Pass4itsure > VMware > VMware Certifications > 5V0-91.20 > 5V0-91.20 Online Practice Questions and Answers

5V0-91.20 Online Practice Questions and Answers

Questions 4

An administrator has configured a policy to run a standard background scan.

How long does this one-time scan take to complete on endpoints assigned to that policy?

A. 180 days

B. 30 days

C. 3-5 days

D. 1 day

Buy Now
Questions 5

What is the meaning, if any, of the event Report write (removable media)?

A. This event would never occur. App Control does not report activity on removable media.

B. A Policy's device control setting `Block writes to unapproved removable media' is set to Report Only. The event details show the process, file name, and hash modified or deleted on the removable media.

C. A Policy's device control setting `Block writes to unapproved removable media' is set to Report Only. The event details show the process and file name modified or deleted on the unapproved removable media.

D. A Policy's device control setting `Block writes to unapproved removable media' is set to Enabled. The event details show the process, file name, and hash modified or deleted on the removable media.

Buy Now
Questions 6

An organization leverages a commonly used software distribution tool to manage deployment of enterprise software and updates. Custom rules are a suitable option to ensure the approval of files delivered by this tool.

Which other trust mechanism could the organization configure for large-scale approval of these files?

A. Windows Update

B. Trusted Distributor

C. Local Approval Mode

D. Rapid Config

Buy Now
Questions 7

An administrator receives an alert with the TTP DATA_TO_ENCRYPTION.

What is known about the alert based on this TTP even if other parts of the alert are unknown?

A. A process attempted to delete encrypted data on the disk.

B. A process attempted to write a file to the disk.

C. A process attempted to modify a monitored file written by the sensor.

D. A process attempted to transfer encrypted data on the disk over the network.

Buy Now
Questions 8

Which two statements are true about Carbon Black alerts? (Choose two.)

A. They can be grouped together.

B. Once received, it can be dismissed in bulk.

C. Once dismissed, the action cannot be undone.

D. Carbon Black does not generate alerts.

E. They are stored for 15 days.

Buy Now
Questions 9

An active compromise is detected on an endpoint. Due to current policies, the compromise was detected but not terminated.

What would be an appropriate action to end the current communication between the device and the attacker?

A. Uninstall the sensor

B. Place the system into bypass mode

C. Place the system into Quarantine D. Remotely scan the endpoint

Buy Now
Questions 10

Refer to the exhibit, noting the circled red dot:

What is the meaning of the red dot under Hits in the Process Search page?

A. Whether the execution of the process resulted in a syslog hit

B. Whether the execution of the process resulted in a sensor hit

C. Whether the execution of the process resulted in matching hits for different users

D. Whether the execution of the process resulted in a feed hit

Buy Now
Questions 11

An administrator needs to manage a group of sensors from within the console.

Which three actions are available for sensors within the Sensor Group? (Choose three.)

A. Move to group

B. Disable

C. Restart

D. Ban

E. Uninstall

F. Share Settings

Buy Now
Questions 12

How can an analyst disregard alerts on multiple devices with the least amount of administrative effort?

A. Select the "Dismiss on all devices" option.

B. Make a note in the Notes/Tags option.

C. Search by hash and dismiss.

D. Turn off the Group Alerts option.

Buy Now
Questions 13

Why would a sensor have a status of "Inactive"?

A. The sensor has not checked in within the last 30 days.

B. The sensor has been uninstalled from the endpoint for more than 30 days.

C. The device has been put in bypass for the last 30 days.

D. The sensor has been in disabled mode for more than 30 days.

Buy Now
Exam Code: 5V0-91.20
Exam Name: VMware Carbon Black Portfolio Skills
Last Update: Mar 28, 2025
Questions: 116
10%OFF Coupon Code: SAVE10

PDF (Q&A)

$49.99

VCE

$55.99

PDF + VCE

$65.99