VMware Carbon Black Cloud Endpoint Standard Skills - 5V0-93.22 Exam Practice Test

Which VMware Carbon Black Cloud process is responsible for uploading event reporting to VMware Carbon Black Cloud?
Correct Answer: B
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
Which statement accurately characterizes Alerts that are categorized as a "Threat" versus those categorized as
"Observed"?
Correct Answer: B
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
An administrator needs to use an ID to search and investigate security incidents in Carbon Black Cloud.
Which three IDs may be used for this purpose? (Choose three.)
Correct Answer: C,D,E
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
A security administrator needs to remediate a security vulnerability that may affect the sensors. The administrator decides to use a tool that can provide interaction and remote access for further investigation.
Which tool is being used by the administrator?
Correct Answer: B
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
A script-based attack has been identified that inflicted damage to the corporate systems. The security administrator found out that the malware was coded into Excel VBA and would like to perform a search to further inspect the incident.
Where in the VMware Carbon Black Cloud Endpoint Standard console can this action be completed?
Correct Answer: D
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
An organization has found application.exe running on some machines in their Workstations policy.
Application.exe has a SUSPECT_MALWARE reputation and runs from C:\Program Files\IT\Tools. The Workstations policy has the following rules which could apply:
Blocking and Isolation Rule
Application on the company banned list > Runs or is running > Deny
Known malware > Runs or is running > Deny
Suspect malware > Runs or is running > Terminate
Permissions Rule
C:\Program Files\IT\Tools\* > Performs any operation > Bypass
Which action, if any, should an administrator take to ensure application.exe cannot run?
Correct Answer: C
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
A VMware Carbon Black managed endpoint is showing up as an inactive device in the console.
What is the threshold, in days, before a machine shows as inactive?
Correct Answer: A
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
0
0
0
0