Free VMware 5V0-93.22 Study Guides Exam Questions & Answer [Q19-Q42]

Share

Free VMware 5V0-93.22 Study Guides Exam Questions and Answer

5V0-93.22 Exam Dumps, 5V0-93.22 Practice Test Questions


VMware Carbon Black Cloud platform is a leading endpoint security solution that provides advanced threat detection and response capabilities. It uses artificial intelligence and machine learning to identify and block malware, ransomware, and other cyber threats in real-time. The VMware 5V0-93.22 exam focuses on testing an individual's ability to install, configure, and manage VMware Carbon Black Cloud Endpoint Standard.


The VMware 5V0-93.22 exam focuses on policy management. In this section, you will be tested on your ability to create and manage policies for endpoint security. You will also be tested on your knowledge of different policy types, such as process blocking policies and event-based policies. The fourth and final section tests your skills in investigation and remediation. In this section, you will be tested on your ability to investigate endpoint threats and remediate them.

 

NEW QUESTION # 19
An administrator needs to create a search, but it must exclude "system.exe".
How should this task be completed?

  • A. #process_name:system.exe
  • B. <process_name:system.exe>
  • C. *process_name:system.exe
  • D. -process_name:system.exe

Answer: D


NEW QUESTION # 20
A security administrator needs to remediate a security vulnerability that may affect the sensors. The administrator decides to use a tool that can provide interaction and remote access for further investigation.
Which tool is being used by the administrator?

  • A. Live Response
  • B. IRepCLI
  • C. CBLauncher
  • D. PowerCLI

Answer: A

Explanation:
Explanation
The tool that the security administrator is using to remediate a security vulnerability that may affect the sensors is Live Response. Live Response is a feature of VMware Carbon Black Cloud Endpoint Standard that allows the administrator to perform remote investigations, contain ongoing attacks, and remediate threats using a command line interface. Live Response enables the administrator to interact with the sensors and access the endpoints in real time, using various commands and scripts. Live Response can also be used to upload or download files, execute processes, terminate processes, delete files, and more12.
The other tools are not relevant or applicable for this scenario. CBLauncher is a tool that allows the administrator to launch applications on the endpoint without triggering policy rules or alerts. CBLauncher is useful for troubleshooting application compatibility issues or testing new applications, but it does not provide interaction or remote access for further investigation3. PowerCLI is a tool that allows the administrator to automate and manage VMware products and services using PowerShell commands and scripts. PowerCLI is useful for administering VMware virtual machines, hosts, networks, storage, and more, but it does not provide interaction or remote access for further investigation4. IRepCLI is a tool that allows the administrator to generate and upload reputation information for files on the endpoint. IRepCLI is useful for enhancing the threat intelligence and detection capabilities of VMware Carbon Black Cloud, but it does not provide interaction or remote access for further investigation5. References:
Use Live Response - VMware Docs, Overview section.
CBLauncher - VMware Docs, Overview section.
Live Response Commands - VMware Docs, Overview section.
VMware PowerCLI Documentation, Overview section.
IRepCLI - VMware Docs, Overview section.


NEW QUESTION # 21
A security administrator needs to review the Live Response activities and commands that have been executed while performing a remediation process to the sensors.
Where can the administrator view this information in the console?

  • A. Audit Log
  • B. Users
  • C. Notifications
  • D. Inbox

Answer: A

Explanation:
Explanation
The security administrator can view the Live Response activities and commands that have been executed while performing a remediation process to the sensors in the Audit Log page in the VMware Carbon Black Cloud Endpoint Standard console. The Audit Log page allows the administrator to review actions performed by Carbon Black Cloud console users, such as logging in, creating policies, banning hashes, isolating devices, and initiating Live Response sessions. The administrator can use various filters and keywords to narrow down the log scope and find the relevant entries. For example, the administrator can use the following keyword to find all the Live Response activities and commands:
live-response
This keyword will return all the log entries that contain the term live-response, which indicates that the action was related to the Live Response feature. The administrator can also use the following fields to refine the search results:
User: The name of the user who performed the action.
Action: The type of action that was performed, such as login, create, update, delete, enable, disable, and so on.
Object: The object that was affected by the action, such as policy, device, hash, and so on.
Date: The date and time range when the action was performed.
The administrator can also modify the level of granularity of the log entries, expand the log scope, limit the log scope to keywords, modify the audit table configuration, and export audit logs to the local machine1.
The other options are incorrect or irrelevant. Users is a page that allows the administrator to manage the users and roles in the Carbon Black Cloud console, not to view the Live Response activities and commands.
Notifications is a page that allows the administrator to view and manage the notifications from the Carbon Black Cloud console, such as alerts, recommendations, and messages, not to view the Live Response activities and commands. Inbox is a page that allows the administrator to view and manage the messages from the Carbon Black Cloud console, such as product updates, announcements, and feedback requests, not to view the Live Response activities and commands. References:
Audit Logs - VMware Docs, Overview section.


NEW QUESTION # 22
An administrator has configured a permission rule with the following options selected:
Application at path: C:\Program Files\**
Operation Attempt: Performs any operation
Action: Bypass
What is the impact, if any, of using the wildcards in the path?

  • A. Executable files in the "Program Files" folder will be blocked.
  • B. No Files will be ignored from the "Program Files" director/, but Malware in the "Program Files" directory will continue to be blocked.
  • C. Only executable files in the "Program Files" folder will be ignored, includingmalware files.
  • D. All executable files in the "Program Files" folder and subfolders will be ignored, includingmalware files.

Answer: D


NEW QUESTION # 23
An administrator has just placed an endpoint into bypass.
What type of protection, if any, will VMware Carbon Black provide this device?

  • A. VMware Carbon Black will be uninstalled from the endpoint.
  • B. VMware Carbon Black will apply policy rules.
  • C. VMware Carbon Black will not provide any protection to the endpoint.
  • D. VMware Carbon Black will place the machine in quarantine.

Answer: C


NEW QUESTION # 24
An administrator needs to make sure all files are scanned locally upon execution.
Which setting is necessary to complete this task?

  • A. Run Background Scan must be set to Expedited.
  • B. Signature Update frequency must be set to 2 hours.
  • C. On-Access File Scan Mode must be set to Aggressive.
  • D. Allow Signature Updates must be enabled.

Answer: C

Explanation:
Explanation
To make sure all files are scanned locally upon execution, the administrator needs to set the On-Access File Scan Mode to Aggressive. This setting will scan all files on execute, regardless of whether they are new or pre-existing on the device. The assigned reputation and policy rules will apply to the scanned files. The other options are incorrect because they are not necessary to complete this task. Option B is incorrect because the Signature Update frequency is not related to the local scanning of files upon execution. It is related to how often the sensor checks in for signature pack updates. Option C is incorrect because the Allow Signature Updates is not related to the local scanning of files upon execution. It is related to enabling or disabling signature updates for the scanner. Option D is incorrect because the Run Background Scan is not related to the local scanning of files upon execution. It is related to enabling or disabling a one-time background scan on any endpoint sensorassigned to a policy. References: Configure Local Scan Settings, Endpoint Standard: How To Configure Local AV Scan


NEW QUESTION # 25
An administrator needs to find all events on the Investigate page where the process is svchost.exe, and the path is not the standard path of C:\Windows\System32.
Which advanced search will yield these results?

  • A. process_name:svchost.exe EXCLUDE process_name:C:\Windows\System32
  • B. process_name:svchost.exe EXCLUDE process_name:C\:\\Windows\\System32
  • C. process_name:svchost.exe AND NOT process_name:C\:\\Windows\\System32
  • D. process_name:svchost.exe AND NOT process_name:C:\Windows\System32

Answer: C


NEW QUESTION # 26
An administrator wants to prevent ransomware that has not been seen before, without blocking other processes.
Which rule should be used?

  • A. [Not listed application] [Runs or is running] [Terminate process]
  • B. [Not listed application] [Performs ransomware-like behavior] [Terminate process
  • C. [Unknown malware] [Runs or is running] [Terminate process]
  • D. [Adware or PUP] [Scrapes memory of another process] [Deny operation]

Answer: B


NEW QUESTION # 27
A security administrator is tasked to enable Live Response on all endpoints in a specific policy.
What is the correct path to configure the required sensor policy setting?

  • A. Policies > Policy > Sensor > Enforce
  • B. Enforce > Policy > Policies > Sensor
  • C. Enforce > Policies > Policy > Sensor
  • D. Policies > Enforce > Policy > Sensor

Answer: C

Explanation:
Explanation
To enable Live Response on all endpoints in a specific policy, the security administrator needs to follow the correct path to configure the required sensor policy setting. The correct path is Enforce > Policies > Policy > Sensor. This path allows the administrator to select a policy group, then click on the Sensor tab, where they can select or deselect the Enable Live Response checkbox as applicable, and then click Save. This will enable or disable Live Response for all endpoints that are assigned to that policy group. The other options are incorrect because they do not match the correctpath to configure the sensor policy setting for Live Response. References: Use Live Response, Use Live Response for VM Workloads


NEW QUESTION # 28
Which VMware Carbon Black Cloud integration is supported for SIEM?

  • A. SolarWinds
  • B. Splunk App
  • C. LogRhythm
  • D. Datadog

Answer: B


NEW QUESTION # 29
An administrator needs to make sure all files are scanned locally upon execution.
Which setting is necessary to complete this task?

  • A. Run Background Scan must be set to Expedited.
  • B. Signature Update frequency must be set to 2 hours.
  • C. On-Access File Scan Mode must be set to Aggressive.
  • D. Allow Signature Updates must be enabled.

Answer: C


NEW QUESTION # 30
An administrator needs to add an application to the Approved List in the VMware Carbon Black Cloud console.
Which two different methods may be used for this purpose? (Choose two.)

  • A. MD5 Hash
  • B. IT Tool
  • C. Signing Certificate
  • D. Application Name
  • E. Application Path

Answer: A,C


NEW QUESTION # 31
An administrator needs to configure a policy for macOS and Linux Sensors, not enabling settings which are only applicable to Windows.
Which three settings are only applicable to Sensors on the Windows operating system? (Choose three.)

  • A. Submit unknown binaries for analysis
  • B. Require code to uninstall sensor
  • C. Scan execute on network drives
  • D. Allow user to disable protection
  • E. Delay execute for cloud scan
  • F. Expedited background scan

Answer: B,C,E


NEW QUESTION # 32
An organization is implementing policy rules. The administrator mentions that one operation attempt must use a Terminate Process action.
Which operation attempt has this requirement?

  • A. Performs ransom ware-like behavior
  • B. Scrapes memory of another process
    D Invokes a command interpreter
  • C. Runs or is running

Answer: A


NEW QUESTION # 33
In which tab of the VMware Carbon Black Cloud interface can sensor status details be found?

  • A. Inventory > Sensors
  • B. Inventory > Endpoints
  • C. Enforce > Policies
  • D. Inventory > Sensor groups

Answer: B


NEW QUESTION # 34
An administrator notices that a sensor's local AV signatures are out-of-date.
What effect does this have on newly discovered files?

  • A. The reputation is determined by cloud reputation.
  • B. The sensor is unable to block a malicious file.
  • C. The sensor prompts the end user to allow or deny the file.
  • D. The sensor automatically blocks the new file.

Answer: A

Explanation:
Explanation
VMware Carbon Black Cloud Endpoint Standard uses a hybrid approach to determine the reputation of files on the endpoints. It combines local scan, which uses signature-based detection to identify known malware, and cloud scan, which uses cloud-based analytics and machine learning to identify unknown or emerging threats.
When a sensor's local AV signatures are out-of-date, it means that the local scan cannot detect the latest malware variants that have been added to the signature database. However, this does not affect the cloud scan, which can still determine the reputation of newly discovered files based on their behavior, characteristics, and context. Therefore, the effect of having out-of-date local AV signatures is that the reputation is determined by cloud reputation, which is more accurate and up-to-date than signature-based detection. The other options are not correct, because the sensor does not prompt the end user, automatically block, or fail to block a new file based on the local AV signatures alone. References: Carbon Black Cloud Endpoint Standard - Technical Overview, View and Update Signature Versions, Endpoint Standard: How to verify AV Signatures are updating


NEW QUESTION # 35
Which statement accurately characterizes Alerts that are categorized as a "Threat" versus those categorized as
"Observed"?

  • A. "Threat" indicates that no block (Deny or Terminate) has occurred. "Observed" indicates a block.
  • B. "Threat" indicates an ongoing attack. "Observed" indicates the attack is over and is being watched.
  • C. "Threat" indicates a block (Deny or Terminate) has occurred. "Observed" indicates that there is no block.
  • D. "Threat" indicates a more likely malicious event. "Observed" are less likely to be malicious.

Answer: D


NEW QUESTION # 36
Which VMware Carbon Black Cloud integration is supported for SIEM?

  • A. SolarWinds
  • B. Splunk App
  • C. LogRhythm
  • D. Datadog

Answer: B

Explanation:
The VMware Carbon Black Cloud integration that is supported for SIEM is the Splunk App. The Splunk App allows administrators to bring alerts, events, audit logs, or vulnerability data from Carbon Black Cloud into their Splunk dashboard1. The Splunk App also supports Splunk SOAR, which enables automated actions and workflows based on Carbon Black Cloud alerts2.
The other options are not supported for SIEM integration with Carbon Black Cloud. SolarWinds, LogRhythm, and Datadog are not listed among the 140+ ecosystempartnerships and integrations that Carbon Black Cloud offers3. They are also not part of the Next-Gen SOC Alliance, which features Splunk, IBM Security, Google Cloud's Chronicle, Exabeam, and Sumo Logic integrations with Carbon Black Cloud1. References:
VMware Carbon Black Cloud Endpoint Standard Skills Reference Materials, Section 2.6: Integrations VMware Carbon Black Cloud Endpoint Standard User Guide, Chapter 12: Integrations Integrations and APIs - VMware Carbon Black Cloud - Cloud SIEM | Sumo Logic Docs VMware Launches Next-Gen SOC Alliance with Splunk, IBM ... - VMware Blogs


NEW QUESTION # 37
What are the highest and lowest file reputation priorities, respectively, in VMware Carbon Black Cloud?

  • A. Priority 1: Company Allowed, Priority 11: Not Listed/Adaptive White
  • B. Priority 1: Known Malware, Priority 11: Common White
  • C. Priority 1: Unknown, Priority 11: Ignore
  • D. Priority 1: Ignore, Priority 11: Unknown

Answer: D

Explanation:
Explanation
According to the VMware Carbon Black Cloud User Guide, the reputation priority is in a descending order with 1 being the highest priority and 11 the lowest priority. The highest priority reputation is Ignore, which is a self-check reputation that Carbon Black Cloud assigns to product files and grants them with full permissions to run. The lowest priority reputation is Unknown, which indicates that Carbon Black Cloud has not yet determined the reputation of the file. References:
Reputation Assignment - VMware Docs, Reputation Priority table.


NEW QUESTION # 38
Which statement is true regarding Blocking/Isolation rules and Permission rules?

  • A. Blocking & Isolation rules are overridden by Upload Rules.
  • B. Upload Rules are overridden by Blocking & Isolation rules.
  • C. Permission Rules are overridden by Blocking & Isolation rules
  • D. D.Blocking & Isolation rules are overridden by Permission Rules

Answer: D

Explanation:
Explanation
The correct statement regarding Blocking/Isolation rules and Permission rules is D. Blocking & Isolation rules are overridden by Permission Rules. This means that if a file or process matches both a Blocking/Isolation rule and a Permission rule, the action specified by the Permission rule will take precedence over the action specified by the Blocking/Isolation rule. For example, if a file has a reputation of SUSPECT_MALWARE and a Blocking/Isolation rule is set to terminate any SUSPECT_MALWARE file that runs, but a Permission rule is set to allow and log any file that runs from a specific path, the file will be allowed and logged if it runs from that path, regardless of its reputation. Permission rules are useful for tuning the behavior of VMware Carbon Black Cloud Endpoint Standard and preventing false positives or unnecessary blocks1.
The other statements are false or irrelevant. Blocking & Isolation rules are not overridden by Upload Rules.
Upload Rules are rules that specify which files and metadata are uploaded to the Carbon Black Cloud for analysis and reputation. Upload Rules do not affect the prevention or detection capabilities of VMware Carbon Black Cloud Endpoint Standard2. Permission Rules are not overridden by Blocking & Isolation rules. As explained above, Permission Rules have a higher priority than Blocking & Isolation rules and can override their actions. Upload Rules are not overridden by Blocking & Isolation rules. Upload Rules and Blocking & Isolation rules are independent of each other and do not affect each other's functionality. References:
Prevention Policy Settings - VMware Docs, Permissions section, Action subsection.
Upload Rules - VMware Docs, Overview section.


NEW QUESTION # 39
An administrator wants to find information about real-world prevention rules that can be used in VMware Carbon Black Cloud Endpoint Standard.
How can the administrator obtain this information?

  • A. Refer to the VMware Carbon Black Cloud sensor install guide.
  • B. Refer to the TAU-TIN's on the VMware Carbon Black community page.
  • C. Refer to an external report from other security vendors to obtain solutions.
  • D. Refer to VMware Carbon Black Cloud user guide.

Answer: B


NEW QUESTION # 40
An organization is seeing a new malicious process that has not been seen before.
Which tool can be used to block this process?

  • A. Policy rules
  • B. Live Response
  • C. Certificate banned list
  • D. Malware Removal

Answer: B

Explanation:
Explanation
Live Response is a tool that allows administrators to remotely access and remediate endpoints in real time.
With Live Response, administrators can block a new malicious process by killing it, deleting its files, and removing any persistence mechanisms. Live Response can also be used to collect forensic data, run scripts, and perform other actions on the endpoints. References: VMware Carbon Black Cloud Endpoint Standard Skills Reference Materials, Section 5.3: Live Response. [Link]


NEW QUESTION # 41
The administrator has configured a permission rule with the following options selected:
Application at path: C:\Program Files\**
Operation Attempt: Performs any operation
Action: Bypass
What is the impact, if any, of using the wildcards in the application at path field?

  • A. Executable files in the "Program Files" directory will be blocked.
  • B. Executable files in the "Program Files" directory and subdirectories will be ignored.
  • C. Executable files in the "Program Files" directory will be logged.
  • D. Executable files in the "Program Files" directory will be subject to blocking rules.

Answer: B

Explanation:
Explanation
The impact of using the wildcards in the application at path field is that executable files in the "Program Files" directory and subdirectories will be ignored by the VMware Carbon Black Cloud Endpoint Standard sensor.
This is because the permission rule has the following options selected:
Application at path: C:\Program Files**
Operation Attempt: Performs any operation
Action: Bypass
The application at path field specifies the path of the executable file that the rule applies to. The ** wildcard matches a partial path across all subdirectory levels and is recursive. For example, C:\Program Files** matches any files in that directory and all subdirectories1.
The operation attempt field specifies the type of operation that the executable file attempts to perform. The Performs any operation option means that the rule applies to any operation, such as creating a file, modifying a registry key, or executing a command.
The action field specifies the action that the VMware Carbon Black Cloud Endpoint Standard sensor takes when the rule is triggered. The Bypass option means that the sensor ignores the executable file and does not apply any blocking rules or log any events for it2.
Therefore, by using the wildcards in the application at path field, the permission rule effectively excludes any executable files in the "Program Files" directory and subdirectories from the VMware Carbon Black Cloud Endpoint Standard sensor's prevention and detection capabilities. References:
Prevention Policy Settings - VMware Docs, Permissions section, Action subsection.
Set Permission Policy Rules - VMware Docs, Procedure section, step 4.
Carbon Black Cloud: How to Use Wildcards in Policy Rules - Carbon Black Community, Wildcard Description table, ** row.


NEW QUESTION # 42
......

Latest 5V0-93.22 Actual Free Exam Questions Updated 62 Questions: https://protechtraining.actualtestsit.com/VMware/5V0-93.22-exam-prep-dumps.html