最新的VMware Carbon Black Portfolio Skills - 5V0-91.20免費考試真題
Which identifier is shared by all events when an alert is investigated?
正確答案: B
Which reputation is processed with the lowest priority for Endpoint Standard?
正確答案: A
A process has created a number of interesting (executable) files in one sequence.
In addition to the event Subtype 'New Unapproved File to Computer', what other event subtype is likely to be associated with this sequence?
In addition to the event Subtype 'New Unapproved File to Computer', what other event subtype is likely to be associated with this sequence?
正確答案: D
An alert for a device running a proprietary application is tied to a vital business operation.
Which action is appropriate to take?
Which action is appropriate to take?
正確答案: D
What does the Aggressive setting do when configured in Local Scan Settings?
正確答案: A
An administrator has updated a Threat Intelligence Report by turning it into a watchlist and needs to disable (Ignore) the old Threat Intelligence Report.
Where in the UI is this action not possible to perform?
Where in the UI is this action not possible to perform?
正確答案: B
A Carbon Black Cloud analyst needs to identify the Internet Explorer extensions installed on Windows endpoints.
Which Live Query statement will successfully query these items?
Which Live Query statement will successfully query these items?
正確答案: A
Given the following query:
SELECT hostname, cpu_type, cpu_brand, cpu_physical_cores, cpu_logical_cores, cpu_microcode, (1.0 * physical_memory / (1000*1000*1000)) AS physical_mem_gb, hardware_vendor, hardware_model, hardware_version, hardware_serial FROM system_info; Which statement Is correct?
SELECT hostname, cpu_type, cpu_brand, cpu_physical_cores, cpu_logical_cores, cpu_microcode, (1.0 * physical_memory / (1000*1000*1000)) AS physical_mem_gb, hardware_vendor, hardware_model, hardware_version, hardware_serial FROM system_info; Which statement Is correct?
正確答案: A
An analyst is reviewing an alert in Enterprise EDR from a custom watchlist. The analyst disagrees with the alert severity rating.
How can the analyst change the alert severity value, if this is possible?
How can the analyst change the alert severity value, if this is possible?
正確答案: A