Arrow Electronics, Inc.

Symantec Data Loss Prevention 15.x Administration

CODE: SYM_000223

LENGTH: 40 Hours (5 days)

PRICE: kr42 000,00


The Symantec Data Loss Prevention 15.x Administration
course is designed to provide you with the fundamental
knowledge to configure and administer the Symantec
Data Loss Prevention Enforce platform. The hands-on
labs include exercises for configuring the Enforce server,
detection servers, and DLP agents; creating policies;
detecting and responding to incidents; performing
incident reporting; and administering users and roles.
You are introduced to the following Symantec Data Loss
Prevention products: Network Monitor, Network Prevent,
Network Discover, Network Protect, Cloud Storage
Discover, Cloud Service for Email, Endpoint Prevent,
and Endpoint Discover.
Note: This course is delivered on a Microsoft Windows


By the end of this course, you will be able to configure
and use Symantec Data Loss Prevention 15.x.


Module 1: Data Loss Prevention Landscape

  • Data Loss Prevention landscape
  • Data loss risk management
  • Data Loss Prevention real-world use cases

Module 2: Overview of Symantec Data Loss


  • Symantec Data Loss Prevention Suite
  • Symantec Data Loss Prevention architecture

Module 3: Identifying and Describing

Confidential Data

  • Identifying confidential data
  • Configuring Symantec Data Loss Prevention to recognize confidential data

  • Described Content Matching (DCM)
  • Exact matching (EDM and EMDI)
  • Indexed Document Matching (IDM)
  • Vector Machine Learning (VML)
  • Sensitive Image Recognition
  • Custom file type detection
  • Hands-On Labs: Tour the Enforce console, create policy groups, configure policies for Personally Identifiable Information (PII) detection, configure a policy for PCI compliance, configure a policy to protect confidential documents, configure a policy to protect source code, configure a policy for Form Recognition, use a template to add a DLP policy, export policies for use at a Disaster Recovery (DR) site, configure Optical Character Recognition (OCR)

Module 4: Locating Confidential Data

Stored on Premises and in the Cloud

  • Determining where to search for confidential data
  • Locating confidential data on corporate repositories
  • Locating confidential data in the Cloud
  • Locating confidential data on endpoint computers
  • Hands-On Labs: Run a Content Enumeration Scan, scan a Windows target, scan endpoint computers for confidential data, scan a server for confidential data using Exact Match Data Identifiers (EMDI), configure a global policy for PII compliance

Module 5: Understanding How Confidential

Data is Being Used

  • Monitoring confidential data moving across the network
  • Monitoring confidential data being used on endpoint computers
  • Hands-On Labs: Configure Network Prevent for Email to monitor SMTP messages, use Network Prevent or Email to monitor SMTP messages, monitor Endpoint activity

Module 6: Educating Users to Adopt Data

Protection Practices

  • Implementing corporate training on data protection policies
  • Providing notifications of user policy violations
  • Hands-On Labs: Configure the Active Directory lookup plugin, configure email notifications, configure onscreen notifications

Module 7: Preventing Unauthorized

Exposure of Confidential Data

  • Using response rules to prevent the exposure of confidential data
  • Protecting confidential data in motion
  • Protecting confidential data in use
  • Protecting confidential data at rest
  • Hands-On Labs: Configure SMTP blocking, test Optical Character Recognition (OCR) and the "HIPAA and HITECH (including PHI)" policy, configure endpoint blocking, configure endpoint User Cancel, scan and quarantine files on a server file share target, scan and quarantine files on an endpoint target

Follow on courses

  •  Symantec Data Loss Prevention 15.5 Planning and
  •  Symantec Data Loss Prevention 15.5 Policy
    Authoring and Incident Remediation

Test and Certification

250-533: Administration of Symantec Data Loss
Prevention 15.5

Session Dates