VMware 5V0-91.20 Exam Practice Questions (P. 3)
- Full Access (56 questions)
- Six months of Premium Access
- Access to one million comments
- Seamless ChatGPT Integration
- Ability to download PDF files
- Anki Flashcard files for revision
- No Captcha & No AdSense
- Advanced Exam Configuration
Question #11
A security policy states to enable Live Response by default across the enterprise. However, the team identified critical systems which should not support Live
Response due to risk. The team needs to disable Live Response on selected systems.
From which page can this goal be accomplished?
Response due to risk. The team needs to disable Live Response on selected systems.
From which page can this goal be accomplished?
send
light_mode
delete
Question #12
An analyst is investigating a specific alert in Endpoint Standard. The analyst selects the investigate button from the alert triage page and sees the following:

Which statement accurately characterizes this situation?

Which statement accurately characterizes this situation?
- AThese events are tied to an observed alert within the user interface.
- BThe policy had no blocking and isolation rules set.
- CThe events shown will all have the same event ID, correlating them to the alert.Most Voted
- DEach event listed contributed to the overall alert score and severity.
Correct Answer:
D
D
send
light_mode
delete
Question #13
Examine the following EDR query:
file_desc:`Windows Command Processor` AND -process_name:cmd.exe
Which process will show in the query results?
file_desc:`Windows Command Processor` AND -process_name:cmd.exe
Which process will show in the query results?
- AAny process named something other than cmd.exe with the file description of ג€Windows Command Processorג€Most Voted
- BAny process with the binary file description ג€Windows Command Processorג€
- CAny process with the binary file description ג€Windows Command Processorג€ named cmd.exe
- DAny process named cmd.exe
Correct Answer:
C
C
send
light_mode
delete
Question #14
Carbon Black App Control maintains an inventory of all interesting (executable) files on endpoints where the agent is installed.
What is the initial inventory procedure called, and how can this process be triggered?
What is the initial inventory procedure called, and how can this process be triggered?
- AInventorying; enable Discovery mode
- BBaselining; install the agent
- CDiscovery; place agent into Disabled mode
- DInitialization; move agent out of Disabled mode
Correct Answer:
A
Reference:
https://www.google.com/url?sa=t&rct=j&q=&esrc=s&source=web&cd=&ved=2ahUKEwic3bDN5YLvAhX3QEEAHd2MDIQQFjAAegQIBRAD&url=https
%3A%2F%2Fcommunity.carbonblack.com%2Fgbouw27325%2Fattachments%2Fgbouw27325%2Fproduct-docs-news%2F2961%2F1%2FVMware%2520Carbon
%2520Black%2520App%2520Control%25208.5.0%2520User%2520Guide.pdf&usg=AOvVaw3es_0JTc8-_BifNR4iFiGl
(7)
A
Reference:
https://www.google.com/url?sa=t&rct=j&q=&esrc=s&source=web&cd=&ved=2ahUKEwic3bDN5YLvAhX3QEEAHd2MDIQQFjAAegQIBRAD&url=https
%3A%2F%2Fcommunity.carbonblack.com%2Fgbouw27325%2Fattachments%2Fgbouw27325%2Fproduct-docs-news%2F2961%2F1%2FVMware%2520Carbon
%2520Black%2520App%2520Control%25208.5.0%2520User%2520Guide.pdf&usg=AOvVaw3es_0JTc8-_BifNR4iFiGl
(7)
send
light_mode
delete
Question #15
This search is entered into the process search page: notepad.exe
Which three statements about this query are true? (Choose three.)
Which three statements about this query are true? (Choose three.)
- AOnly processes named notepad.exe will be returned.
- BSince a field name is not selected, query performance will be impacted.
- CA field identifier is required for all criteria within a process search.
- DThe search will fail with an error.
- EAll processes containing the text notepad.exe in any default field.
- FProcesses with registry modifications containing notepad.exe would be retuned.
Correct Answer:
BEF
BEF
send
light_mode
delete
All Pages