VMware 5V0-91.20 Exam Practice Questions (P. 1)
- Full Access (56 questions)
 - Six months of Premium Access
 - Access to one million comments
 - Seamless ChatGPT Integration
 
- Ability to download PDF files
 - Anki Flashcard files for revision
 - No Captcha & No AdSense
 - Advanced Exam Configuration
 
Question #1
                                    An administrator is troubleshooting App Control agent issues. When navigating to the Computer Details page, the administrator sees the following:

What is the status of the WINDOWS-CLIENT agent?
                                
                              
What is the status of the WINDOWS-CLIENT agent?
- AConnected and Up to date
 - BDisconnected and Up to date
 - CConnected but unsupported
 - DConnected but health check failed
 
                                        Correct Answer:
B
                                        
                                        
                                            
                                        
                                    
                                   
                                    B
          
          send
        
        
          light_mode
          delete
      
    Question #2
                                    There is a need to ignore all activity at an application path.
Which rule definition should be used to address this need?
                                
                              Which rule definition should be used to address this need?
- AApplication at Path, Performs any operation, Bypass
 - BApplication at Path, Runs or is Running, Bypass
 - CApplication at Path, Runs or is Running, Allow & Log
 - DApplication at Path, Performs any operation, Allow & Log
 
                                        Correct Answer:
A
Reference:
https://community.carbonblack.com/t5/Knowledge-Base/Carbon-Black-Cloud-Console-How-to-Set-up-Exclusions-in-the/ta-p/42334
                                   
                                    A
Reference:
https://community.carbonblack.com/t5/Knowledge-Base/Carbon-Black-Cloud-Console-How-to-Set-up-Exclusions-in-the/ta-p/42334
          
          send
        
        
          light_mode
          delete
      
    Question #3
                                    An analyst is investigating an alert within the Enterprise EDR console and needs to take action on it.
Which three actions are available to take on the alert? (Choose three.)
                                
                              Which three actions are available to take on the alert? (Choose three.)
- AIgnore alert
 - BDismiss
 - CDismiss on all devices if grouping is enabled
 - DEdit watchlist
 - ESave report
 - FNotifications history
 
                                        Correct Answer:
BCE
Reference:
https://community.carbonblack.com/t5/Knowledge-Base/Carbon-Black-Cloud-How-to-Dismiss-Alerts/ta-p/51766
                                   
                                    BCE
Reference:
https://community.carbonblack.com/t5/Knowledge-Base/Carbon-Black-Cloud-How-to-Dismiss-Alerts/ta-p/51766
          
          send
        
        
          light_mode
          delete
      
    Question #4
                                    An administrator needs to manage a group of sensors from within the console.
Which three actions are available for sensors within the Sensor Group? (Choose three.)
                                
                              Which three actions are available for sensors within the Sensor Group? (Choose three.)
- AMove to group
 - BDisable
 - CRestart
 - DBan
 - EUninstall
 - FShare Settings
 
                                        Correct Answer:
ACE
Reference:
https://www.google.com/url?sa=t&rct=j&q=&esrc=s&source=web&cd=&ved=2ahUKEwjttoeA3ILvAhU6QhUIHZaND-YQFjAAegQIARAD&url=https%3A
%2F%2Fcommunity.carbonblack.com%2Fgbouw27325%2Fattachments%2Fgbouw27325%2Fproduct-docs-news%2F3020%2F1%
2FCB_EDR_7.3_User_Guide.pdf&usg=AOvVaw23smt4s66MWHdv9jM2PYF-
(86)
                                   
                                    ACE
Reference:
https://www.google.com/url?sa=t&rct=j&q=&esrc=s&source=web&cd=&ved=2ahUKEwjttoeA3ILvAhU6QhUIHZaND-YQFjAAegQIARAD&url=https%3A
%2F%2Fcommunity.carbonblack.com%2Fgbouw27325%2Fattachments%2Fgbouw27325%2Fproduct-docs-news%2F3020%2F1%
2FCB_EDR_7.3_User_Guide.pdf&usg=AOvVaw23smt4s66MWHdv9jM2PYF-
(86)
          
          send
        
        
          light_mode
          delete
      
    Question #5
                                    An analyst has investigated two alerts on two separate HR workstations and found that notepad.exe has established communication to another IP address.
Which rule will kill notepad.exe entirely if this activity is detected in the future?
                                
                              Which rule will kill notepad.exe entirely if this activity is detected in the future?
- A**\system32\notepad.exe --> Communicates over the network --> Terminate processMost Voted
 - B**\system32\notepad.exe --> Runs or is Running --> Deny operation
 - C**/system32/notepad.exe --> Runs or is Running --> Terminate process
 - D**/system32/notepad.exe--> Communicates over the network --> Deny operation
 
                                        Correct Answer:
C
Reference:
https://www.google.com/url?
sa=t&rct=j&q=&esrc=s&source=web&cd=&cad=rja&uact=8&ved=2ahUKEwj88fL33YLvAhVQRhUIHYbdDxAQFjABegQIARAD&url=https%3A%2F%
2Fwww.carbonblack.com%2Fblog%2Fcb-threatsight-investigation-reveals-retadup-worm-leverages-autoit-launch-monero-cryptomining-campaign%
2F&usg=AOvVaw0De3tmD7FlQSs8VNMVsH7u
                                   
                                    C
Reference:
https://www.google.com/url?
sa=t&rct=j&q=&esrc=s&source=web&cd=&cad=rja&uact=8&ved=2ahUKEwj88fL33YLvAhVQRhUIHYbdDxAQFjABegQIARAD&url=https%3A%2F%
2Fwww.carbonblack.com%2Fblog%2Fcb-threatsight-investigation-reveals-retadup-worm-leverages-autoit-launch-monero-cryptomining-campaign%
2F&usg=AOvVaw0De3tmD7FlQSs8VNMVsH7u
          
          send
        
        
          light_mode
          delete
      
    All Pages
