VMware 5V0-91.20 Dumps Updated [Jan-2022] Get 100% Real Exam Questions! [Q26-Q41]

Share

[Jan-2022] Pass VMware 5V0-91.20 Exam in First Attempt Guaranteed!

Full 5V0-91.20 Practice Test and 115 unique questions with explanations waiting just for you, get it now!

NEW QUESTION 26
Review the following EDR query:
parent_name:outlook.exe AND -alliance_score_srstrust:* AND -digsig_result: "Signed' Which process would show in the query results?

  • A. Processes invoking outlook.exe that do not have an SRS Trust value and that are not digitally signed.
  • B. Processes invoked by outlook.exe that have an SRS Trust value and that are digitally signed.
  • C. Processes invoking outlook.exe that have an SRS Trust value and that are not digitally signed.
  • D. Processes invoked by outlook.exe that do not have an SRS Trust value and that are not digitally signed.

Answer: C

 

NEW QUESTION 27
Which reputation is processed with the lowest priority for Endpoint Standard?

  • A. Local White
  • B. Known Malware
  • C. Common White
  • D. Trusted White

Answer: B

 

NEW QUESTION 28
An analyst has investigated two alerts on two separate HR workstations and found that notepad.exe has established communication to another IP address.
Which rule will kill notepad.exe entirely if this activity is detected in the future?

  • A. **/system32/notepad.exe--> Communicates over the network --> Deny operation
  • B. **/system32/notepad.exe --> Runs or is Running --> Terminate process
  • C. **\system32\notepad.exe --> Communicates over the network --> Terminate process
  • D. **\system32\notepad.exe --> Runs or is Running --> Deny operation

Answer: B

 

NEW QUESTION 29
An administrator runs the following query in Audit and Remediation:
SELECT *
FROM users
WHERE UID >= 500;
How long will this query stay active and accept data from the sensors?

  • A. 30 days
  • B. 7 days
  • C. 14 days
  • D. 1 day

Answer: A

 

NEW QUESTION 30
An Enterprise EDR administrator is reviewing the Investigate page and believes they are receiving false positive hits from specific watchlist.
Which three options reduce future false positive hits from this watchlist? (Choose three.)

  • A. Disable the watchlist associated with the false positives.
  • B. Select edit watchlist and uncheck alert on hits.
  • C. Dismiss the watchlist hit.
  • D. Disable/remove the report associated with the false positives.
  • E. Modify policy rules to exclude the false positive directory.
  • F. Disable/remove the IOC associated with the false positives.

Answer: B,D,F

 

NEW QUESTION 31
A security policy states to enable Live Response by default across the enterprise. However, the team identified critical systems which should not support Live Response due to risk. The team needs to disable Live Response on selected systems.
From which page can this goal be accomplished?

  • A. API Access
  • B. Policy
  • C. Roles
  • D. Endpoints

Answer: C

 

NEW QUESTION 32
Which wildcard configuration applies a policy to all files and subfolders in a specific folder in Endpoint Standard?

  • A. C:\Program Files\example\$
  • B. C:\Program Files\example\*
  • C. C:\Program Files\example\$$
  • D. C:\Program Files\example\**

Answer: D

 

NEW QUESTION 33
An Endpoint Standard administrator finds a binary in the environment and decides to manually add the file hash to the Banned List.
Which reputation does the file now have?

  • A. Suspect/Heuristic Malware
  • B. Adware/PUP Malware
  • C. Known Malware
  • D. Company Black

Answer: A

 

NEW QUESTION 34
What is the meaning, if any, of the event Report write (removable media)?

  • A. This event would never occur. App Control does not report activity on removable media.
  • B. A Policy's device control setting 'Block writes to unapproved removable media' is set to Report Only. The event details show the process, file name, and hash modified or deleted on the removable media.
  • C. A Policy's device control setting 'Block writes to unapproved removable media' is set to Enabled. The event details show the process, file name, and hash modified or deleted on the removable media.
  • D. A Policy's device control setting 'Block writes to unapproved removable media' is set to Report Only. The event details show the process and file name modified or deleted on the unapproved removable media.

Answer: D

 

NEW QUESTION 35
A watchlist generates a false positive on the Triage Alerts page, so the watchlist must be updated.
How should this task be accomplished?

  • A. One can update watchlists from the Process Search Page.
  • B. Open the Watchlist Page and click the pencil button associated with the watchlist.
  • C. One can update watchlists directly on the Triage Alerts Page using the pencil icon.
  • D. Open the process analysis page and select the Add Watchlist Exclusion option from the Actions menu.

Answer: C

 

NEW QUESTION 36
A Carbon Black Cloud Endpoint Standard analyst is testing different search operator combinations.
Which two queries produce the same result? (Choose two.)

  • A. process_name:chrome.exe OR NOT netconn_domain:google.com
  • B. process_name:chrome.exe AND NOT netconn_domain:google.com
  • C. process_name:chrome.exe netconn_domain:google.com
  • D. process_narne:chrome.exe NOT netconn_domain:google.com
  • E. process_name:chrome.exe OR netconn_domain:google.com

Answer: A,D

 

NEW QUESTION 37
What are three ways to ignore a feed report within the EDR user interface? (Choose three.)

  • A. Investigations page
  • B. Alert Dashboard page
  • C. After marking a feed alert as a false positive
  • D. Search Threat Reports page
  • E. Threat Reports Details page
  • F. Threat Intelligence Feeds page

Answer: C,E,F

Explanation:
Reference:
Prevent-False-Positives/ta-p/64413

 

NEW QUESTION 38
An Endpoint Standard administrator is working with an IT team to explicitly permit specific applications from the environment using both the IT Tools and Certs Approved List features.
Once applied, which reputation would these applications be classified under for processing?

  • A. Trusted White
  • B. Local White
  • C. Company White
  • D. Common White

Answer: A

 

NEW QUESTION 39
An analyst navigates to the alerts page in Endpoint Standard and sees the following:

What does the yellow color represent on the left side of the row?

  • A. It is an alert from a watchlist rather than the analytics engine.
  • B. It is a dismissed alert within the user interface.
  • C. It is an observed alert and may indicate suspicious behavior.
  • D. It is a threat alert and warrants immediate investigation.

Answer: A

 

NEW QUESTION 40
An administrator needs to manage a group of sensors from within the console.
Which three actions are available for sensors within the Sensor Group? (Choose three.)

  • A. Uninstall
  • B. Disable
  • C. Move to group
  • D. Ban
  • E. Share Settings
  • F. Restart

Answer: A,C,F

 

NEW QUESTION 41
......

Get Latest 5V0-91.20 Dumps Exam Questions in here: https://www.dumpsquestion.com/5V0-91.20-exam-dumps-collection.html