Questions for the 5V0-91-20 were updated on : Nov 14 ,2024
An administrator needs to check configurations using Audit across several policies and locations
within the organization.
How can the administrator run the query to only these specific devices?
D
A process wrote an executable file as detailed in the following event:
Which rule type should be used to ensure that files of the same name and path, written by that
process in the future, will not be blocked when they execute?
B
Which enforcement level does not block unapproved files but will block files that have been
specifically banned?
A. Medium Enforcement
B. Disabled
C. Visibility
D. Low Enforcement
B
The protection level applied to computers running the App Control
Agent. A range of levels from High (Block Unapproved) to None
(Disabled) enable you to specify the level of file blocking required.
An administrator has updated a Threat Intelligence Report by turning it into a watchlist and needs to
disable (Ignore) the old Threat Intelligence Report.
Where in the UI is this action not possible to perform?
B
An analyst navigates to the alerts page in Endpoint Standard and sees the following:
What does the yellow color represent on the left side of the row?
A
An administrator is concerned that someone may be using unauthorized commands from cmd.exe.
These commands are not considered suspicious or malicious, and there is no policy based around
them.
Which page should the administrator use to find these commands?
A
An analyst has investigated multiple alerts on a number of HR workstations and found that java.exe is
attempting to PowerShell. Of the Windows workstations in question, the analyst has also found that
Java is installed in multiple locations. The analyst needs to block java.exe from this type of operation.
Which rule meets this need?
C
Review the following query:
path:c:\program\ files\ \(x86\)\microsoft
How would this query input term be interpreted?
D
Which statement filters data to only return rows where the publisher of the software includes
VMware anywhere in the name?
D
An administrator ran the following query.
SELECT name, VERSION, install_location, install_source, publisher, install_date, uninstall_string
FROM programs WHERE publisher = "Microsoft Corporation";
The administrator notices a lot of installed programs are not returned.
How can the administrator alter the query to see all results?
A
Which actions are available for Permissions?
C
Refer to the exhibit, noting the circled red dot:
What is the meaning of the red dot under Hits in the Process Search page?
C
An Endpoint Standard administrator is working with an IT team to explicitly permit specific
applications from the environment using both the IT Tools and Certs Approved List features.
Once applied, which reputation would these applications be classified under for processing?
A
At which three frequencies may a Carbon Black Audit and Remediation administrator schedule the
run of Live Queries? (Choose three.)
ABD
Which strategy should be used to purge inactive bans from the web console?
C