[Q29-Q46] Verified 5V0-93.22 dumps Q&As - Pass Guarantee or Full Refund [Dec-2023]

Share

Verified 5V0-93.22 dumps Q&As - Pass Guarantee or Full Refund [Dec-2023]

5V0-93.22 PDF Dumps | Dec 31, 2023 Recently Updated Questions 

NEW QUESTION # 29
A company wants to prevent an executable from running in their organization. The current reputation for the file is NOT LISTED, and the machines are in the default standard policy.
Which action should be taken to prevent the file from executing?

  • A. Use Live Response to kill the process.
  • B. Add the hash to the MALWARE list.
  • C. Use Live Response to delete the file.
  • D. Add the hash to the company banned list.

Answer: D

Explanation:
Explanation
The company banned list is a feature of VMware Carbon Black Cloud Endpoint Standard that allows administrators to prevent specific files from running on the endpoints by their hash values. The company banned list has a higher priority than the file reputation, so even if the file is not listed or unknown by Carbon Black, it will be blocked if its hash is in the company banned list. Adding the hash to the company banned list is the most effective and efficient way to prevent the file from executing on the endpoints. The other options are either not feasible or not scalable. Adding the hash to the malware list would not work, because the malware list is a global list maintained by Carbon Black, and administrators cannot add hashes to it. Using Live Response to kill the process or delete the file would only work for one endpoint at a time, and it would not prevent the file from running again if it is still present on the endpoint or downloaded from another source. References: Carbon Black Cloud Endpoint Standard - Technical Overview, Add Hash to Banned List, Carbon Black Cloud: How to Add a SHA256 Hash to Approved/Banned List


NEW QUESTION # 30
An administrator is investigating an alert and reads a summary that says:
The application powershell.exe was leveraged to make a potentially malicious network connection.
Which action should the administrator take immediately to block that connection?

  • A. Click Delete Application
  • B. Click Export Alert
  • C. Click Drop Connection
  • D. Click Quarantine Asset

Answer: C

Explanation:
Explanation
The correct answer is to click Drop Connection, which is a feature of VMware Carbon Black Cloud Endpoint Standard that allows the administrator to immediately terminate a network connection that is deemed malicious or suspicious. This feature can be accessed from the Alert Details page, where the administrator can see the application, process, and destination IP address of the connection. By clicking Drop Connection, the administrator can block the connection without affecting the rest of the system or network. This is a quick and effective way to stop a potential threat from communicating with a remote server or exfiltrating data. References: = VMware Carbon Black Cloud Endpoint Standard Skills Reference Materials, Section 4.3:
Investigate Alerts, Subsection 4.3.2: Drop Connection.


NEW QUESTION # 31
An administrator notices that a sensor's local AV signatures are out-of-date.
What effect does this have on newly discovered files?

  • A. The sensor prompts the end user to allow or deny the file.
  • B. The reputation is determined by cloud reputation.
  • C. The sensor automatically blocks the new file.
  • D. The sensor is unable to block a malicious file.

Answer: B


NEW QUESTION # 32
Which command is used to immediately terminate a current Live Response session?

  • A. execfg
  • B. detach -q
  • C. kill
  • D. delete

Answer: B


NEW QUESTION # 33
An administrator has dismissed a group of alerts and ticked the box for "Dismiss future instances of this alert on all devices in all policies". There is also a Notification configured to email the administrator whenever an alert of the same Severity occurs. The following day, a new alert is added to the same group of alerts.
How will this alert be handled?

  • A. The alert will show when the Dismissed filter is selected on the Alerts page, and a Notification email will be sent.
  • B. The alert will show when Not Dismissed filter is selected on Alerts page, but a Notification email will not be sent.
  • C. The alert will show when the Not Dismissed filter is selected on Alerts page, and a Notification email will be sent.
  • D. The alert will show when the Dismissed filter is selected on Alerts page, but a Notification email will not be sent.

Answer: D

Explanation:
Explanation
When an administrator dismisses a group of alerts and ticks the box for "Dismiss future instances of this alert on all devices in all policies", the following happens:
The alerts are moved to the Dismissed tab on the Alerts page, and the alert count is reduced accordingly.
The alerts are no longer displayed on the Dashboard or the Device page.
The alerts are no longer considered for the device health score or the policy health score.
The alerts are no longer sent to any configured Notifications.
Therefore, if a new alert is added to the same group of alerts, it will also be dismissed automatically and follow the same rules as above. This means that the alert will show when the Dismissed filter is selected on Alerts page, but a Notification email will not be sent. References: VMware Carbon Black Cloud Endpoint Standard Skills Reference Materials, Section 6.2: Dismissing Alerts, Page 46.


NEW QUESTION # 34
An administrator needs to fully analyze the relevant information of an event stored in the VMware Carbon Black Cloud.
On which page can this information be found?

  • A. Live Query
  • B. Investigate
  • C. Enforce
  • D. Inventory

Answer: B


NEW QUESTION # 35
A recent application has been blocked using hash ban, which is an indicator that some users attempted an unexpected activity. Even though the activity was blocked, the security administrator wants to further investigate the attempt in VMware Carbon Black Cloud Endpoint Standard.
Which page should the administrator navigate to for a graphical view of the event?

  • A. Process Analysis
  • B. Audit Log
  • C. Alert Triage
  • D. Watchlists

Answer: A

Explanation:
Explanation
The Process Analysis page in VMware Carbon Black Cloud Endpoint Standard is a graphical view of the event that shows the process tree, the event timeline, and the event details. The process tree displays the parent-child relationships of the processes involved in the event, as well as the actions taken by the policy, such as blocking or alerting. The event timeline shows the chronological sequence of the events, such as process executions, file modifications, network connections, and registry changes. The event details provide more information about the selected event, such as the process name, path, hash, command line, reputation, and Carbon Black TTPs. The Process Analysis page can help the security administrator to investigate the hash ban event and understand the context and impact of the blocked application. References: Carbon Black Cloud Endpoint Standard - Technical Overview, Add Hash to Banned List, Carbon Black Cloud: How to Add a SHA256 Hash to Approved/Banned List


NEW QUESTION # 36
An administrator has been tasked with preventing the use of unauthorized USB storage devices from being used in the environment.
Which item needs to be enabled in order to enforce this requirement?

  • A. Choose to disable USB device access on each endpoint from the Inventory page.
  • B. Select the option to block USB devices from the Reputation page.
  • C. Elect to approve only allowed USB devices from the USB Devices page.
  • D. Enable the Block access to all unapproved USB devices within the policies option.

Answer: C

Explanation:
Explanation
To prevent the use of unauthorized USB storage devices, the administrator needs to enable the USB Device Control feature in the VMware Carbon Black Cloud Endpoint Standard. This feature allows the administrator to approve or block specific USB devices based on their vendor ID, product ID, serial number, and device type. The administrator can also set a default action for unapproved USB devices, such as block, read-only, or allow. The administrator can manage the USB devices from the USB Devices page under the Settings menu. From this page, the administrator can view the list of USB devices that have been detected by the endpoints, and elect to approve only the allowed USB devices. The administrator can also export or import the list of approved USB devices for backup or replication purposes. References:
VMware Carbon Black Cloud Endpoint Standard Skills Reference Materials, Module 4: USB Device Control, pages 4-1 to 4-9.
VMware Carbon Black Cloud Endpoint Standard User Guide, Chapter 11: USB Device Control, pages
147-152.


NEW QUESTION # 37
An administrator has configured a permission rule with the following options selected:
Application at path: C:\Program Files\**
Operation Attempt: Performs any operation
Action: Bypass
What is the impact, if any, of using the wildcards in the path?

  • A. Only executable files in the "Program Files" folder will be ignored, includingmalware files.
  • B. No Files will be ignored from the "Program Files" director/, but Malware in the "Program Files" directory will continue to be blocked.
  • C. All executable files in the "Program Files" folder and subfolders will be ignored, includingmalware files.
  • D. Executable files in the "Program Files" folder will be blocked.

Answer: C


NEW QUESTION # 38
An administrator would like to proactively know that something may get blocked when putting a policy rule in the environment.
How can this information be obtained?

  • A. Put the rules in and see what happens to the endpoints.
    D Determine what would happen based on previously used antivirus software
  • B. Search the data using the test rule functionality.
    B Examine log files to see what would be impacted

Answer: B


NEW QUESTION # 39
Which port does the VMware Carbon Black sensor use to communicate to VMware Carbon Black Cloud?

  • A. 0
  • B. 1
  • C. 2
  • D. 3

Answer: B


NEW QUESTION # 40
An administrator needs to configure a policy for macOS and Linux Sensors, not enabling settings which are only applicable to Windows.
Which three settings are only applicable to Sensors on the Windows operating system? (Choose three.)

  • A. Delay execute for cloud scan
  • B. Expedited background scan
  • C. Scan execute on network drives
    F Require code to uninstall sensor
  • D. Submit unknown binaries for analysis
  • E. Allow user to disable protection

Answer: A,B,C

Explanation:
Explanation
These settings are part of the Prevention policy settings for Windows sensors, and they are not available for macOS or Linux sensors. These settings have the following functions:
Delay execute for cloud scan: This setting allows the sensor to delay the execution of unknown files until the cloud scan result is returned. This setting can prevent potential malware from running before the cloud reputation is determined.
Expedited background scan: This setting allows the sensor to perform a background scan of the endpoint as soon as possible after the sensor is installed or updated. This setting can help to identify and remediate any existing threats on the endpoint.
Scan execute on network drives: This setting allows the sensor to scan files that are executed from network drives. This setting can help to protect the endpoint from network-based attacks.
The other settings are applicable to sensors on both Windows and non-Windows operating systems. B. Allow user to disable protection is a setting that allows the user to temporarily disable the sensor protection from the system tray icon. C. Submit unknown binaries for analysis is a setting that allows the sensor to upload unknown files to the cloud for analysis and reputation. F. Require code to uninstall sensor is a setting that requires the user to enter a code to uninstall the sensor from the endpoint. References:
Prevention Policy Settings - VMware Docs, Windows Settings section.
Prevention Policy Settings - VMware Docs, macOS and Linux Settings section.


NEW QUESTION # 41
What is a security benefit of VMware Carbon Black Cloud Endpoint Standard?

  • A. Policy rules that can be tested by selecting test rule next to the desired operation attempt
  • B. Visibility into the entire attack chain and customizable threat intelligence that can be used to gain insight into problems
  • C. Customizable threat feeds that plug into a single agent and single console
  • D. A flexible query scheduler that can be used to gather information about the environment

Answer: B

Explanation:
Explanation
A security benefit of VMware Carbon Black Cloud Endpoint Standard is that it provides visibility into the entire attack chain and customizable threat intelligence that can be used to gain insight into problems.
Endpoint Standard uses behavioral analytics to detect and prevent malicious activity on endpoints, and also collects comprehensive event data that can be used to investigate and respond to incidents. Endpoint Standard also allows administrators to customize their threat intelligence feeds and alerts, and integrate with other security tools and platforms. This way, administrators can gain a deeper understanding of the threats facing their organization and take appropriate actions to mitigate them. The other options are incorrect because they are not security benefits of Endpoint Standard. Option A is incorrect because a flexible query scheduler is a feature of VMware Carbon Black Audit and Remediation, not Endpoint Standard. Option C is incorrect because customizable threat feeds are a feature of VMware Carbon Black Enterprise EDR, not Endpoint Standard. Option D is incorrect because policy rules that can be tested by selecting test rule next to the desired operation attempt are a feature of VMware Carbon Black App Control, not Endpoint Standard. References: VMware Carbon Black Cloud Endpoint Standard Datasheet, Carbon Black Cloud Endpoint Standard - Technical Overview


NEW QUESTION # 42
A VMware Carbon Black managed endpoint is showing up as an inactive device in the console.
What is the threshold, in days, before a machine shows as inactive?

  • A. 90 days
  • B. 60 days
  • C. 30 days
  • D. 7 days

Answer: D

Explanation:
Explanation
According to the VMware Carbon Black Cloud Endpoint Standard User Guide, the threshold, in days, before a machine shows as inactive in the console is 7 days. An inactive device is a device that has not communicated with the Carbon Black Cloud console for more than 7 days. The console displays the last communication time for each device on the Endpoints page. The administrator can use the Inactive Devices filter to view all the inactive devices in the organization. The administrator can also use the Device Status widget on the Dashboard page to see the number and percentage of inactive devices in the organization. The administrator can take various actions to resolve the inactive device issue, such as:
Check the network connectivity and firewall settings of the device
Check the sensor status and version on the device
Check the policy settings and rules applied to the device
Reinstall the sensor on the device
Delete the device from the console if it is no longer in use References:
VMware Carbon Black Cloud Endpoint Standard User Guide, page 14, Inactive Devices section.


NEW QUESTION # 43
What connectivity is required for VMware Carbon Black Cloud Endpoint Standard to perform Sensor Certificate Validation?

  • A. TCP/80 to GoDaddy CRL URL (crl.godaddy.com and ocsp.godaddy.com)
  • B. TCP/443 to GoDaddy OCSP and CRL URLs (crl.godaddy.com and ocsp.godaddy.com)
  • C. TCP/80 to GoDaddy OCSP and CRL URLs (crl.godaddy.com and ocsp.godaddy.com)
  • D. TCP/443 to GoDaddy CRL URL (crl.godaddy.com and ocsp.godaddy.com)

Answer: B


NEW QUESTION # 44
What are the highest and lowest file reputation priorities, respectively, in VMware Carbon Black Cloud?

  • A. Priority 1: Ignore, Priority 11: Unknown
  • B. Priority 1: Company Allowed, Priority 11: Not Listed/Adaptive White
  • C. Priority 1: Known Malware, Priority 11: Common White
  • D. Priority 1: Unknown, Priority 11: Ignore

Answer: A


NEW QUESTION # 45
Which scenario would qualify for the "Local White" Reputation?

  • A. The file was added as an IT took
  • B. The hash was previously analyzed, AND it is not on any known good or bad lists.
  • C. The file was signed using a trusted certificate.
  • D. The hash was not on any known good or known bad lists, AND the file is signed.

Answer: A


NEW QUESTION # 46
......

5V0-93.22 Exam Questions – Valid 5V0-93.22 Dumps Pdf: https://www.exams4sures.com/VMware/5V0-93.22-practice-exam-dumps.html

5V0-93.22 Practice Test Questions Answers Updated 62 Questions: https://drive.google.com/open?id=1Abr-ScYt4Z_XkFqedjNugU9QTYFSkbH-