Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free VMware Carbon Black Cloud Endpoint Standard Skills 5V0-93.22 Exam Questions

Page: 1 / 6 Total 60 questions

Want more questions? Get Premium Access.

Question 1

An administrator is investigating an alert and reads a summary that says:

The application powershell.exe was leveraged to make a potentially malicious network connection.

Which action should the administrator take immediately to block that connection?

Correct Answer: D. Click Drop Connection

Question 2

Is it possible to search for unsigned files in the console?

Correct Answer: C. Yes, by using the search: process_publisher_state:FILE_SIGNATURE_STATE_UNSIGNED D. Yes, by looking at signed and unsigned executables in the environment and seeing if another difference can be found, thus locating unsigned files in the environment.

Question 3

An administrator has determined that the following rule was the cause for an unexpected block:

[Suspected malware] [Invokes a command interpreter] [Terminate process]

All reputations for the process which was blocked show SUSPECT_MALWARE.

Which reputation was used by the sensor for the decision to terminate the process?

Correct Answer: D. Effective reputation

Question 4

The VMware Carbon Black Cloud Sensor is not able to establish connectivity to the VMware Carbon Black Cloud Content Management URL over the standard SSL port TCP/443.

Which port, if any, will be the tailback?

Correct Answer: C. TCP/8443

Question 5

What is a security benefit of VMware Carbon Black Cloud Endpoint Standard?

Correct Answer: B. Visibility into the entire attack chain and customizable threat intelligence that can be used to gain insight into problems

Question 6

Which VMware Carbon Black Cloud process is responsible for uploading event reporting to VMware Carbon Black Cloud?

Correct Answer: D. Sensor Service (RepMqr

Question 7

A company wants to prevent an executable from running in their organization. The current reputation for the file is NOT LISTED, and the machines are in the default standard policy.

Which action should be taken to prevent the file from executing?

Correct Answer: D. Add the hash to the company banned list.

Question 8

Which scenario would qualify for the "Local White" Reputation?

Correct Answer: A. The file was added as an IT took

Question 9

An organization is seeing a new malicious process that has not been seen before.

Which tool can be used to block this process?

Correct Answer: A. Policy rules

Question 10

An administrator needs to create a search, but it must exclude "system.exe".

How should this task be completed?

Correct Answer: D. -process_name:system.exe