[Sep-2021] Dumps Brief Outline Of The 5V0-91.20 Exam - Lead2PassExam
5V0-91.20 Training & Certification Get Latest VMware Carbon Black EndPoint Protection 2021
NEW QUESTION 23
Which list below captures all Enforcement Levels for App Control policies?
- A. High Enforcement, Medium Enforcement, Low Enforcement, None (Visibility), None (Disabled)
- B. High Enforcement, Medium Enforcement, Low Enforcement
- C. Control, Local Approval, Disabled
- D. Critical, Lockdown, Monitored, Tracking, Banning
Answer: A
Explanation:
Reference:
sa=t&rct=j&q=&esrc=s&source=web&cd=&ved=2ahUKEwiFsPPz04XvAhWRsnEKHV4lBukQFjABegQIAhAD& url=https%3A%2F%2Fcommunity.carbonblack.com%2Fgbouw27325%2Fattachments%2Fgbouw27325%
2Fproduct-docs-news%2F2961%2F1%2FVMware%2520Carbon%2520Black%2520App%2520Control%
25208.5.0%2520User%2520Guide.pdf&usg=AOvVaw3es_0JTc8-_BifNR4iFiGl (6)
NEW QUESTION 24
Which two statements are true about Carbon Black alerts? (Choose two.)
- A. Once dismissed, the action cannot be undone.
- B. They can be grouped together.
- C. Once received, it can be dismissed in bulk.
- D. They are stored for 15 days.
- E. Carbon Black does not generate alerts.
Answer: D,E
NEW QUESTION 25
Review this result after executing a query in the Process Search page, noting the circled black dot:
What is the meaning of the black dot shown under Tags?
- A. The events for the process were tagged in an investigation.
- B. The execution of the process resulted in watchlist hits.
- C. The events for the process were also sent to the Syslog Server.
- D. The execution of the process resulted in feed hits.
Answer: D
NEW QUESTION 26
A Carbon Black Cloud analyst needs to identify the Internet Explorer extensions installed on Windows endpoints.
Which Live Query statement will successfully query these items?
- A. SELECT * FROM registry WHERE ie_extensions;
- B. SELECT * FROM ie_extensions;
- C. SELECT * FROM registry JOIN ie_extensions;
- D. SELECT * FROM ie_extensions WHERE enabled=true;
Answer: C
NEW QUESTION 27
A process wrote an executable file as detailed in the following event:
Which rule type should be used to ensure that files of the same name and path, written by that process in the future, will not be blocked when they execute?
- A. File Creation Control
- B. Advances (Write-Ignore)
- C. Trusted Path
- D. Trusted Publisher
Answer: A
NEW QUESTION 28
Review the following EDR query:
parent_name:outlook.exe AND -alliance_score_srstrust:* AND -digsig_result: "Signed' Which process would show in the query results?
- A. Processes invoking outlook.exe that do not have an SRS Trust value and that are not digitally signed.
- B. Processes invoked by outlook.exe that have an SRS Trust value and that are digitally signed.
- C. Processes invoking outlook.exe that have an SRS Trust value and that are not digitally signed.
- D. Processes invoked by outlook.exe that do not have an SRS Trust value and that are not digitally signed.
Answer: C
NEW QUESTION 29
How can an analyst disregard alerts on multiple devices with the least amount of administrative effort?
- A. Search by hash and dismiss.
- B. Make a note in the Notes/Tags option.
- C. Turn off the Group Alerts option.
- D. Select the "Dismiss on all devices" option.
Answer: C
Explanation:
Reference:
sa=t&rct=j&q=&esrc=s&source=web&cd=&cad=rja&uact=8&ved=2ahUKEwjv6pryl4XvAhWagVwKHTCMDTE QFjAAegQIARAD&url=https%3A%2F%2Fcommunity.carbonblack.com%2Ft5%2FKnowledge-Base%
2FCarbon-Black-Cloud-How-to-Dismiss-Alerts%2Fta-p%
2F51766&usg=AOvVaw2x1mST1tWpuASUMLmFhyuI (80)
NEW QUESTION 30
While an administrator is reviewing an alert, the device is observed beaconing to an unknown destination.
Which action should be taken to stop this behavior?
- A. Put the device in Bypass mode
- B. Assign the application to the Approved List
- C. Deregister the sensor
- D. Place the device in Quarantine
Answer: A
NEW QUESTION 31
Review the following EDR query:
(parent_name:powershell.exe OR parent_name:cmd.exe) AND netconn_count:[l TO *] Which process would show in the query results?
- A. Processes invoking Powershell.exe and cmd.exe with multiple network connection events
- B. Processes invoked by Powershell.exe and cmd.exe with a single network connection event
- C. Processes invoked by Powershell.exe or cmd.exe with any number of network connection events
- D. Processes invoking Powershell.exe or cmd.exe with multiple network connection events
Answer: B
NEW QUESTION 32
Examine the following EDR query:
file_desc:"Windows Command Processor" AND -process_name:cmd.exe
Which process will show in the query results?
- A. Any process named something other than cmd.exe with the file description of "Windows Command Processor"
- B. Any process with the binary file description "Windows Command Processor" named cmd.exe
- C. Any process with the binary file description "Windows Command Processor"
- D. Any process named cmd.exe
Answer: B
NEW QUESTION 33
An alert for a device running a proprietary application is tied to a vital business operation.
Which action is appropriate to take?
- A. Terminate the process.
- B. Quarantine the device.
- C. Deny the operation.
- D. Add the application to the Approved List.
Answer: D
NEW QUESTION 34
An administrator ran the following query.
SELECT name, VERSION, install_location, install_source, publisher, install_date, uninstall_string FROM programs WHERE publisher = "Microsoft Corporation"; The administrator notices a lot of installed programs are not returned.
How can the administrator alter the query to see all results?
- A. Change the WHERE clause to = "*"
- B. Replace the = with LIKE
- C. Remove the WHERE clause
- D. Edit the WHERE clause to remove the quotes
Answer: D
NEW QUESTION 35
Which strategy is used to create an exclusion in Endpoint Standard for another AV/security product?
- A. Approved List
- B. Isolation Rule
- C. Bypass Mode
- D. Permission Rule
Answer: A
NEW QUESTION 36
What occurs when an administrator selects "Enable private logging level" in Sensor Settings under Policy?
- A. Domain names are obfuscated.
- B. Script Files that have unknown reputations are not uploaded.
- C. Live Response is disabled.
- D. Delay execute for cloud scan is disabled.
Answer: B
NEW QUESTION 37
Which reputation is processed with the lowest priority for Endpoint Standard?
- A. Known Malware
- B. Local White
- C. Common White
- D. Trusted White
Answer: A
NEW QUESTION 38
An administrator needs to manage a group of sensors from within the console.
Which three actions are available for sensors within the Sensor Group? (Choose three.)
- A. Restart
- B. Disable
- C. Ban
- D. Share Settings
- E. Move to group
- F. Uninstall
Answer: A,E,F
NEW QUESTION 39
A watchlist generates a false positive on the Triage Alerts page, so the watchlist must be updated.
How should this task be accomplished?
- A. Open the Watchlist Page and click the pencil button associated with the watchlist.
- B. One can update watchlists from the Process Search Page.
- C. One can update watchlists directly on the Triage Alerts Page using the pencil icon.
- D. Open the process analysis page and select the Add Watchlist Exclusion option from the Actions menu.
Answer: C
NEW QUESTION 40
An administrator is troubleshooting App Control agent issues. When navigating to the Computer Details page, the administrator sees the following:
What is the status of the WINDOWS-CLIENT agent?
- A. Connected and Up to date
- B. Connected but unsupported
- C. Disconnected and Up to date
- D. Connected but health check failed
Answer: C
NEW QUESTION 41
There is a requirement to block ransomware when a sensor is offline.
Which blocking and isolation rule fulfills this requirement?
- A. Known Malware -> Performs ransomware-like behavior -> Terminate process
- B. Unknown Application -> Performs ransomware-like behavior -> Terminate process
- C. Not Listed Application -> Performs ransomware-like behavior -> Deny operation
- D. Suspect Malware -> Performs ransomware-like behavior -> Deny operation
Answer: A
NEW QUESTION 42
An authorized administrator plans to remove the App Control agent from a computer.
Which Enforcement Level must a computer be in before the agent can be uninstalled?
- A. Low Enforcement
- B. Visibility
- C. Any Enforcement Level
- D. None (Disabled)
Answer: C
NEW QUESTION 43
What information does the Alert Details panel provide on the Alert Triage page in Endpoint Standard?
- A. Device ID
- B. Alert ID
- C. Threat ID
- D. Process ID
Answer: C
NEW QUESTION 44
An analyst is investigating an alert within Enterprise EDR on the process analysis page. The process tree can be seen below:
Which statement accurately characterizes this situation?
- A. The solid line between the nodes denotes a process was injected into by another process.
- B. The analyst navigated to this process analysis page from the wscrlpt.exe process.
- C. Several nodes in this process tree have watchlist hits.
- D. Conhost.exe has one or more child processes.
Answer: A
NEW QUESTION 45
Which statement should be used when constructing queries in Carbon Black Audit and Remediation, Live Query?
- A. UPDATE
- B. ALTER
- C. REMOVE
- D. SELECT
Answer: D
NEW QUESTION 46
......
Certification Training for 5V0-91.20 Exam Dumps Test Engine: https://www.lead2passexam.com/VMware/valid-5V0-91.20-exam-dumps.html