Free VMware Carbon Black Portfolio Skills Exam 5V0-91.20 Exam Practice Test

UNLOCK FULL
5V0-91.20 Exam Features
In Just $59 You can Access
  • All Official Question Types
  • Interactive Web-Based Practice Test Software
  • No Installation or 3rd Party Software Required
  • Customize your practice sessions (Free Demo)
  • 24/7 Customer Support
Page: 1 / 24
Total Questions: 116
  • Which strategy should be used to purge inactive bans from the web console?

    Answer: 3 Next Question
  • What are the three available methods in VMware Carbon Black App Control by which an endpoint (agent) can be assigned to a specific policy? (Choose three.)

    Answer: 3, 4, 6 Next Question
  • An administrator needs to query all endpoints in the HR group for instances of an obfuscated copy of cmd.exe.Given this Enterprise EDR query:process_name:cmd.exe AND device_group:HR AND NOT enriched:trueWhich example could be added to the query to provide the desired results?

    Answer: 1 Next Question
  • An analyst has investigated multiple alerts on a number of HR workstations and found that java.exe is attempting to PowerShell. Of the Windows workstations in question, the analyst has also found that Java is installed in multiple locations. The analyst needs to block java.exe from this type of operation.Which rule meets this need?

    Answer: 3 Next Question
  • What does the Aggressive setting do when configured in Local Scan Settings?

    Answer: 3 Next Question
  • Which enforcement level does not block unapproved files but will block files that have been specifically banned?

    Answer: 2 Next Question
  • A Carbon Black Cloud Endpoint Standard analyst is testing different search operator combinations.Which two queries produce the same result? (Choose two.)

    Answer: 1, 5 Next Question
  • An analyst is investigating an alert within the Enterprise EDR console and needs to take action on it.Which three actions are available to take on the alert? (Choose three.)

    Answer: 2, 3, 5 Next Question
  • Given an event rule: Approve nVidia Drivers, changes the local state to Approved for file writes or execution blocks when the publisher is NVIDIA Corporation.How is an alert created that is triggered whenever an nVidia driver is approved by the event rule?

    Answer: 2 Next Question
  • An Enterprise EDR administrator is reviewing the Investigate page and believes they are receiving false positive hits from specific watchlist.Which three options reduce future false positive hits from this watchlist? (Choose three.)

    Answer: 1, 2, 4 Next Question
Page: 1 / 24
Total Questions: 116