VMware 5V0-93.22 Exam Practice Questions (P. 3)
- Full Access (60 questions)
- Six months of Premium Access
- Access to one million comments
- Seamless ChatGPT Integration
- Ability to download PDF files
- Anki Flashcard files for revision
- No Captcha & No AdSense
- Advanced Exam Configuration
Question #11
An administrator wants to find information about real-world prevention rules that can be used in VMware Carbon Black Cloud Endpoint Standard.
How can the administrator obtain this information?
How can the administrator obtain this information?
- ARefer to an external report from other security vendors to obtain solutions.
- BRefer to the TAU-TIN's on the VMware Carbon Black community page.
- CRefer to the VMware Carbon Black Cloud sensor install guide.
- DRefer to VMware Carbon Black Cloud user guide.
Correct Answer:
B
B
send
light_mode
delete
Question #12
Is it possible to search for unsigned files in the console?
- AYes, by using the search:
NOT process_publisher_state:FILE_SIGNATURE_STATE_SIGNED - BNo, it is not possible to return a query for unsigned files.
- CYes, by using the search:
process_publisher_state:FILE_SIGNATURE_STATE_UNSIGNED - DYes, by looking at signed and unsigned executables in the environment and seeing if another difference can be found, thus locating unsigned files in the environment.
Correct Answer:
C
C
send
light_mode
delete
Question #13
The administrator has configured a permission rule with the following options selected:
Application at path: C:\Program Files\**
Operation Attempt: Performs any operation
Action: Bypass -
What is the impact, if any, of using the wildcards in the application at path field?
Application at path: C:\Program Files\**
Operation Attempt: Performs any operation
Action: Bypass -
What is the impact, if any, of using the wildcards in the application at path field?
- AExecutable files in the "Program Files" directory and subdirectories will be ignored.
- BExecutable files in the "Program Files" directory will be blocked.
- CExecutable files in the "Program Files" directory will be logged.
- DExecutable files in the "Program Files" directory will be subject to blocking rules.
Correct Answer:
A
A
send
light_mode
delete
Question #14
A script-based attack has been identified that inflicted damage to the corporate systems. The security administrator found out that the malware was coded into Excel VBA and would like to perform a search to further inspect the incident.
Where in the VMware Carbon Black Cloud Endpoint Standard console can this action be completed?
Where in the VMware Carbon Black Cloud Endpoint Standard console can this action be completed?
send
light_mode
delete
Question #15
An administrator would like to proactively know that something may get blocked when putting a policy rule in the environment.
How can this information be obtained?
How can this information be obtained?
- ASearch the data using the test rule functionality.
- BExamine log files to see what would be impacted.
- CPut the rules in and see what happens to the endpoints.
- DDetermine what would happen based on previously used antivirus software.
Correct Answer:
A
A
send
light_mode
delete
All Pages