Skip to main content

5V0-91.20 Real Exam Questions

VMware Carbon Black Portfolio Skills

116 questions available · Page 1 of 12

Updated Exam DumpsVerified AnswersPass Guarantee

Get Complete Exam Dumps
Question 1 Single choice

Which reputation is processed with the lowest priority for Endpoint Standard?

  1. A

    Local White

  2. B

    Known Malware

  3. C

    Trusted White

  4. D

    Common White

Show answer and explanation

Correct answer: B

Question 2 Single choice

How can an analyst disregard alerts on multiple devices with the least amount of administrative effort?

  1. A

    Select the "Dismiss on all devices" option.

  2. B

    Make a note in the Notes/Tags option.

  3. C

    Search by hash and dismiss.

  4. D

    Turn off the Group Alerts option.

Show answer and explanation

Correct answer: D

Explanation

References:
https://www.google.com/url?sa=t&rct=j&q=&esrc=s&source=web&cd=&cad=rja&uact=8&ved=2ahUKEwjv6pryl4XvAhWagVwKHTCMDTEQFjAAegQIARAD&url=https%3A%2F%2Fcommunity.carbonblack.com%2Ft5%2FKnowledge-Base%2FCarbon-Black-Cloud-How-to-Dismiss-Alerts%2Fta-p%2F51766&usg=AOvVaw2x1mST1tWpuASUMLmFhyuI(80)

Question 3 Single choice

A company wants to implement the strictest security controls for computers on which the software seldom changes (i.e., servers or single-purpose systems).

Which Enforcement Level is the most fitting?

  1. A

    Low Enforcement

  2. B

    Medium Enforcement

  3. C

    High Enforcement

  4. D

    None (Visibility)

Show answer and explanation

Correct answer: C

Question 4 Single choice

An Enterprise EDR administrator sees the process in the graphic on the Investigate page but does not see an alert for this process:

How can the administrator generate an alert for future hits against this watchlist?

  1. A

    select the watchlist on the watchlists page, select the Scheduled Task Created report, and use Take

    Action to select Alert on hit for the report.

  2. B

    Select the watchlist on the watchlists page, select the Scheduled Task Created report, and use Take

    Action to toggle Alert on hit to On.

  3. C

    Select the watchlist on the watchlists page and click on Alerts: Off to toggle the alerts to On.

  4. D

    Select the watchlist on the watchlists page, use Take Action to select Edit, and select Alert on hit.

Show answer and explanation

Correct answer: D

Question 5 Multiple choice

At which three frequencies may a Carbon Black Audit and Remediation administrator schedule the run of Live Queries? (Choose three.)

  1. A

    Monthly

  2. B

    Daily

  3. C

    Bi-Weekly

  4. D

    Weekly

  5. E

    Hourly

  6. F

    Any frequency

Show answer and explanation

Correct answers: A, B, D

Question 6 Single choice

An authorized administrator plans to remove the App Control agent from a computer.

Which Enforcement Level must a computer be in before the agent can be uninstalled?

  1. A

    Visibility

  2. B

    None (Disabled)

  3. C

    Any Enforcement Level

  4. D

    Low Enforcement

Show answer and explanation

Correct answer: C

Question 7 Single choice

Review the following EDR query:

(parent_name:powershell.exe OR parent_name:cmd.exe) AND netconn_count:[l TO *]

Which process would show in the query results?

  1. A

    Processes invoked by Powershell.exe and cmd.exe with a single network connection event

  2. B

    Processes invoking Powershell.exe and cmd.exe with multiple network connection events

  3. C

    Processes invoked by Powershell.exe or cmd.exe with any number of network connection events

  4. D

    Processes invoking Powershell.exe or cmd.exe with multiple network connection events

Show answer and explanation

Correct answer: A

Question 8 Single choice

What information does the Alert Details panel provide on the Alert Triage page in Endpoint Standard?

  1. A

    Threat ID

  2. B

    Process ID

  3. C

    Device ID

  4. D

    Alert ID

Show answer and explanation

Correct answer: A

Question 9 Single choice

An Enterprise EDR administrator wants to use Watchlists curated by VMware Carbon Black and other threat intelligence specialists.

How should the administrator add these curated Watchlists from the Watchlists page?

  1. A

    Click Add Watchlists, and input the URL(s) for the desired Watchlists.

  2. B

    Click Take Action, select Edit, and select the desired Watchlists.

  3. C

    Click Take Action, and select Subscribe for the desired Watchlists.

  4. D

    Click Add Watchlists, on the Subscribe tab select the desired Watchlists, and click Subscribe.

Show answer and explanation

Correct answer: A

Explanation

References:
https://www.google.com/url?sa=t&rct=j&q=&esrc=s&source=web&cd=&ved=2ahUKEwjl1tW404XvAhWZRhUIHSygB74QFjADegQIExAD&url=https%3A%2F%2Fcommunity.carbonblack.com%2Fgbouw27325%2Fattachments%2Fgbouw27325%2Fproduct-docs-news%F1913%2F18%2FEnterprise%2520EDR%2520Getting%2520Started.pdf&usg=AOvVaw2_M7opfEgUaIIfutBZChvk(5)

Question 10 Single choice

A company uses Audit and Remediation to check configurations and adhere to compliance regulations.
The regulations require monthly reporting and twelve months of data retained.

How can an administrator accomplish this requirement with Audit and Remediation?

  1. A

    Schedule the query to run monthly, and set the data retention to 12 months for the query.

  2. B

    Schedule the query to run monthly, and configure the audit log retention to 12 months.

  3. C

    Schedule the query to run monthly, and no further action is required.

  4. D

    Schedule the query to run monthly, and export the results for each run to an external location.

Show answer and explanation

Correct answer: D