Carbon Black Portfolio Skills Free Sample Questions

20 free sample questions248 in the full practice test Other version: 5V0-93-22(257)

Try simulator

5V0-91.20 Sample Questions

  1. Question 1

    A security architect at a financial institution is designing a policy for VMware Carbon Black App Control to protect critical database servers. The primary goal is to prevent any unauthorized executables from running, while minimizing administrative overhead for patching cycles managed by an automated deployment tool. The deployment tool's agent is known to use dynamically named executables in temporary directories. Which enforcement level is the most appropriate for these servers?

    Answer and explanation

    Correct answer: D

    High Enforcement is the correct security posture for critical servers, as it blocks all unapproved executables by default. However, to accommodate the automated deployment tool that uses dynamic executables, a specific rule must be created. An updatable trust rule or a rule targeting the deployment tool's trusted publisher certificate would allow the patching process to function without compromising the overall security level. Simply using High Enforcement would block the tool, while Medium or Low Enforcement would not provide adequate protection.

  2. Question 2

    A SOC analyst is using Carbon Black Cloud Enterprise EDR to investigate a sophisticated alert on a developer's workstation. The process chart shows that powershell.exe spawned csc.exe (C# compiler), which then wrote an unsigned executable to disk and established a network connection to a rare external IP. The analyst needs to create a watchlist to detect this specific sequence of behaviors across the entire enterprise. Which query would be most effective for this watchlist?

    Answer and explanation

    Correct answer: C

    This query effectively chains the observed behaviors together. It looks for csc.exe (process_name) that was spawned by powershell.exe (parent_name), which then loaded modules (childproc_modload_count) indicating it wrote and executed a file, and also made a network connection (netconn_count). This combination is highly specific to the suspicious TTP (Tactics, Techniques, and Procedures) and minimizes false positives from legitimate developer activity.

  3. Question 3

    An administrator for a large retail company is using Carbon Black Cloud Audit and Remediation to verify PCI-DSS compliance. They need to generate a report of all local user accounts that have password last set dates older than 90 days on all Windows-based point-of-sale terminals. Which Live Query is correctly structured to retrieve this information efficiently?

    Answer and explanation

    Correct answer: C

    This is the most accurate and efficient query. It correctly selects from the users table (u), filters for local accounts, ensures password_last_set is not zero (which can indicate password never expires), and compares the Unix epoch timestamp of the last set password against the current time minus 90 days in seconds (90 * 24 * 60 * 60 = 7776000). Using epoch time for comparison is the standard and most reliable method in OSQuery/SQLite.

  4. Question 4

    Multiple answers

    A security team is migrating from a legacy AV solution to Carbon Black Cloud Endpoint Standard. They have a policy requirement to block the execution of all applications categorized as 'Riskware' but must allow a specific, internally developed tool that is sometimes flagged as such. The tool is signed with the company's code-signing certificate. Which two actions should be taken within the policy configuration to meet this requirement? (Select TWO)

    Answer and explanation

    Correct answers: B, D

    This action directly fulfills the requirement to block all applications categorized as 'Riskware'. This is the primary blocking mechanism.

    This action creates the necessary exception. Since permission rules are evaluated before deny rules, this ensures the internally developed, signed tool will be allowed to run, even if it has a 'Riskware' reputation. This is more scalable than whitelisting by hash, as it covers new versions of the tool automatically.

  5. Question 5

    During an incident response scenario using on-premises VMware Carbon Black EDR, an analyst needs to find all endpoints where a malicious binary, evil.exe, has been seen. The search must be as fast as possible to scope the incident quickly. The analyst only has the binary's SHA-256 hash. Which search method should the analyst use?

    Answer and explanation

    Correct answer: B

    A binary search in Carbon Black EDR is specifically designed for this purpose. It leverages a pre-computed index of all hashes seen in the environment, making it extremely fast for finding where a specific binary exists or has executed. A process search would be slower as it has to search through all process event data.

  6. Question 6

    True or False: In VMware Carbon Black App Control, a rule set to 'Allow & Log' for an unapproved application will permit the application to execute but will not generate an event visible on the console.

    Answer and explanation

    Correct answer: B

    The statement is false. The 'Allow & Log' action explicitly permits the execution AND generates a corresponding event that is recorded and visible in the App Control console. This is used to permit specific actions while maintaining an audit trail.

  7. Question 7

    An organization is using Carbon Black Cloud Endpoint Standard. A security administrator has configured a policy that places devices into quarantine upon detecting a high-severity threat. What is the effect of this quarantine action on the endpoint?

    graph TD subgraph Endpoint [Quarantined Endpoint] A[Sensor] --> B{CBC Cloud} C(Internal Network) -.-> D{No Connection} E(Internet) -.-> D end B -- Manages --> A A -. Blocks .-> C A -. Blocks .-> E
    Answer and explanation

    Correct answer: C

    When a device is quarantined by Carbon Black Cloud, the sensor blocks all inbound and outbound network connections. However, it explicitly maintains its own connection to the Carbon Black Cloud. This allows administrators to continue managing the sensor, collect data via Live Query, or perform remediation actions via Live Response, while preventing the compromised endpoint from communicating with other systems or attackers.

  8. Question 8

    Multiple answers

    A SOC manager is reviewing the alert triage process for their team, who use Carbon Black Cloud Enterprise EDR. The manager wants to ensure analysts can quickly pivot from an alert to proactively hunt for related activity on other endpoints. Which three features, directly accessible from the alert triage page, facilitate this workflow? (Choose THREE)

    Answer and explanation

    Correct answers: A, B, C

    This option allows an analyst to quickly check the reputation of a hash against a third-party intelligence source, which can inform subsequent hunting queries.

    This allows the analyst to immediately run OSQuery against all endpoints to hunt for indicators of compromise (IOCs) or other artifacts related to the alert.

    The 'Go Hunt' feature pre-populates the Investigate page with key telemetry from the alert (like process name, hash, command line), allowing the analyst to instantly search for that activity across the entire fleet.

  9. Question 9

    A consultant is deploying on-premises Carbon Black EDR for a client with a large, geographically distributed network connected by high-latency WAN links. To optimize performance and reduce data transfer over the WAN, sensor data from remote sites should be processed locally before being forwarded to the central EDR cluster. Which EDR component should be deployed at the remote sites to achieve this?

    Answer and explanation

    Correct answer: C

    In an on-premises Carbon Black EDR clustered environment, Minion nodes are responsible for receiving raw sensor event data, processing it, and storing it. By deploying Minion nodes at remote sites, sensors at those sites can send their data to the local Minion, which processes it before forwarding the indexed results to the central Master node. This significantly reduces the amount of raw data traversing the WAN link.

  10. Question 10

    An administrator needs to use Live Response to remove a persistence mechanism created by malware on a Windows endpoint. The malware created a scheduled task named MicrosoftUpdater. Which Live Response command should be used to delete this task?

    Answer and explanation

    Correct answer: B

    Live Response does not have a native delete task command. To interact with system services like the Task Scheduler, you must use the execfg (execute foreground) command to run native OS binaries. schtasks.exe is the correct Windows command-line utility for managing scheduled tasks, and the /delete /tn ... /f arguments will correctly and forcefully remove the specified task.

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 505 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon