VMware Carbon Black Cloud Endpoint Standard Skills Free Sample Questions

20 free sample questions257 in the full practice test Other version: 5V0-91.20(248)

Try simulator

5V0-93-22 Sample Questions

  1. Question 1

    A security architect is designing a Carbon Black Cloud policy for a fleet of developer workstations. The developers frequently use unsigned, internally-developed command-line tools. The security team requires that all known malware is blocked, but wants to avoid disrupting development workflows. Which Reputation Priority configuration within the policy best balances these requirements?

    Answer and explanation

    Correct answer: B

    Setting Carbon Black Intelligence (Cloud) reputation to the highest priority ensures that known malware and suspicious files identified by VMware's threat intelligence are blocked first. This provides the core security requirement. Since the internal tools are unsigned, prioritizing Company Approved (Signed) would not help and could be complex to manage. Prioritizing IT Tools or ignoring reputation would weaken the security posture unacceptably.

  2. Question 2

    During an incident investigation, a SOC analyst needs to find all network connections made by the process svchost.exe that did NOT go to a specific internal domain corp.local. Which search query would accomplish this?

    Answer and explanation

    Correct answer: C

    The correct syntax to exclude a value in a Carbon Black Cloud search query is to prefix the field with a hyphen (-). This query correctly filters for events where the process name is svchost.exe and excludes any events where the network connection domain is corp.local. The NOT operator is not used in this manner for field value exclusion.

  3. Question 3

    A system administrator notices that the Carbon Black sensor is causing high CPU utilization on a critical database server. The high CPU usage correlates with frequent write operations to a specific log directory, D:\AppLogs\. The security team has confirmed these write operations are benign and part of the application's normal function. What is the most precise and efficient way to resolve the performance issue without weakening the server's overall security posture?

    Answer and explanation

    Correct answer: B

    A Sensor Operation Exclusion is designed specifically for performance tuning. It instructs the sensor to ignore file, script, and network operations for a specified path or certificate, which directly addresses the high CPU caused by monitoring frequent, benign write operations. Event Reporting Exclusions only stop events from being sent to the cloud, but the sensor still processes them locally. Adding a permission rule doesn't stop the sensor from monitoring the activity, and placing the sensor in bypass mode is a significant security risk.

  4. Question 4

    An incident responder is using Live Response to investigate a compromised Windows endpoint. They need to retrieve a suspicious file named update.dll from the user's temporary directory for offline analysis. Which sequence of commands should be used?

    Answer and explanation

    Correct answer: A

    The correct sequence is to first change the current directory to the location of the file using cd %temp%, and then use the get command to retrieve the file from the endpoint to the Carbon Black Cloud. The pull command does not exist. Executing get with the full path is also a valid method, but the cd command is commonly used to simplify paths. The memget command is for retrieving process memory, not files.

  5. Question 5

    A security policy is configured with a rule to block the execution of powershell.exe. A separate, lower-precedence rule in the same policy adds a permission for a digitally signed PowerShell script, C:\scripts\admin_tool.ps1. When a user attempts to run this signed script, what is the expected outcome?

    Answer and explanation

    Correct answer: B

    In Carbon Black Cloud's prevention logic, if the interpreter (powershell.exe in this case) is explicitly blocked, any scripts that rely on that interpreter will also be blocked, regardless of permissions on the script file itself. The block on the parent process (powershell.exe) is enforced before the script is even processed.

  6. Question 6

    True or False: The Carbon Black Cloud sensor on a macOS endpoint can function and apply prevention policies even when it cannot communicate with the Carbon Black Cloud backend.

    Answer and explanation

    Correct answer: A

    This is true. The Carbon Black Cloud sensor is designed to operate autonomously. It downloads the latest policy and threat intelligence, allowing it to enforce prevention rules and block threats even when the endpoint is offline or unable to reach the cloud. When connectivity is restored, it uploads the queued event data.

  7. Question 7

    Multiple answers

    A security analyst receives a high-severity alert for lsass.exe being accessed by a non-system process on a domain controller. This is a strong indicator of a credential dumping attack. According to best practices, what are the most critical initial response actions to take directly from the Carbon Black Cloud console? (Select TWO)

    Answer and explanation

    Correct answers: A, B

  8. Question 8

    A financial services company is deploying Carbon Black Cloud Endpoint Standard. Due to regulatory compliance, they must prevent any process from writing files with the extension .dat to any external USB storage device. Which type of rule should an administrator create to enforce this specific requirement?

    Answer and explanation

    Correct answer: D

    This requirement calls for controlling a specific operation (write) based on file path and device type. An 'operation' blocking rule is the correct tool. It can be configured to target the 'write' operation, specify the file pattern (*\*.dat), and apply this logic only when the target media is 'removable'. This provides precise control without blocking legitimate use of USB devices or processes.

  9. Question 9

    While reviewing the sensor status on the Endpoints page, an administrator sees a device with the status 'Deregistered'. What does this status indicate about the sensor and the device?

    Answer and explanation

    Correct answer: A

    The 'Deregistered' status means that the sensor has been properly uninstalled from the endpoint using the command-line with the company deregistration code. The console record is maintained for a short period before being automatically purged. This is different from a sensor that is merely offline or has been manually deleted from the console.

  10. Question 10

    A company has a custom-built legacy application that is unsigned and frequently flagged as 'SUSPICIOUS' by Carbon Black Cloud, causing business interruptions. The application is known to be safe. The security team wants to ensure this specific application can always run without being blocked, across all policies, without affecting the reputation evaluation of any other applications. What is the most appropriate global override to apply?

    Answer and explanation

    Correct answer: A

    Adding the application's SHA-256 hash to the 'Approved List' (a reputation override) is the most specific and secure method. This action globally designates that specific binary as trusted, ensuring it will run regardless of policy settings or its cloud reputation. Banning it is incorrect. Adding it to the 'IT Tool' list is less definitive and can be overridden by policy. A permission rule is policy-specific, not global.

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 505 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon