Free 5V0-91.20 Exam Braindumps (page: 3)

Page 2 of 30

An analyst navigates to the alerts page in Endpoint Standard and sees the following:
What does the yellow color represent on the left side of the row?

  1. It is an alert from a watchlist rather than the analytics engine.
  2. It is a threat alert and warrants immediate investigation.
  3. It is an observed alert and may indicate suspicious behavior.
  4. It is a dismissed alert within the user interface.

Answer(s): A



An administrator is concerned that someone may be using unauthorized commands from cmd.exe. These commands are not considered suspicious or malicious, and there is no policy based around them.
Which page should the administrator use to find these commands?

  1. Sensor Management
  2. Investigate
  3. Policies
  4. Alerts

Answer(s): A



An analyst has investigated multiple alerts on a number of HR workstations and found that java.exe is attempting to PowerShell. Of the Windows workstations in question, the analyst has also found that Java is installed in multiple locations. The analyst needs to block java.exe from this type of operation.
Which rule meets this need?

  1. **/java.exe --> Invokes an untrusted process --> Terminate process
  2. **/Program Files/*/java.exe--> Invokes an untrusted process --> Deny operation
  3. **\Program Files\*\java.exe --> Invokes a command interpreter --> Terminate process
  4. **\java.exe --> Invokes a command interpreter --> Deny operation

Answer(s): C



Review the following query:
path:c:\program\ files\ \(x86\)\microsoft
How would this query input term be interpreted?

  1. c:\program files x86\microsoft
  2. c:rogram files (x86)icrosoft
  3. c:rogramfilesx86icrosoft
  4. c:\program files (x86)\microsoft

Answer(s): D






Post your Comments and Discuss VMware 5V0-91.20 exam with other Community members:

5V0-91.20 Discussions & Posts