Master 2021 Latest The Questions VMware Carbon Black EndPoint Protection 2021 and Pass 5V0-91.20 Real Exam! [Q11-Q26]

Share

Master 2021 Latest The Questions VMware Carbon Black EndPoint Protection 2021 and Pass 5V0-91.20  Real Exam!

Penetration testers simulate 5V0-91.20 exam PDF

NEW QUESTION 11
Carbon Black App Control maintains an inventory of all interesting (executable) files on endpoints where the agent is installed.
What is the initial inventory procedure called, and how can this process be triggered?

  • A. Initialization; move agent out of Disabled mode
  • B. Discovery; place agent into Disabled mode
  • C. Inventorying; enable Discovery mode
  • D. Baselining; install the agent

Answer: C

 

NEW QUESTION 12
An administrator viewed and filtered the results of a completed query within the User Interface for Audit and Remediation. The administrator exported the results to create charts and other visuals for reporting. When viewing the exported results, the administrator noticed some results were missing from the data set.
Why did the administrator not have the full data set from the query?

  • A. Export was used prior to the query completing, and some data is missing.
  • B. Export is limited to the first hundred rows, and the query had more rows than supported.
  • C. Export applies to the data visible in the UI; filtering will impact the viewable data.
  • D. Export pulls all results; the query must not have covered all data required.

Answer: A

 

NEW QUESTION 13
An administrator has updated a Threat Intelligence Report by turning it into a watchlist and needs to disable (Ignore) the old Threat Intelligence Report.
Where in the UI is this action not possible to perform?

  • A. Threat Report Page
  • B. Threat Intelligence Feeds Page
  • C. Search Threat Reports Page
  • D. Triage Alerts Page

Answer: B

 

NEW QUESTION 14
A security policy states to enable Live Response by default across the enterprise. However, the team identified critical systems which should not support Live Response due to risk. The team needs to disable Live Response on selected systems.
From which page can this goal be accomplished?

  • A. Endpoints
  • B. Roles
  • C. API Access
  • D. Policy

Answer: B

 

NEW QUESTION 15
Which two statements are true about Carbon Black alerts? (Choose two.)

  • A. Once dismissed, the action cannot be undone.
  • B. They can be grouped together.
  • C. Once received, it can be dismissed in bulk.
  • D. They are stored for 15 days.
  • E. Carbon Black does not generate alerts.

Answer: D,E

 

NEW QUESTION 16
An administrator observes the following event detail in the Investigate tab for an application with an unknown reputation making network connections:

Upon further review of the event details returned, the reputation is observed as NOT_LISTED, and the applied (cloud) reputation is UNKNOWN.
Why is the applied (cloud) reputation UNKNOWN and not NOT_LISTED?

  • A. NOT_LISTED was applied by the sensor after observing no cloud reputation, as evidenced by the applied cloud reputation UNKNOWN.
  • B. The sensor demoted the local reputation from UNKNOWN to NOT_LISTED based on the coud reputation.
  • C. The application was UNKNOWN at the time of the event but then later determined to be NOT_LISTED.
  • D. The sensor demoted the local reputation from NOT_LISTED to UNKNOWN based on the cloud reputation.

Answer: C

 

NEW QUESTION 17
Which enforcement level does not block unapproved files but will block files that have been specifically banned?

  • A. Disabled
  • B. Low Enforcement
  • C. Visibility
  • D. Medium Enforcement

Answer: A

Explanation:
Explanation
The protection level applied to computers running the App Control
Agent. A range of levels from High (Block Unapproved) to None
(Disabled) enable you to specify the level of file blocking required.

 

NEW QUESTION 18
An analyst has investigated two alerts on two separate HR workstations and found that notepad.exe has established communication to another IP address.
Which rule will kill notepad.exe entirely if this activity is detected in the future?

  • A. **/system32/notepad.exe --> Runs or is Running --> Terminate process
  • B. **\system32\notepad.exe --> Runs or is Running --> Deny operation
  • C. **\system32\notepad.exe --> Communicates over the network --> Terminate process
  • D. **/system32/notepad.exe--> Communicates over the network --> Deny operation

Answer: A

 

NEW QUESTION 19
An analyst has investigated multiple alerts on a number of HR workstations and found that java.exe is attempting to PowerShell. Of the Windows workstations in question, the analyst has also found that Java is installed in multiple locations. The analyst needs to block java.exe from this type of operation.
Which rule meets this need?

  • A. **\java.exe -> Invokes a command interpreter -> Deny operation
  • B. **\Program Files\*\java.exe -> Invokes a command interpreter -> Terminate process
  • C. **/java.exe -> Invokes an untrusted process -> Terminate process
  • D. **/Program Files/*/java.exe-> Invokes an untrusted process -> Deny operation

Answer: B

 

NEW QUESTION 20
An administrator receives an alert with the TTP DATA_TO_ENCRYPTION.
What is known about the alert based on this TTP even if other parts of the alert are unknown?

  • A. A process attempted to delete encrypted data on the disk.
  • B. A process attempted to write a file to the disk.
  • C. A process attempted to modify a monitored file written by the sensor.
  • D. A process attempted to transfer encrypted data on the disk over the network.

Answer: B

 

NEW QUESTION 21
What is the meaning, if any, of the event Report write (removable media)?

  • A. A Policy's device control setting 'Block writes to unapproved removable media' is set to Report Only. The event details show the process, file name, and hash modified or deleted on the removable media.
  • B. A Policy's device control setting 'Block writes to unapproved removable media' is set to Report Only. The event details show the process and file name modified or deleted on the unapproved removable media.
  • C. This event would never occur. App Control does not report activity on removable media.
  • D. A Policy's device control setting 'Block writes to unapproved removable media' is set to Enabled. The event details show the process, file name, and hash modified or deleted on the removable media.

Answer: B

 

NEW QUESTION 22
An organization leverages a commonly used software distribution tool to manage deployment of enterprise software and updates. Custom rules are a suitable option to ensure the approval of files delivered by this tool.
Which other trust mechanism could the organization configure for large-scale approval of these files?

  • A. Local Approval Mode
  • B. Windows Update
  • C. Trusted Distributor
  • D. Rapid Config

Answer: A

 

NEW QUESTION 23
Which Sensor Status under Endpoint Health indicates that a system's policy enforcement is disabled, and the sensor is not sending security event data to the cloud?

  • A. Inactive
  • B. Deregistered
  • C. Quarantined
  • D. Bypass

Answer: D

Explanation:
Reference:
Bypass-has-been-Enabled-on-the/ta-p/74905

 

NEW QUESTION 24
An administrator ran the following query.
SELECT name, VERSION, install_location, install_source, publisher, install_date, uninstall_string FROM programs WHERE publisher = "Microsoft Corporation"; The administrator notices a lot of installed programs are not returned.
How can the administrator alter the query to see all results?

  • A. Change the WHERE clause to = "*"
  • B. Replace the = with LIKE
  • C. Remove the WHERE clause
  • D. Edit the WHERE clause to remove the quotes

Answer: D

 

NEW QUESTION 25
A company wants to implement the strictest security controls for computers on which the software seldom changes (i.e., servers or single-purpose systems).
Which Enforcement Level is the most fitting?

  • A. Low Enforcement
  • B. None (Visibility)
  • C. High Enforcement
  • D. Medium Enforcement

Answer: C

 

NEW QUESTION 26
......

Penetration testers simulate 5V0-91.20 exam: https://www.lead2passexam.com/VMware/valid-5V0-91.20-exam-dumps.html