VMware 5V0-93.22 - VMware Carbon Black Cloud Endpoint Standard Skills
An administrator wants to find information about real-world prevention rules that can be used in VMware Carbon Black Cloud Endpoint Standard.
How can the administrator obtain this information?
In which tab of the VMware Carbon Black Cloud interface can sensor status details be found?
Which scenario would qualify for the "Local White" Reputation?
An organization is implementing policy rules. The administrator mentions that one operation attempt must use a Terminate Process action.
Which operation attempt has this requirement?
An administrator needs to create a search, but it must exclude "system.exe".
How should this task be completed?
An administrator is reviewing how event data is categorized and identified in VMware Carbon Black Cloud.
Which method is used?
An administrator wants to prevent malicious code that has not been seen before from retrieving credentials from the Local Security Authority Subsystem Service, without causing otherwise good applications from being blocked.
Which rule should be used?
An administrator notices that a sensor's local AV signatures are out-of-date.
What effect does this have on newly discovered files?
A security administrator needs to review the Live Response activities and commands that have been executed while performing a remediation process to the sensors.
Where can the administrator view this information in the console?
An administrator wants to be notified when particular Tactics, Techniques, or Procedures (TTPs) are observed on a managed endpoint.
Which notification option must the administrator configure to receive this notification?