Labour Day Sale Limited Time 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 713PS592

Note! The 5V0-91.20 Exam is no longer available.

5V0-91.20 VMware Carbon Black Portfolio Skills Questions and Answers

Questions 4

An analyst is reviewing an alert in Enterprise EDR from a custom watchlist. The analyst disagrees with the alert severity rating.

How can the analyst change the alert severity value, if this is possible?

Options:

A.

The alert severity is assigned by the backend analytics.

B.

The alert severity is not configurable.

C.

Change the alert severity on the watchlist.

D.

Change the alert severity on the report.

Buy Now
Questions 5

An administrator runs the following query in Audit and Remediation:

SELECT *

FROM users

WHERE UID >= 500;

How long will this query stay active and accept data from the sensors?

Options:

A.

1 day

B.

7 days

C.

14 days

D.

30 days

Buy Now
Questions 6

Refer to the exhibit:

5V0-91.20 Question 6

Which statement is true in regards to communication between the sensor and server?

Options:

A.

The sensor must be able to resolve the name cb.yourcompany.com.

B.

The server must have an entry in the host file for cb.yourcompany.com.

C.

The communication is unencrypted.

D.

The sensor will communicate on a non-default port.

Buy Now
Questions 7

An administrator is interested in upgrading endpoints to the latest release in VMware Carbon Black App Control (V8.1.4+).

What is the first step to make a new agent available for installation or upgrade?

Options:

A.

Download from the Carbon Black Cloud Back End

B.

Download from the Carbon Black App Control Server

C.

Download from the Carbon Black User Exchange

D.

Download from the Carbon Black Software Reputation Service (SRS)

Buy Now
Questions 8

Why would a sensor have a status of "Inactive"?

The sensor has not checked in within the last 30 days.

The sensor has been uninstalled from the endpoint for more than 30 days.

The device has been put in bypass for the last 30 days.

The sensor has been in disabled mode for more than 30 days.

Options:

Buy Now
Questions 9

What are three ways to ignore a feed report within the EDR user interface? (Choose three.)

Options:

A.

Threat Reports Details page

B.

Threat Intelligence Feeds page

C.

Investigations page

D.

Search Threat Reports page

E.

Alert Dashboard page

F.

After marking a feed alert as a false positive

Buy Now
Questions 10

How often do watchlists run?

Options:

A.

Every 10 minutes

B.

Every 5 minutes

C.

Watchlists can be configured to run at scheduled intervals

D.

Every 30 minutes

Buy Now
Questions 11

An administrator wants to query the status of the firewall for all endpoints. The administrator will query the

registry key found here

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy

\StandardProfile.

To make the results easier to understand, the administrator wants to return either enabled or disabled for the results, rather than the value from the registry key.

Which SQL statement will rewrite the output based on a specific result set returned from the system?

Options:

A.

CASE

B.

AS

C.

ALTER

D.

SELECT

Buy Now
Questions 12

How is a new Alert of type Event Alert created whenever an endpoint is added or deleted and send emails for the App Control admin whenever these events occur?

Options:

A.

Add filter in Event Properties for Subtype Endpoint added and Endpoint deleted. Click Create and add the App Control admin email, and then click Create &. Exit.

B.

Add filter in Event Properties for Subtype Computer added and Computer deleted. Add the App Control admin email, and then click Create & Exit.

C.

Add filter in Event Properties for Subtype Computer added and Computer deleted. Click Create and add the App Control admin email, and then click Create & Exit.

D.

Add filter in Event Properties for Subtype Computer modified. Add the App Control admin email, and then click Create & Exit.

Buy Now
Questions 13

Review the following EDR query:

(parent_name:powershell.exe OR parent_name:cmd.exe) AND netconn_count:[l TO *]

Which process would show in the query results?

Options:

A.

Processes invoked by Powershell.exe and cmd.exe with a single network connection event

B.

Processes invoking Powershell.exe and cmd.exe with multiple network connection events

C.

Processes invoked by Powershell.exe or cmd.exe with any number of network connection events

D.

Processes invoking Powershell.exe or cmd.exe with multiple network connection events

Buy Now
Questions 14

Which strategy should be used to purge inactive bans from the web console?

Options:

A.

Schedule an add-hoc cron job to remove

B.

Use a pre-configured system cron job daily to remove them

C.

Run the cbbannlng script on the EDR server

D.

Go to the hashes page on the web console and remove them

Buy Now
Questions 15

An analyst wants to block an application's specific behavior but does not want to kill the process entirely as it is heavily used on workstations. The analyst needs to use a Blocking and Isolation Action to ensure that the process is kept alive while blocking further unwanted activity.

Which Blocking and Isolation Action should the analyst use to accomplish this goal?

Options:

A.

Log Operation

B.

Deny Operation

C.

Terminate Process

D.

Block Process

Buy Now
Questions 16

There is a need to ignore all activity at an application path.

Which rule definition should be used to address this need?

Options:

A.

Application at Path, Performs any operation, Bypass

B.

Application at Path, Runs or is Running, Bypass

C.

Application at Path, Runs or is Running, Allow & Log

D.

Application at Path, Performs any operation, Allow & Log

Buy Now
Questions 17

Carbon Black App Control maintains an inventory of all interesting (executable) files on endpoints where the agent is installed.

What is the initial inventory procedure called, and how can this process be triggered?

Options:

A.

Inventorying; enable Discovery mode

B.

Baselining; install the agent

C.

Discovery; place agent into Disabled mode

D.

Initialization; move agent out of Disabled mode

Buy Now
Exam Code: 5V0-91.20
Exam Name: VMware Carbon Black Portfolio Skills
Last Update: Apr 14, 2023
Questions: 116