installer from being displayed during a scripted deployment?
  • How does Sophos address insider threats?
  • How does Sophos categorize user access and permissions?
  • What is a primary function of the Sophos Central API?
  • How can the Competitor Removal Tool be modified to remove software that has not been detected?
  • What is the second step of the troubleshooting process?
  • What does Sophos provide in response to security incidents?
  • Which portable executable (PE) files will be returned when a threat search is launched?
  • Why might the status 'Last time updated from cache' show as 'in a year'?
  • Where can you find detailed information about a specific threat?
  • What is the purpose of Sophos’ Advanced Threat Protection?
  • What type of traffic is allowed when an endpoint is in self isolation mode?
  • Which tool can be used for analyzing network performance in Sophos?
  • What is the primary function of the Sophos Update Cache?
  • Which Windows service must be disabled when recovering a tamper protected endpoint?
  • What search criteria do you enter to identify an updating issue in the SophosUpdate.log?
  • What security feature is used in Sophos Firewall to protect from DDoS attacks?
  • What feature allows Sophos Endpoint to rollback ransomware changes?
  • What are some key notable features of Sophos Central?
  • TRUE or FALSE: AD sync needs to be installed on a DC?
  • What is the role of Sophos' Anti-Ransomware technology?
  • What is a major benefit of using audit logs in Sophos?
  • The Central Admin Dashboard shows that none of your endpoints are using one of your update caches. What command do you use to investigate this?
  • Which Sophos product is designed to block unwanted applications?
  • What type of encryption does Sophos use to protect sensitive data in transit?
  • Where can you find SafeStore quarantine folders on a Windows Endpoint? Choose two.
  • What kind of updates does Sophos provide to prevent new threats?
  • You suspect an issue with your Update Cache. Which 2 logs do you need to examine? Choose two.
  • What is often an outcome of effective incident response in Sophos?
  • How frequently should Sophos systems be configured for optimal performance?
  • What type of logs does Sophos maintain to assist with compliance?
  • Which component is crucial for diagnosing issues with an endpoint?
  • Can you deploy a Message Relay without an Update Cache?
  • How does Sophos act upon detected vulnerabilities in systems?
  • What value data should be entered in the Windows Registry to disable the Sophos MCS Agent Service?
  • In a Windows computer, which component is responsible for logging details into the 'Sophos.log' file?
  • How does Sophos CASB enhance cloud security?
  • What command is used to clear the DNS cache on a Windows machine?
  • What are the two primary functions of Sophos Clean?
  • Is all quarantined data encrypted in SafeStore?
  • Which of the following statements about user permissions in Sophos Central is correct?
  • What information does the Sophos Diagnostic Utility provide?
  • What does Sophos’ Web Filtering allow administrators to do?
  • How does Sophos’ Phish Threat feature help organizations?
  • What role does activity reporting play in Sophos compliance management?
  • Where is the AD sync log location?
  • What key aspect does Sophos’ Advanced Threat Protection utilize for threat detection?
  • If an installation of Sophos Central failed on a Windows computer, which log file should you refer to first?
  • What is the function of Safe Browsing in Intercept X?
  • What alerts may indicate a compromised endpoint in Sophos?
  • Which of the following Windows tools do you use to display the route taken to reach a networking destination?
  • Can the default Update Cache TCP port of 8191 be modified?
  • Which feature of Sophos provides protection against unauthorized access to data?
  • What command is used to display the current configuration of the system proxy?
  • What port number does a Message Relay use?
  • When setting up a new Sophos Central account, which of the following datacentre locations can you select? Choose three.
  • What does Sophos Managed Threat Response do?
  • What encryption standard does Sophos Full Disk Encryption use?
  • Which two methods provided by Sophos display the status of all Sophos services on Windows computers?
  • From which two locations can you run the Windows version of the Sophos Diagnostic Utility?
  • Where can you find information about whether an endpoint is using a proxy for updating?
  • What is the primary purpose of the Endpoint Self Help Tool?
  • What is the role of endpoint detection and response (EDR) in malware protection?
  • In which three ways can you allow a quarantined file to be restored?
  • What is the primary function of Sophos' Endpoint Protection client?
  • What is the function of application lockdown in Intercept X?
  • True or False: The Sophos Diagnostic Utility is available for Windows endpoints only.
  • How does Sophos integrate with third-party security solutions?
  • What output formats are supported by the SDR Exporter Tool?
  • What is one of the primary functions of the Virus Removal Tool?
  • What is the role of a Sophos Central policy?
  • What is the primary function of Sophos Email Gateway?
  • Which installer runs the Competitor Removal Tool (CRT)?
  • Which feature protects the Sophos installation from being disabled by malware?
  • What is the minimum type of user required to connect to Active Directory to gather user and group information?
  • Where is the 'SophosCloudInstaller_.log' file found?
  • What command resolves the IP address of srv.sophos.local and shows the DNS server providing the resolution?
  • Which three are required to perform troubleshooting on an endpoint?
  • What feature does Sophos provide to mitigate risks from unverified applications?
  • When clearing the local AutoUpdate cache, which two folders need to be renamed?
  • To confirm the LDAP port when AD Sync is not working, which port should you use with telnet?
  • What is a key function of Sophos XG Firewall?
  • What is the recommended policy setting for endpoint protection?
  • What feature allows Sophos to effectively identify and respond to data breaches?
  • Why is it essential to apply updates and patches across a network?
  • Which of the following Windows tools do you use to test IP network connectivity?
  • What is the common reason for using telnet to troubleshoot AD Sync?
  • What reporting features are essential for compliance management in Sophos?
  • What can a server policy for Threat Protection in Sophos Central be assigned to?
  • What should you do if your endpoint is not updating correctly?
  • What is the primary goal of incident response within the context of Sophos?
  • If a user needs to adjust the Tamper Protection settings, which option grants them access?
  • Which Windows tool is used to resolve IP addresses to hostnames and vice versa?
  • How long can you override the Sophos Central policy when troubleshooting an endpoint?
  • What are the three actions available following a threat search?
  • What must be enforced to modify settings for scheduled scanning in a cloned threat protection base policy?
  • What is the most likely reason the option to stop the AutoUpdate service is greyed out in Windows Services?
  • What role does managed threat response play in Sophos solutions?
  • How often should security policies be reviewed in Sophos?
  • What type of data is captured by Sophos' active threat response feature?
  • You wish to uninstall Sophos Endpoint software from a Windows 10 computer, but Tamper Protection is enabled. Which two methods are supported for removal?
  • Which Sophos product is specifically designed for email protection?
  • Can you deploy an update cache without a Message Relay?
  • When configuring Active Directory synchronization, what location is defined by default in filters under the User Discovery Filters tab?
  • What is the role of the Sophos Central Management platform?
  • Which of the following can indicate a potential malware infection?
  • What is a notable benefit of Sophos’ Sandbox technology?
  • Which Sophos product provides real-time antivirus protection?
  • True or False: AD Sync will delete groups and users with no Central Admin role when they are no longer present in the search results?
  • Which Windows tool would you use to display the network configuration?
  • How frequently should compliance reports be reviewed to maintain effectiveness in Sophos?
  • What is the third step of the troubleshooting process?
  • What is the value of deploying Endpoint Detection and Response (EDR) capabilities?
  • What is the primary purpose of Sophos Endpoint Protection?
  • Which user access method is implemented by Sophos?
  • Which type of files does Sophos Antivirus scan by default?
  • When would it be necessary to perform manual cleanup on a detected threat?
  • What action can be taken to allow access to a desired site that is blocked by Web Control without allowing access to all sites in the same category?
  • Which Windows tool is used to test connectivity to a specific port or service?
  • What does the AD Sync utility primarily focus on?
  • What is essential for the effectiveness of Sophos managed threat response?
  • Where is the location of AutoUpdate's warehouse on a protected endpoint?
  • Where can you find the option to check if an endpoint is using a proxy for updating in the Endpoint Self Help Tool?
  • How does Sophos manage endpoint compliance?
  • Which statement is true for API Credentials?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy