5V0-91.20 Exam Questions
116 real 5V0-91.20 exam questions with expert-verified answers and explanations. Page 2 of 3.
- Question #51
An analyst is investigating a specific alert in Endpoint Standard. The analyst sees the investigate button from the alert triage page and sees the following: [IMAGE CONTENT] Which...
- Question #52
Examine the following EDR query: file_desc:"Windows Command Processor" AND -process_name:cmd.exe Which process will show in the query results?
- Question #53
Carbon Black App Control maintains an inventory of all interesting (executable) files on endpoints where the agent is installed. What is the initial inventory procedure called, and...
- Question #54
This search is entered into the process search page: notepad.exe Which three statements about this query are true? (Choose three.)
- Question #55
A company wants to implement the strictest security controls for computers on which the software seldom changes (i.e., servers or single-purpose systems). Which Enforcement Level i...
- Question #56
What does the Aggressive setting do when configured in Local Scan Settings?
- Question #57
Review the following search: childproc_name:"rundll32.exe" AND -digsig_result:"Signed" AND path:c:\windows\* What is this search looking for?
- Question #58
Which reputation is processed with the lowest priority for Endpoint Standard?
- Question #59
Which statement is true about Carbon Black Live Response (CBLR)?
- Question #60
Management has directed that the SOC team be enabled to create global file bans via the App Control API. How would this be configured in the App Control Console?
- Question #61
An administrator is creating a query per policy for Audit and Remediation. The administrator ran several recommended queries already but notices they are unable to run the same rec...
- Question #62
An Endpoint Standard administrator finds a binary in the environment and decides to manually add the file hash to the Banned List. Which reputation does the file now have?
- Question #63
Given an event rule: Approve nVidia Drivers, changes the local state to Approved for file writes or execution blocks when the publisher is NVIDIA Corporation. How is an alert creat...
- Question #64
An Endpoint Standard analyst runs the following query in the graphic below: Which three statements are true from the results shown? (Choose three.)
- Question #65
An administrator receives an alert with the TTP_DATA_TO_ENCRYPTION. What is known about the alert based on this TTP even if other parts of the alert are unknown?
- Question #66
How can an analyst disregard alerts on multiple devices with the least amount of administrative effort?
- Question #67
What is the meaning, if any, of the Event Report write (removable media)?
- Question #68
Which action is only available for the "Performs any operation" and "Performs any API Operation" operation attempts?
- Question #69
Review this EDR query: childproc_name:whoami.exe AND childproc_name:hostname.exe AND childproc_name:tasklist.exe AND childproc_name:ipconfig.exe Which process would show in the que...
- Question #70
A Carbon Black Cloud analyst needs to identify the Internet Explorer extensions installed on Windows endpoints. Which Live Query statement will successfully query these items?
- Question #71
Which statement is true about configuring VMware Carbon Black Application Control for use on non-persistent virtual machines (VM's)?
- Question #72
An administrator uses the following Enterprise EDR search query to show web browsers spawning nonbrowser child processes that connect over the network: (parent_name:chrome.exe OR p...
- Question #73
Given the following query: SELECT * FROM users WHERE UID >= 500; Which statement is correct?
- Question #74
What is the maximum number of binaries (hashes) that can be banned using the web console?
- Question #75
An administrator wants to allow files to run from a network share. Which rule type should the administrator configure?
- Question #76
An analyst is reviewing an alert in Enterprise EDR from a custom watchlist. The analyst disagrees with the alert severity rating. How can the analyst change the alert severity valu...
- Question #77
What information does the Alert Details panel provide on the Alert Triage page in Endpoint Standard?
- Question #78
An analyst on the security team noticed that several alerts are false positives within Enterprise EDR. The analyst disables the IOC within the report from those alerts. Which state...
- Question #79
Which identifier is shared by all events when an alert is investigated?
- Question #80
An Enterprise EDR administrator wants to use Watchlists curated by VMware Carbon Black and other threat intelligence specialists. How should the administrator add these curated Wat...
- Question #81
An incorrectly constructed watchlist generates 10,000 incorrect alerts. How should an administrator resolve this issue?
- Question #82
Which list below captures all Enforcement Levels for App Control policies?
- Question #83
A company uses Audit and Remediation to check configurations and adhere to compliance regulations. The regulations require monthly reporting and twelve months of data retained. How...
- Question #84
An administrator needs to query all endpoints in the HR group for instances of an obfuscated copy of cmd.exe. Given this Enterprise EDR query: process_name:cmd.exe AND device_group...
- Question #85
App Control System Health email alerts for excessive agent backlog are occurring hourly. This is overwhelming the security analysts, and they would like to reduce the notifications...
- Question #86
An analyst wants to block an application's specific behavior but does not want to kill the process entirely as it is heavily used on workstations. The analyst needs to use a Blocki...
- Question #87
An administrator wants to query the status of the firewall for all endpoints. The administrator will query the registry key found here HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\S...
- Question #88
An organization leverages a commonly used software distribution tool to manage deployment of enterprise software and updates. Custom rules are a suitable option to ensure the appro...
- Question #89
How often do watchlists run?
- Question #90
Which statement should be used when constructing queries in Carbon Black Audit and Remediation, Live Query?
- Question #91
Which wildcard configuration applies a policy to all files and subfolders in a specific folder in Endpoint Standard?
- Question #92
An alert for a device running a proprietary application is tied to a vital business operation. Which action is appropriate to take?
- Question #93
An administrator needs to check configurations using Audit across several policies and locations within the organization. How can the administrator run the query to only these spec...
- Question #94
A process wrote an executable file as detailed in the following event: Timestamp: Jan 15, 2020 16:00:32 Source: USWIN-MGMT1 Subtype: New Unapproved File To Command: File Path: c:\w...
- Question #95
Which enforcement level does not block unapproved files but will block files that have been specifically banned?
- Question #96
An administrator has updated a Threat Intelligence Report by turning it into a watchlist and needs to disable (Ignore) the old Threat Intelligence Report. Where in the UI is this a...
- Question #97
An analyst navigates to the alerts page in Endpoint Standard and sees the following: [Image of a table with alerts] What does the yellow color represent on the left side of the row...
- Question #98
An administrator is concerned that someone may be using unauthorized commands from cmd.exe. These commands are not considered suspicious or malicious, and there is no policy based...
- Question #99
An analyst has investigated multiple alerts on a number of HR workstations and found that java.exe is attempting to PowerShell. Of the Windows workstations in question, the analyst...
- Question #100
Review the following query: path:c:\program\ files\ (x86)\microsoft How would this query input term be interpreted?