Which command is used to immediately terminate a current Live Response session?
A. delete
B. kill
C. execfg
D. detach -q
正解:D
解説: (Pass4Test メンバーにのみ表示されます)
質問 2:
A security administrator is tasked to investigate an alert about a suspicious running process trying to modify a system registry.
Which components can be checked to further inspect the cause of the alert?
A. Command lines. Device ID, and priority score
B. Priority score, file reputation, and timestamp
C. TTPs involved, network connections, and child path
D. Event details, command lines, and TTPs involved
正解:D
解説: (Pass4Test メンバーにのみ表示されます)
質問 3:
Which scenario would qualify for the "Local White" Reputation?
A. The hash was previously analyzed, AND it is not on any known good or bad lists.
B. The hash was not on any known good or known bad lists, AND the file is signed.
C. The file was signed using a trusted certificate.
D. The file was added as an IT took
正解:C
解説: (Pass4Test メンバーにのみ表示されます)
質問 4:
What are the highest and lowest file reputation priorities, respectively, in VMware Carbon Black Cloud?
A. Priority 1: Known Malware, Priority 11: Common White
B. Priority 1: Company Allowed, Priority 11: Not Listed/Adaptive White
C. Priority 1: Ignore, Priority 11: Unknown
D. Priority 1: Unknown, Priority 11: Ignore
正解:C
解説: (Pass4Test メンバーにのみ表示されます)
質問 5:
A script-based attack has been identified that inflicted damage to the corporate systems. The security administrator found out that the malware was coded into Excel VBA and would like to perform a search to further inspect the incident.
Where in the VMware Carbon Black Cloud Endpoint Standard console can this action be completed?
A. Settings
B. Investigate
C. Endpoints
D. Alerts
正解:B
解説: (Pass4Test メンバーにのみ表示されます)
小原** -
試験見事合格することができました。確かに高的中率でした。
次は5V0-93.22も貴社の問題集でがんばって、資格を取りたいと思います。今後ともよろしくお願いします。