VMware Carbon Black Portfolio Skills - 5V0-91.20 Exam Practice Test
An analyst has investigated multiple alerts on a number of HR workstations and found that java.exe is attempting to PowerShell. Of the Windows workstations in question, the analyst has also found that Java is installed in multiple locations. The analyst needs to block java.exe from this type of operation.
Which rule meets this need?
Which rule meets this need?
Correct Answer: B
Vote an answer
There is a need to ignore all activity at an application path.
Which rule definition should be used to address this need?
Which rule definition should be used to address this need?
Correct Answer: D
Vote an answer
What are the three available methods in VMware Carbon Black App Control by which an endpoint (agent) can be assigned to a specific policy? (Choose three.)
Correct Answer: A,B,D
Vote an answer
An analyst is investigating an alert within the Enterprise EDR console and needs to take action on it.
Which three actions are available to take on the alert? (Choose three.)
Which three actions are available to take on the alert? (Choose three.)
Correct Answer: A,D,E
Vote an answer
Explanation: Only visible for Fast2test members. You can sign-up / login (it's free).
An administrator has configured a policy to run a standard background scan.
How long does this one-time scan take to complete on endpoints assigned to that policy?
How long does this one-time scan take to complete on endpoints assigned to that policy?
Correct Answer: B
Vote an answer
An administrator receives an alert with the TTP DATA_TO_ENCRYPTION.
What is known about the alert based on this TTP even if other parts of the alert are unknown?
What is known about the alert based on this TTP even if other parts of the alert are unknown?
Correct Answer: D
Vote an answer
Which enforcement level does not block unapproved files but will block files that have been specifically banned?
Correct Answer: B
Vote an answer