VMware Carbon Black Portfolio Skills - 5V0-91.20 模擬練習
An administrator needs to query all endpoints in the HR group for instances of an obfuscated copy of cmd.exe.
Given this Enterprise EDR query:
process_name:cmd.exe AND device_group:HR AND NOT enriched:true
Which example could be added to the query to provide the desired results?
Given this Enterprise EDR query:
process_name:cmd.exe AND device_group:HR AND NOT enriched:true
Which example could be added to the query to provide the desired results?
正解: A
Which Live Query statement is properly constructed?
正解: A
An analyst has investigated multiple alerts on a number of HR workstations and found that java.exe is attempting to PowerShell. Of the Windows workstations in question, the analyst has also found that Java is installed in multiple locations. The analyst needs to block java.exe from this type of operation.
Which rule meets this need?
Which rule meets this need?
正解: B
Which statement should be used when constructing queries in Carbon Black Audit and Remediation, Live Query?
正解: C
A watchlist generates a false positive on the Triage Alerts page, so the watchlist must be updated.
How should this task be accomplished?
How should this task be accomplished?
正解: C
What does the Aggressive setting do when configured in Local Scan Settings?
正解: B
An active compromise is detected on an endpoint. Due to current policies, the compromise was detected but not terminated.
What would be an appropriate action to end the current communication between the device and the attacker?
What would be an appropriate action to end the current communication between the device and the attacker?
正解: D