Best Preparations of 5V0-91.20 Exam 2021 VMware Carbon Black EndPoint Protection 2021 Unlimited 115 Questions
Focus on 5V0-91.20 All-in-One Exam Guide For Quick Preparation.
NEW QUESTION 64
An administrator wants to query the status of the firewall for all endpoints. The administrator will query the registry key found here HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy
\StandardProfile.
To make the results easier to understand, the administrator wants to return either enabled or disabled for the results, rather than the value from the registry key.
Which SQL statement will rewrite the output based on a specific result set returned from the system?
- A. ALTER
- B. SELECT
- C. AS
- D. CASE
Answer: D
NEW QUESTION 65
An administrator ran the following query.
SELECT name, VERSION, install_location, install_source, publisher, install_date, uninstall_string FROM programs WHERE publisher = "Microsoft Corporation"; The administrator notices a lot of installed programs are not returned.
How can the administrator alter the query to see all results?
- A. Change the WHERE clause to = "*"
- B. Replace the = with LIKE
- C. Remove the WHERE clause
- D. Edit the WHERE clause to remove the quotes
Answer: D
NEW QUESTION 66
Refer to the exhibit:
Which two statements are true about Carbon Black Live Response (CBLR)? (Choose two.)
- A. A CBLR session is established.
- B. A CBLR session is not attached.
- C. A CBLR session already exists.
- D. CBLR is enabled.
- E. CBLR is disabled.
Answer: B,C
NEW QUESTION 67
What is the meaning, if any, of the event Report write (removable media)?
- A. A Policy's device control setting 'Block writes to unapproved removable media' is set to Report Only. The event details show the process, file name, and hash modified or deleted on the removable media.
- B. A Policy's device control setting 'Block writes to unapproved removable media' is set to Report Only. The event details show the process and file name modified or deleted on the unapproved removable media.
- C. This event would never occur. App Control does not report activity on removable media.
- D. A Policy's device control setting 'Block writes to unapproved removable media' is set to Enabled. The event details show the process, file name, and hash modified or deleted on the removable media.
Answer: B
NEW QUESTION 68
Which statement correctly defines the results of ignoring a feed report?
- A. Ignoring a feed report will remove all instances of the report.
- B. Ignoring a feed report will also ignore the threat intelligence feed.
- C. Ignoring a feed report will ignore all indicators in other threat reports.
- D. Ignoring a feed report will ignore future instances of that report.
Answer: B
NEW QUESTION 69
An analyst has investigated multiple alerts on a number of HR workstations and found that java.exe is attempting to PowerShell. Of the Windows workstations in question, the analyst has also found that Java is installed in multiple locations. The analyst needs to block java.exe from this type of operation.
Which rule meets this need?
- A. **\java.exe -> Invokes a command interpreter -> Deny operation
- B. **\Program Files\*\java.exe -> Invokes a command interpreter -> Terminate process
- C. **/java.exe -> Invokes an untrusted process -> Terminate process
- D. **/Program Files/*/java.exe-> Invokes an untrusted process -> Deny operation
Answer: B
NEW QUESTION 70
An analyst on the security team noticed that several alerts are false positives within Enterprise EDR. The analyst disables the IOC within the report from those alerts.
Which statement correctly explains what disabling the IOC will accomplish?
- A. The report will no longer generate hits or alerts on the device from the alert.
- B. The report will no longer generate hits or alerts.
- C. That specific IOC in the report will no longer generate hits or alerts on the device from the alert.
- D. That specific IOC in the report will no longer generate hits or alerts.
Answer: D
NEW QUESTION 71
What does the Aggressive setting do when configured in Local Scan Settings?
- A. It adds a temporary reputation.
- B. It scans all files on execution.
- C. It enables signature updates for the scanner.
- D. It scans new files on first execution.
Answer: D
NEW QUESTION 72
An administrator wants to find instances where the binary Is unsigned.
Which term will accomplish this search?
- A. NOT process_publisher_state:FILE_SIGNATURE_STATE_SIGNED
- B. process_publisher:FILE_SIGNATURE_STATE_NOT_SIGNED
- C. NOT process_publisher:FILE_SIGNATURE_STATE_SIGNED
- D. process_publisher_state:FILE_SIGNATURE_STATE_NOT_SIGNED
Answer: A
NEW QUESTION 73
An Enterprise EDR administrator sees the process in the graphic on the Investigate page but does not see an alert for this process:
How can the administrator generate an alert for future hits against this watchlist?
- A. Select the watchlist on the watchlists page, select the Scheduled Task Created report, and use Take Action to toggle Alert on hit to On.
- B. Select the watchlist on the watchlists page, use Take Action to select Edit, and select Alert on hit.
- C. select the watchlist on the watchlists page, select the Scheduled Task Created report, and use Take Action to select Alert on hit for the report.
- D. Select the watchlist on the watchlists page and click on Alerts: Off to toggle the alerts to On.
Answer: B
NEW QUESTION 74
When dismissing alerts, when should an administrator select "If alert occurs in the future, automatically dismiss it from all devices"?
- A. When the administrator wishes to be notified again to this behavior
- B. When the administrator wishes to apply this action to all future alerts from the device
- C. When the administrator wishes to mark the alert instance as a false positive
- D. When the administrator wishes to remove the alert
Answer: B
NEW QUESTION 75
An administrator is reviewing an alert about a known and required application in the environment. The application has been given the reputation of PUP, with the alert reason being that the PUP was detected. As a result, this application is matching policy blocking & isolation rules for PUPs in the environment and Is not behaving as expected.
Which step should the administrator take to remediate this situation?
- A. Dismiss the alert
- B. Add the file to the Approved List
- C. Add the file to the Banned List and Delete application
- D. Add the file to the Approved List and Dismiss alert
Answer: A
NEW QUESTION 76
A company wants to implement the strictest security controls for computers on which the software seldom changes (i.e., servers or single-purpose systems).
Which Enforcement Level is the most fitting?
- A. Low Enforcement
- B. None (Visibility)
- C. High Enforcement
- D. Medium Enforcement
Answer: C
NEW QUESTION 77
An alert for a device running a proprietary application is tied to a vital business operation.
Which action is appropriate to take?
- A. Terminate the process.
- B. Quarantine the device.
- C. Deny the operation.
- D. Add the application to the Approved List.
Answer: D
NEW QUESTION 78
Which enforcement level does not block unapproved files but will block files that have been specifically banned?
- A. Disabled
- B. Visibility
- C. Medium Enforcement
- D. Low Enforcement
The protection level applied to computers running the App Control
Agent. A range of levels from High (Block Unapproved) to None
(Disabled) enable you to specify the level of file blocking required.
Answer: A
NEW QUESTION 79
An authorized administrator plans to remove the App Control agent from a computer.
Which Enforcement Level must a computer be in before the agent can be uninstalled?
- A. Low Enforcement
- B. Visibility
- C. Any Enforcement Level
- D. None (Disabled)
Answer: C
NEW QUESTION 80
Which strategy is used to create an exclusion in Endpoint Standard for another AV/security product?
- A. Approved List
- B. Isolation Rule
- C. Bypass Mode
- D. Permission Rule
Answer: A
NEW QUESTION 81
When executing a program in App Control, the notification message informs the user that the file is not approved with an option to request approval.
Which Enforcement level is currently enacted?
- A. High
- B. Default
- C. Medium
- D. Low
Answer: B
NEW QUESTION 82
An administrator is interested in upgrading endpoints to the latest release in VMware Carbon Black App Control (V8.1.4+).
What is the first step to make a new agent available for installation or upgrade?
- A. Download from the Carbon Black Software Reputation Service (SRS)
- B. Download from the Carbon Black User Exchange
- C. Download from the Carbon Black App Control Server
- D. Download from the Carbon Black Cloud Back End
Answer: D
NEW QUESTION 83
An administrator wants to allow files to run from a network share.
Which rule type should the administrator configure?
- A. Network Execute (Allow)
- B. Write Approve (Network)
- C. Execute Prompt (Shared Path)
- D. Trusted Path
Answer: C
NEW QUESTION 84
Which strategy should be used to purge inactive bans from the web console?
- A. Go to the hashes page on the web console and remove them
- B. Run the cbbannlng script on the EDR server
- C. Use a pre-configured system cron job daily to remove them
- D. Schedule an add-hoc cron job to remove
Answer: B
NEW QUESTION 85
An administrator needs to check configurations using Audit across several policies and locations within the organization.
How can the administrator run the query to only these specific devices?
- A. Specify endpoints on the query by selecting the check box for each device.
- B. Specify endpoints on the query by typing the sensor name into the text box, selecting the device. Repeat as necessary for all devices.
- C. Specify the policy for the endpoints on the query, and then select the check box for each device.
- D. Specify the policy for the endpoints on the query, and then type the sensor name into the text box, selecting the devices. Repeat as necessary for all devices.
Answer: D
NEW QUESTION 86
There is a requirement to block ransomware when a sensor is offline.
Which blocking and isolation rule fulfills this requirement?
- A. Known Malware -> Performs ransomware-like behavior -> Terminate process
- B. Unknown Application -> Performs ransomware-like behavior -> Terminate process
- C. Not Listed Application -> Performs ransomware-like behavior -> Deny operation
- D. Suspect Malware -> Performs ransomware-like behavior -> Deny operation
Answer: A
NEW QUESTION 87
Review the following EDR query:
(parent_name:powershell.exe OR parent_name:cmd.exe) AND netconn_count:[l TO *] Which process would show in the query results?
- A. Processes invoking Powershell.exe and cmd.exe with multiple network connection events
- B. Processes invoked by Powershell.exe and cmd.exe with a single network connection event
- C. Processes invoked by Powershell.exe or cmd.exe with any number of network connection events
- D. Processes invoking Powershell.exe or cmd.exe with multiple network connection events
Answer: B
NEW QUESTION 88
......
Guaranteed Success with 5V0-91.20 Dumps: https://www.actualtests4sure.com/5V0-91.20-test-questions.html

