[Q36-Q55] リアルな5V0-93.22は100%カバー試験問題をゲット [2024年05月]

Share

リアルな5V0-93.22は100%カバー試験問題をゲット [2024年05月]

問題集まとめ概要は5V0-93.22試験問題集はここ


VMware 5V0-93.22の認定試験は、60問の多肢選択問題から構成され、105分以内に完了する必要があります。試験に合格するには、100〜500のスケールで最低300点以上を取得する必要があります。VMwareは、試験を受ける前に、エンドポイントセキュリティの最低6か月の経験とエンドポイント保護プラットフォームの熟知を推奨しています。試験に合格すると、VMware Carbon Black Cloud Endpoint Standard Skillsバッジを取得し、VMware Carbon Black Cloud Endpoint Standardを使用してエンドポイントセキュリティソリューションを実装および管理する専門知識が認定されます。

 

質問 # 36
An administrator wants to find information about real-world prevention rules that can be used in VMware Carbon Black Cloud Endpoint Standard.
How can the administrator obtain this information?

  • A. Refer to the VMware Carbon Black Cloud sensor install guide.
  • B. Refer to the TAU-TIN's on the VMware Carbon Black community page.
  • C. Refer to an external report from other security vendors to obtain solutions.
  • D. Refer to VMware Carbon Black Cloud user guide.

正解:B

解説:
Explanation
TAU-TIN stands for Threat Analysis Unit - Threat Intelligence Notification, which is a series of documents published by the VMware Carbon Black Threat Analysis Unit (TAU) on the VMware Carbon Black community page. These documents provide information about various threats, such as ransomware, malware, and info-stealers, that are detected and prevented by VMware Carbon Black Cloud Endpoint Standard. They also provide recommendations for creating prevention rules based on the observed behavior and indicators of compromise (IOCs) of the threats. For example, the TAU-TIN document for PyCrypter Ransomware1 provides the following prevention rule:
process_name:python.exe AND childproc_name:cmd.exe AND childproc_cmdline:*vssadmin* This rule will prevent any Python process from spawning a command prompt that executes the vssadmin command, which is used by PyCrypter to delete volume shadow copies and prevent data recovery.
Therefore, by referring to the TAU-TIN's on the VMware Carbon Black community page, an administrator can find information about real-world prevention rules that can be used in VMware Carbon Black Cloud Endpoint Standard. References:
Home - Carbon Black Community, Welcome to the VMware Carbon Black User Exchange section.
TAU-TIN - PyCrypter Ransomware - Carbon Black Community, Threat Analysis Unit - Threat Intelligence Notification section.


質問 # 37
An administrator has configured a permission rule with the following options selected:
Application at path: C:\Program Files\**
Operation Attempt: Performs any operation
Action: Bypass
What is the impact, if any, of using the wildcards in the path?

  • A. Executable files in the "Program Files" folder will be blocked.
  • B. No Files will be ignored from the "Program Files" director/, but Malware in the "Program Files" directory will continue to be blocked.
  • C. Only executable files in the "Program Files" folder will be ignored, includingmalware files.
  • D. All executable files in the "Program Files" folder and subfolders will be ignored, includingmalware files.

正解:D


質問 # 38
An administrator needs to create a search, but it must exclude "system.exe".
How should this task be completed?

  • A. #process_name:system.exe
  • B. <process_name:system.exe>
  • C. -process_name:system.exe
  • D. *process_name:system.exe

正解:C


質問 # 39
An administrator wants to prevent a spreadsheet from being misused to run malicious code, while minimizing the risk of breaking normal operations of a spreadsheet.
Which rule should be used?

  • A. **\excel.exe [Runs malware] [Deny operation]
  • B. **\excel.exe [Invokes a command interpreter] [Deny operation]
  • C. **/Microsoft Excel.app/** [Communicates over the network] [Terminate process]
  • D. **\Microsoft Office\** [Runs external code] [Terminate process]

正解:B


質問 # 40
An administrator is investigating an alert and reads a summary that says:
The application powershell.exe was leveraged to make a potentially malicious network connection.
Which action should the administrator take immediately to block that connection?

  • A. Click Delete Application
  • B. Click Quarantine Asset
  • C. Click Export Alert
  • D. Click Drop Connection

正解:D

解説:
Explanation
The correct answer is to click Drop Connection, which is a feature of VMware Carbon Black Cloud Endpoint Standard that allows the administrator to immediately terminate a network connection that is deemed malicious or suspicious. This feature can be accessed from the Alert Details page, where the administrator can see the application, process, and destination IP address of the connection. By clicking Drop Connection, the administrator can block the connection without affecting the rest of the system or network. This is a quick and effective way to stop a potential threat from communicating with a remote server or exfiltrating data. References: = VMware Carbon Black Cloud Endpoint Standard Skills Reference Materials, Section 4.3:
Investigate Alerts, Subsection 4.3.2: Drop Connection.


質問 # 41
In which tab of the VMware Carbon Black Cloud interface can sensor status details be found?

  • A. Inventory > Sensor groups
  • B. Inventory > Sensors
  • C. Enforce > Policies
  • D. Inventory > Endpoints

正解:D


質問 # 42
What is a security benefit of VMware Carbon Black Cloud Endpoint Standard?

  • A. Customizable threat feeds that plug into a single agent and single console
  • B. Policy rules that can be tested by selecting test rule next to the desired operation attempt
  • C. A flexible query scheduler that can be used to gather information about the environment
  • D. Visibility into the entire attack chain and customizable threat intelligence that can be used to gain insight into problems

正解:D

解説:
Explanation
A security benefit of VMware Carbon Black Cloud Endpoint Standard is that it provides visibility into the entire attack chain and customizable threat intelligence that can be used to gain insight into problems.
Endpoint Standard uses behavioral analytics to detect and prevent malicious activity on endpoints, and also collects comprehensive event data that can be used to investigate and respond to incidents. Endpoint Standard also allows administrators to customize their threat intelligence feeds and alerts, and integrate with other security tools and platforms. This way, administrators can gain a deeper understanding of the threats facing their organization and take appropriate actions to mitigate them. The other options are incorrect because they are not security benefits of Endpoint Standard. Option A is incorrect because a flexible query scheduler is a feature of VMware Carbon Black Audit and Remediation, not Endpoint Standard. Option C is incorrect because customizable threat feeds are a feature of VMware Carbon Black Enterprise EDR, not Endpoint Standard. Option D is incorrect because policy rules that can be tested by selecting test rule next to the desired operation attempt are a feature of VMware Carbon Black App Control, not Endpoint Standard. References: VMware Carbon Black Cloud Endpoint Standard Datasheet, Carbon Black Cloud Endpoint Standard - Technical Overview


質問 # 43
A security administrator needs to review the Live Response activities and commands that have been executed while performing a remediation process to the sensors.
Where can the administrator view this information in the console?

  • A. Users
  • B. Audit Log
  • C. Inbox
  • D. Notifications

正解:B


質問 # 44
In which tab of the VMware Carbon Black Cloud interface can sensor status details be found?

  • A. Inventory > Sensor groups
  • B. Inventory > Sensors
  • C. Enforce > Policies
  • D. Inventory > Endpoints

正解:D

解説:
Explanation
The sensor status details can be found in the Inventory > Endpoints tab of the VMware Carbon Black Cloud interface. This tab displays all the deployed sensors by default, and allows the administrator to filter them by various criteria, such as status, policy, group, OS, or device name. The status column indicates the state of a sensor and any administrator actions that have been taken on the sensor, such as bypass, quarantine, or deregister. The administrator can also view more details about a sensor by clicking on its name, such as the sensor version, last check-in time, device health score, and policy history. The administrator can also take actions on a sensor from this tab, such as updating, isolating, or uninstalling the sensor. References: Sensor Status and Details - Asset Groups, Carbon Black Cloud Endpoint Standard - Technical Overview


質問 # 45
An administrator has been tasked with preventing the use of unauthorized USB storage devices from being used in the environment.
Which item needs to be enabled in order to enforce this requirement?

  • A. Enable the Block access to all unapproved USB devices within the policies option.
  • B. Choose to disable USB device access on each endpoint from the Inventory page.
  • C. Select the option to block USB devices from the Reputation page.
  • D. Elect to approve only allowed USB devices from the USB Devices page.

正解:D

解説:
Explanation
To prevent the use of unauthorized USB storage devices, the administrator needs to enable the USB Device Control feature in the VMware Carbon Black Cloud Endpoint Standard. This feature allows the administrator to approve or block specific USB devices based on their vendor ID, product ID, serial number, and device type. The administrator can also set a default action for unapproved USB devices, such as block, read-only, or allow. The administrator can manage the USB devices from the USB Devices page under the Settings menu. From this page, the administrator can view the list of USB devices that have been detected by the endpoints, and elect to approve only the allowed USB devices. The administrator can also export or import the list of approved USB devices for backup or replication purposes. References:
VMware Carbon Black Cloud Endpoint Standard Skills Reference Materials, Module 4: USB Device Control, pages 4-1 to 4-9.
VMware Carbon Black Cloud Endpoint Standard User Guide, Chapter 11: USB Device Control, pages
147-152.


質問 # 46
What is a security benefit of VMware Carbon Black Cloud Endpoint Standard?

  • A. Data leakage protection (DLP) is enforced on endpoints or subsets of endpoints.
  • B. Customized threat feeds can be combined with other outside threat intelligence sources.
  • C. Firewall rule configuration are provided in the environment.
  • D. Events and alerts are tagged with Carbon Black TTPs to provide context around attacks.

正解:D


質問 # 47
The use of leading wildcards in a query is not recommended unless absolutely necessary because they carry a significant performance penalty for the search.
What is an example of a leading wildcard?

  • A. filemod:system32/*ntdll.dll
  • B. filemod:system32/ntdll.dll
  • C. filemod:system32/ntdll.dll*
  • D. filemod:*/system32/ntdll.dll

正解:D

解説:
Explanation
A leading wildcard is a wildcard that is placed at the beginning of a search term, such as * or ?. A leading wildcard matches any characters that precede the specified term. For example, filemod:/system32/ntdll.dll matches any file modification events that end with /system32/ntdll.dll, regardless of the drive letter or the directory name. A leading wildcard is not recommended unless absolutely necessary because it carries a significant performance penalty for the search. This is because the search engine has to scan the entire index for possible matches, rather than using the index to quickly narrow down the results1.
The other options are not examples of leading wildcards. A. filemod:system32/ntdll.dll is an exact match query that matches only file modification events that are exactly system32/ntdll.dll. B. filemod:system32/ ntdll.dll is a trailing wildcard query that matches any file modification events that start with system32/ and end with ntdll.dll, regardless of the characters in between. D. filemod:system32/ntdll.dll is a trailing wildcard query that matches any file modification events that start with system32/ntdll.dll, regardless of the characters that follow. References:
Search Syntax - VMware Docs, Wildcards section.


質問 # 48
An administrator has dismissed a group of alerts and ticked the box for "Dismiss future instances of this alert on all devices in all policies". There is also a Notification configured to email the administrator whenever an alert of the same Severity occurs. The following day, a new alert is added to the same group of alerts.
How will this alert be handled?

  • A. The alert will show when the Dismissed filter is selected on Alerts page, but a Notification email will not be sent.
  • B. The alert will show when Not Dismissed filter is selected on Alerts page, but a Notification email will not be sent.
  • C. The alert will show when the Dismissed filter is selected on the Alerts page, and a Notification email will be sent.
  • D. The alert will show when the Not Dismissed filter is selected on Alerts page, and a Notification email will be sent.

正解:A


質問 # 49
A user downloaded and executed malware on a system. The malware is actively exfiltrating data.
Which immediate action is recommended to prevent further exfiltration?

  • A. Request upload of the file for analysis.
  • B. Run a background scan.
  • C. Place the device in quarantine.
  • D. Check Security Advisories and Threat Research contents.

正解:C

解説:
Explanation
Placing the device in quarantine is the recommended immediate action to prevent further exfiltration of data by the malware. Quarantine is a feature of VMware Carbon Black Cloud Endpoint Standard that allows you to isolate a device from the network, preventing any communication with other devices or external servers. This can help contain an active threat and prevent further damage. You can quarantine a device from the Devices page or from the Device Summary page. You can also unquarantine a device when the threat is resolved.
References:
VMware Carbon Black Cloud Endpoint Standard - On Demand, Module 5: Responding to Threats, Lesson 2: Quarantine a Device, slide 5.
VMware Carbon Black Cloud Endpoint Standard, page 11, Quarantine a Device.


質問 # 50
An administrator has configured a permission rule with the following options selected:
Application at path: C:\Program Files\**
Operation Attempt: Performs any operation
Action: Bypass
What is the impact, if any, of using the wildcards in the path?

  • A. Executable files in the "Program Files" folder will be blocked.
  • B. No Files will be ignored from the "Program Files" director/, but Malware in the "Program Files" directory will continue to be blocked.
  • C. Only executable files in the "Program Files" folder will be ignored, includingmalware files.
  • D. All executable files in the "Program Files" folder and subfolders will be ignored, includingmalware files.

正解:D

解説:
Explanation
The impact of using the wildcards in the path is that all executable files in the "Program Files" folder and subfolders will be ignored, including malware files. This is because the double asterisk ** matches any files or directories in that path, and the Bypass action means that the sensor will notmonitor or block any operations performed by those files. This is a very permissive and risky rule, as it could allow malicious files to run without interference from the sensor. A more restrictive and secure rule would be to specify the exact path of the application that needs to be allowed, and use the Allow and Log action instead of Bypass. This way, the sensor will only ignore the specified application, and still log its operations for visibility and analysis. References: Carbon Black Cloud: How to Use Wildcards in Policy Rules, Set Permission Policy Rules


質問 # 51
A script-based attack has been identified that inflicted damage to the corporate systems. The security administrator found out that the malware was coded into Excel VBA and would like to perform a search to further inspect the incident.
Where in the VMware Carbon Black Cloud Endpoint Standard console can this action be completed?

  • A. Endpoints
  • B. Settings
  • C. Investigate
  • D. Alerts

正解:C


質問 # 52
An administrator is tasked to create a reputation override for a company-critical application based on the highest available priority in the reputation list. The company-critical application is already known by VMware Carbon Black.
Which method of reputation override must the administrator use?

  • A. Hash
  • B. IT Tool
  • C. Signing Certificate
  • D. Local Approved

正解:C


質問 # 53
A recent application has been blocked using hash ban, which is an indicator that some users attempted an unexpected activity. Even though the activity was blocked, the security administrator wants to further investigate the attempt in VMware Carbon Black Cloud Endpoint Standard.
Which page should the administrator navigate to for a graphical view of the event?

  • A. Alert Triage
  • B. Watchlists
  • C. Audit Log
  • D. Process Analysis

正解:D


質問 # 54
An administrator has been tasked with preventing the use of unauthorized USB storage devices from being used in the environment.
Which item needs to be enabled in order to enforce this requirement?

  • A. Choose to disable USB device access on each endpoint from the Inventory page.
  • B. Select the option to block USB devices from the Reputation page.
  • C. Elect to approve only allowed USB devices from the USB Devices page.
  • D. Enable the Block access to all unapproved USB devices within the policies option.

正解:D


質問 # 55
......


VMware Carbon Black Cloud Endpoint Standard Skills試験(VMware 5V0-93.22)は、エンドポイントセキュリティ管理におけるITプロフェッショナルのスキルと知識を検証するよう設計されています。サイバー脅威が進化し、より洗練されるにつれて、組織がエンドポイントを効果的に管理し、保護するスキルを持つ熟練した専門家を持つことがますます重要になっています。VMware Carbon Black Cloud Endpoint Standard Skills試験は、VMware Carbon Black Cloudソリューションを使用してエンドポイントを管理し、保護する能力を評価することを目的としています。

 

認定トレーニングは5V0-93.22試験問題集テストエンジン:https://www.passtest.jp/VMware/5V0-93.22-shiken.html

5V0-93.22トレーニングと認定最新のVMware Security Solutions問題をゲットせよ:https://drive.google.com/open?id=1JnPfJ0zBDmANEuBy2qYyArjcy7hgT76b