Certified Technical Associate - Security (VCTA-Security 2024) Free Sample Questions

Create a free account to browse all 20 sample questions. The full practice test includes 195 questions. Use the simulator for timed and flashcard mode.

Try Simulator

1V0-91.22 Sample Questions

  1. Question 1

    Q1

    A security analyst is investigating a threat alert in VMware Carbon Black Cloud. They need to understand the full execution chain of a suspicious binary, including all parent and child processes, network connections, and registry modifications initiated by the threat. Which feature within the Carbon Black Cloud console provides this detailed, chronological visualization?

    Show answer & explanation

    Correct answer: C

    The Process Analysis Tree is the specific feature in Carbon Black Cloud designed to provide a graphical, interactive visualization of an entire event chain. It shows the root cause, parent/child process relationships, network connections, and file modifications, which is exactly what the analyst needs for a deep investigation. Live Query is for ad-hoc querying of endpoints, and the Alerts Triage page provides a high-level list of alerts, not the detailed event chain.

  2. Question 2

    Q2

    A company is implementing a Zero Trust security model for its data center using VMware NSX-T. The primary goal is to prevent lateral movement of threats by isolating every workload. Which NSX-T feature is the most fundamental component for achieving this level of granular, workload-centric isolation?

    Show answer & explanation

    Correct answer: B

    The NSX Distributed Firewall (DFW) is the core component for implementing micro-segmentation. It operates at the vNIC level of each virtual machine, allowing for stateful firewalling between individual workloads on the same logical network segment. This capability is essential for creating a Zero Trust environment by enforcing least-privilege access and preventing lateral movement. The Gateway Firewall protects North-South traffic, while IDS/IPS and N/S Service Insertion are additional security services, not the fundamental isolation mechanism.

  3. Question 3

    Q3Multiple answers

    A Workspace ONE administrator needs to configure a compliance policy that automatically performs an enterprise wipe on any jailbroken or rooted Android device as soon as it is detected. Which two components must be configured in the Workspace ONE UEM console to achieve this? (Select TWO)

    Show answer & explanation

    Correct answers: A, C

    A compliance rule is needed to define the trigger condition. In this case, the rule must be set to detect the 'Compromised Status' of a device, which identifies jailbroken or rooted devices.

    An action must be configured to specify what happens when the compliance rule is violated. For this requirement, the action must be set to 'Enterprise Wipe' to remove corporate data and management from the device.

  4. Question 4

    Q4

    True or False: VMware Carbon Black Cloud's Next-Generation Antivirus (NGAV) capabilities rely solely on signature-based detection to identify and block malware.

    Show answer & explanation

    Correct answer: B

    This statement is false. A key differentiator of NGAV solutions like Carbon Black Cloud is that they go beyond traditional signature-based detection. They heavily utilize behavioral analysis, machine learning models, and threat intelligence to detect both known and unknown (zero-day) threats based on their actions and patterns, not just their file hash.

  5. Question 5

    Q5

    A financial services firm is deploying VMware Carbon Black Cloud. Due to strict data residency regulations, all endpoint telemetry data must be stored and processed within the European Union. During the initial setup of the Carbon Black Cloud organization, which setting determines the geographical location of the data storage?

    Show answer & explanation

    Correct answer: C

    Data residency for Carbon Black Cloud is determined by the specific cloud instance the organization is provisioned on. VMware operates multiple instances in different geographic regions (e.g., prod.eu.confer.net for Europe). This selection is made during the initial organization setup and registration process and dictates where all data for that organization will reside. It cannot be changed after the organization is created.

  6. Question 6

    Q6

    An administrator is reviewing the performance of the Carbon Black Cloud sensor on a fleet of developer workstations. They notice that builds of a custom, in-house application are taking significantly longer than expected. They suspect the sensor's real-time scanning is causing the performance degradation. What is the most precise and secure method to exclude the application's build directory from scanning without creating a broad security gap?

    Show answer & explanation

    Correct answer: C

    Creating a targeted permission rule is the most secure and precise method. This allows the administrator to specify the exact application (e.g., compiler.exe) and grant it permissions to perform actions that might otherwise be flagged, such as writing new executables. This is far more secure than disabling scanning entirely or creating a broad folder exclusion, which could be exploited by malware. Whitelisting the final executable doesn't help with the performance of the build process itself.

  7. Question 7

    Q7

    A security team is designing an NSX-T Distributed Firewall policy for a three-tier web application. The policy must enforce the following communication flow:

    graph TD Internet --> F5_LB[Load Balancer] F5_LB --> Web_Tier Web_Tier -->|TCP/8443| App_Tier App_Tier -->|TCP/1433| DB_Tier

    Which type of DFW rule should be created to allow traffic from the Web_Tier to the App_Tier?

    Show answer & explanation

    Correct answer: D

    To allow traffic to the App_Tier, an Ingress rule must be applied to the App_Tier's security group. The rule's source should be defined as the Web_Tier security group, and the service should be set to TCP port 8443. This correctly implements the required communication path while adhering to the principle of least privilege.

  8. Question 8

    Q8

    A company uses Workspace ONE UEM to manage its corporate-owned iOS devices. A new security mandate requires that devices must be updated to the latest major iOS version within 30 days of its public release. How can an administrator enforce this policy and track compliance?

    Show answer & explanation

    Correct answer: B

    Workspace ONE UEM provides specific tools for this. An OS Update profile can be configured to schedule and force the download and installation of a specific iOS version. A corresponding compliance policy can then be created to check if the device's OS version is greater than or equal to the required version. If a device is not compliant, the policy can trigger actions like notifications or access restrictions.

  9. Question 9

    Q9

    A new administrator is trying to understand the different policy modes in VMware Carbon Black Cloud. They need to configure a policy for a group of critical servers that should block all known malware but only report on, not block, potentially unwanted programs (PUPs). Which policy mode should be used?

    Show answer & explanation

    Correct answer: B

    The 'Standard' policy mode is designed for this exact scenario. It automatically blocks processes that are identified as known malware but will only generate alerts (report) for processes that are classified as PUPs or suspicious, allowing an administrator to review them before taking action. 'Advanced' would also block PUPs, and 'Disabled' or 'Non-Malware' would not provide the necessary malware protection.

  10. Question 10

    Q10

    Case Study

    A healthcare organization, HealthFirst, is modernizing its security posture to protect sensitive patient data (ePHI) and comply with HIPAA regulations. Their environment consists of a vSphere-based private cloud hosting their Electronic Health Record (EHR) system and a mix of corporate-owned and BYOD mobile devices used by clinicians to access patient information. The CISO has mandated a move to a Zero Trust architecture.

    The EHR system is a classic three-tier application (Web, Application, Database). Currently, all servers for this application reside on the same VLAN, allowing unrestricted communication between them. Clinicians use a variety of iOS and Android devices to access a web portal for the EHR system. The security team has identified lateral movement within the data center and unmanaged, non-compliant mobile devices as their two biggest risks.

    Requirements:

    1. Prevent lateral threat movement between the EHR application tiers.
    2. Ensure that only compliant and trusted mobile devices can access the EHR web portal.
    3. Provide detailed visibility into any attempted attacks on the EHR servers.
    4. The solution must be centrally managed and integrated.

    Which combination of VMware products best fulfills all of HealthFirst's requirements?

    Show answer & explanation

    Correct answer: B

    This combination directly addresses all requirements. NSX-T's Distributed Firewall provides micro-segmentation to stop lateral movement (Req 1). Workspace ONE UEM and Access enforce device compliance checks and apply conditional access policies to control access to the EHR portal (Req 2). Carbon Black Cloud deployed on the EHR servers provides advanced threat detection, EDR capabilities for visibility into attacks (Req 3), and integrates with the other solutions for a centrally managed posture (Req 4).

Register free to unlock 10 more sample questions

Create a free account to continue with the rest of the 1V0-91.22 sample set.

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 195 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon