Question 1
A security architect is designing a Carbon Black Cloud policy for a fleet of developer workstations. The developers frequently use unsigned, internally-developed command-line tools. The security team requires that all known malware is blocked, but wants to avoid disrupting development workflows. Which Reputation Priority configuration within the policy best balances these requirements?
Answer and explanation
Correct answer: B
Setting Carbon Black Intelligence (Cloud) reputation to the highest priority ensures that known malware and suspicious files identified by VMware's threat intelligence are blocked first. This provides the core security requirement. Since the internal tools are unsigned, prioritizing Company Approved (Signed) would not help and could be complex to manage. Prioritizing IT Tools or ignoring reputation would weaken the security posture unacceptably.