Online Questions - Valid Practice To your 5V0-91.20 Exam (Updated 115 Questions) [Q32-Q56]

Share

Online Questions - Valid Practice To your 5V0-91.20 Exam (Updated 115 Questions)

Practice To 5V0-91.20 - Remarkable Practice On your VMware Carbon Black Portfolio Skills Exam

NEW QUESTION 32
A process is writing numerous interesting files that never actually execute.
Which rule type can the administrator define that will prevent reporting these file creations?

  • A. File Creation Control (Suppress)
  • B. Expert (Tag Process, Terminate Process)
  • C. Execute Ignore
  • D. Performance Optimization

Answer: D

 

NEW QUESTION 33
At which three frequencies may a Carbon Black Audit and Remediation administrator schedule the run of Live Queries? (Choose three.)

  • A. Weekly
  • B. Any frequency
  • C. Daily
  • D. Hourly
  • E. Bi-Weekly
  • F. Monthly

Answer: A,C,F

 

NEW QUESTION 34
An analyst is reviewing an alert in Enterprise EDR from a custom watchlist. The analyst disagrees with the alert severity rating.
How can the analyst change the alert severity value, if this is possible?

  • A. Change the alert severity on the watchlist.
  • B. Change the alert severity on the report.
  • C. The alert severity is assigned by the backend analytics.
  • D. The alert severity is not configurable.

Answer: A

 

NEW QUESTION 35
An alert for a device running a proprietary application is tied to a vital business operation.
Which action is appropriate to take?

  • A. Terminate the process.
  • B. Quarantine the device.
  • C. Deny the operation.
  • D. Add the application to the Approved List.

Answer: D

 

NEW QUESTION 36
Which list below captures all Enforcement Levels for App Control policies?

  • A. High Enforcement, Medium Enforcement, Low Enforcement, None (Visibility), None (Disabled)
  • B. High Enforcement, Medium Enforcement, Low Enforcement
  • C. Control, Local Approval, Disabled
  • D. Critical, Lockdown, Monitored, Tracking, Banning

Answer: A

Explanation:
Reference:
sa=t&rct=j&q=&esrc=s&source=web&cd=&ved=2ahUKEwiFsPPz04XvAhWRsnEKHV4lBukQFjABegQIAhAD& url=https%3A%2F%2Fcommunity.carbonblack.com%2Fgbouw27325%2Fattachments%2Fgbouw27325%
2Fproduct-docs-news%2F2961%2F1%2FVMware%2520Carbon%2520Black%2520App%2520Control%
25208.5.0%2520User%2520Guide.pdf&usg=AOvVaw3es_0JTc8-_BifNR4iFiGl (6)

 

NEW QUESTION 37
Which enforcement level does not block unapproved files but will block files that have been specifically banned?

  • A. Disabled
  • B. Visibility
  • C. Medium Enforcement
  • D. Low Enforcement
    The protection level applied to computers running the App Control
    Agent. A range of levels from High (Block Unapproved) to None
    (Disabled) enable you to specify the level of file blocking required.

Answer: A

 

NEW QUESTION 38
Given an event rule: Approve nVidia Drivers, changes the local state to Approved for file writes or execution blocks when the publisher is NVIDIA Corporation.
How is an alert created that is triggered whenever an nVidia driver is approved by the event rule?

  • A. Create a custom rule name Approve nVidia that approves writes or blocks when the publisher is NVIDIA Corporation. Create an alert for rule name Approve nVidia. Click Create and add email recipients.
  • B. Add a new Alert of type Event Alert. Set Subtype to New unapproved file to computer and Execution block (unapproved file) and Publisher to NVIDIA Corporation. Click Create and add email recipients.
  • C. Click Create Alert on the event rule Approve nVidia Drivers details page. Add email recipients. Create and Exit.
  • D. Click Create Alert on the event rule Approve nVidia Drivers details page. Click Create and add email recipients. Create and Exit.

Answer: D

 

NEW QUESTION 39
Which two statements are true regarding Live Response? (Choose two.)

  • A. Live Response requires both view and manage permissions to use.
  • B. Live Response utilizes the same channel for sensor-server communications.
  • C. Live Response supports one user per session on an endpoint.
  • D. Live Response can only be initiated through the user interface.
  • E. Live Response opens an SSH session with the remote device.

Answer: B,D

 

NEW QUESTION 40
An analyst is investigating an alert within Enterprise EDR. The alert is tied to an unusual process name. When navigating to the binary details page, for the binary used in the alert, the analyst sees the following:

The analyst wants to find any instances of this process executing regardless of the process name used.
Which two details from the binary can be used to search for the application regardless of the seen name?
(Choose two.)

  • A. The publisher name
  • B. The original filename
  • C. The product version
  • D. The binary's hash
  • E. The path

Answer: C,E

 

NEW QUESTION 41
What is the meaning, if any, of the event Report write (removable media)?

  • A. A Policy's device control setting 'Block writes to unapproved removable media' is set to Report Only. The event details show the process, file name, and hash modified or deleted on the removable media.
  • B. A Policy's device control setting 'Block writes to unapproved removable media' is set to Report Only. The event details show the process and file name modified or deleted on the unapproved removable media.
  • C. This event would never occur. App Control does not report activity on removable media.
  • D. A Policy's device control setting 'Block writes to unapproved removable media' is set to Enabled. The event details show the process, file name, and hash modified or deleted on the removable media.

Answer: B

 

NEW QUESTION 42
Which reputation is processed with the lowest priority for Endpoint Standard?

  • A. Known Malware
  • B. Local White
  • C. Common White
  • D. Trusted White

Answer: A

 

NEW QUESTION 43
Which reputation has the highest priority in Cloud Endpoint Standard?

  • A. Adware/PUP Malware
  • B. Ignore
  • C. Known Malware
  • D. Unknown

Answer: C

 

NEW QUESTION 44
This search is entered into the process search page: notepad.exe
Which three statements about this query are true? (Choose three.)

  • A. A field identifier is required for all criteria within a process search.
  • B. Only processes named notepad.exe will be returned.
  • C. Since a field name is not selected, query performance will be impacted.
  • D. Processes with registry modifications containing notepad.exe would be retuned.
  • E. All processes containing the text notepad.exe in any default field.
  • F. The search will fail with an error.

Answer: C,D,E

 

NEW QUESTION 45
A security policy states to enable Live Response by default across the enterprise. However, the team identified critical systems which should not support Live Response due to risk. The team needs to disable Live Response on selected systems.
From which page can this goal be accomplished?

  • A. Endpoints
  • B. Roles
  • C. API Access
  • D. Policy

Answer: B

 

NEW QUESTION 46
The security operations group is complaining that they are getting multiple App Control alerts for specific malicious files after they have banned the file.
Which step is necessary to prevent future alerts on these files?

  • A. Edit the Malicious File Detected Alert. Select the criteria: Ignore already banned files.
  • B. Edit the Malicious File Detected Alert. Select the criteria: Ignore already banned files and Ignore already approved files.
  • C. Disable the Reminder Mail.
  • D. Set the Alert Status to Disabled.

Answer: C

 

NEW QUESTION 47
What are the three available methods in VMware Carbon Black App Control by which an endpoint (agent) can be assigned to a specific policy? (Choose three.)

  • A. Manual policy assignment
  • B. By branded/policy-specific installer
  • C. By installing the agent via SCCM
  • D. By Active Directory Mapping
  • E. By pushing the designated GPO script
  • F. Via DASCLI command

Answer: A,C,D

 

NEW QUESTION 48
An administrator runs the following query in Audit and Remediation:
SELECT *
FROM users
WHERE UID >= 500;
How long will this query stay active and accept data from the sensors?

  • A. 30 days
  • B. 14 days
  • C. 7 days
  • D. 1 day

Answer: A

 

NEW QUESTION 49
An administrator wants to query the status of the firewall for all endpoints. The administrator will query the registry key found here HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy
\StandardProfile.
To make the results easier to understand, the administrator wants to return either enabled or disabled for the results, rather than the value from the registry key.
Which SQL statement will rewrite the output based on a specific result set returned from the system?

  • A. ALTER
  • B. SELECT
  • C. AS
  • D. CASE

Answer: D

 

NEW QUESTION 50
An administrator is troubleshooting App Control agent issues. When navigating to the Computer Details page, the administrator sees the following:

What is the status of the WINDOWS-CLIENT agent?

  • A. Connected and Up to date
  • B. Connected but unsupported
  • C. Disconnected and Up to date
  • D. Connected but health check failed

Answer: C

 

NEW QUESTION 51
Review this result after executing a query in the Process Search page, noting the circled black dot:

What is the meaning of the black dot shown under Tags?

  • A. The events for the process were tagged in an investigation.
  • B. The execution of the process resulted in watchlist hits.
  • C. The events for the process were also sent to the Syslog Server.
  • D. The execution of the process resulted in feed hits.

Answer: D

 

NEW QUESTION 52
When dismissing alerts, when should an administrator select "If alert occurs in the future, automatically dismiss it from all devices"?

  • A. When the administrator wishes to be notified again to this behavior
  • B. When the administrator wishes to apply this action to all future alerts from the device
  • C. When the administrator wishes to mark the alert instance as a false positive
  • D. When the administrator wishes to remove the alert

Answer: B

 

NEW QUESTION 53
Level 3 service desk personnel have been approved to modify computer enforcement levels by security governance.
Which set of steps is required to implement this change?

  • A. Create new user role, map AD group to role, assign permission "Manage computers" to role.
  • B. Assign permission "Temporary assign computers" to each user.
  • C. Create new user role, assign permission "Manage computers" to role.
  • D. Create new user role, map AD group to role, assign permission "Temporary assign computers" to role.

Answer: B

 

NEW QUESTION 54
An administrator needs to check configurations using Audit across several policies and locations within the organization.
How can the administrator run the query to only these specific devices?

  • A. Specify endpoints on the query by selecting the check box for each device.
  • B. Specify endpoints on the query by typing the sensor name into the text box, selecting the device. Repeat as necessary for all devices.
  • C. Specify the policy for the endpoints on the query, and then select the check box for each device.
  • D. Specify the policy for the endpoints on the query, and then type the sensor name into the text box, selecting the devices. Repeat as necessary for all devices.

Answer: D

 

NEW QUESTION 55
An Endpoint Standard administrator finds a binary in the environment and decides to manually add the file hash to the Banned List.
Which reputation does the file now have?

  • A. Adware/PUP Malware
  • B. Company Black
  • C. Suspect/Heuristic Malware
  • D. Known Malware

Answer: C

 

NEW QUESTION 56
......

True 5V0-91.20 Exam Extraordinary Practice For the Exam: https://www.torrentvce.com/5V0-91.20-valid-vce-collection.html