An administrator needs to add an application to the Approved List in the VMware Carbon Black Cloud console.
Which two different methods may be used for this purpose? (Choose two.)
An administrator has determined that the following rule was the cause for an unexpected block:
[Suspected malware] [Invokes a command interpreter] [Terminate process]
All reputations for the process which was blocked show SUSPECT_MALWARE.
Which reputation was used by the sensor for the decision to terminate the process?
Which scenario would qualify for the "Local White" Reputation?
An administrator is tasked to create a reputation override for a company-critical application based on the highest available priority in the reputation list. The company-critical application is already known by VMware Carbon Black.
Which method of reputation override must the administrator use?
An administrator wants to prevent ransomware that has not been seen before, without blocking other processes.
Which rule should be used?
An administrator is reviewing how event data is categorized and identified in VMware Carbon Black Cloud.
Which method is used?
A security administrator is tasked to enable Live Response on all endpoints in a specific policy.
What is the correct path to configure the required sensor policy setting?
Which statement accurately characterizes Alerts that are categorized as a "Threat" versus those categorized as "Observed"?
PDF + Testing Engine
|
---|
$66 |
Testing Engine
|
---|
$50 |
PDF (Q&A)
|
---|
$42 |
VMware Free Exams |
---|
![]() |