1V0-91.22 Sample Questions & Answers
Three areas tie for the heaviest weight: Carbon Black Cloud, NSX's security side and Workspace ONE's security features, installing and configuring each, and VMware's overall security architecture, next to security planning, performance tuning, and troubleshooting.
Launch the full 1V0-91.22 simulator →Showing 10 of 20 free samples.
- Question 1Advanced
Performance-tuning, Optimization, and Upgrades · Carbon Black Policy Optimization
An administrator is reviewing the performance of the Carbon Black Cloud sensor on a fleet of developer workstations. They notice that builds of a custom, in-house application are taking significantly longer than expected. They suspect the sensor's real-time scanning is causing the performance degradation. What is the most precise and secure method to exclude the application's build directory from scanning without creating a broad security gap?
Show answer & explanation
Correct answer: C
Creating a targeted permission rule is the most secure and precise method. This allows the administrator to specify the exact application (e.g., compiler.exe) and grant it permissions to perform actions that might otherwise be flagged, such as writing new executables. This is far more secure than disabling scanning entirely or creating a broad folder exclusion, which could be exploited by malware. Whitelisting the final executable doesn't help with the performance of the build process itself.
- Question 2Intermediate
Planning and Designing · NSX-T DFW Rule Design
A security team is designing an NSX-T Distributed Firewall policy for a three-tier web application. The policy must enforce the following communication flow:
graph TD Internet --> F5_LB[Load Balancer] F5_LB --> Web_Tier Web_Tier -->|TCP/8443| App_Tier App_Tier -->|TCP/1433| DB_TierWhich type of DFW rule should be created to allow traffic from the Web_Tier to the App_Tier?
Show answer & explanation
Correct answer: D
To allow traffic to the App_Tier, an Ingress rule must be applied to the App_Tier's security group. The rule's source should be defined as the Web_Tier security group, and the service should be set to TCP port 8443. This correctly implements the required communication path while adhering to the principle of least privilege.
- Question 3Intermediate
Products and Solutions · Workspace ONE OS Updates Management
A company uses Workspace ONE UEM to manage its corporate-owned iOS devices. A new security mandate requires that devices must be updated to the latest major iOS version within 30 days of its public release. How can an administrator enforce this policy and track compliance?
Show answer & explanation
Correct answer: B
Workspace ONE UEM provides specific tools for this. An OS Update profile can be configured to schedule and force the download and installation of a specific iOS version. A corresponding compliance policy can then be created to check if the device's OS version is greater than or equal to the required version. If a device is not compliant, the policy can trigger actions like notifications or access restrictions.
- Question 4Beginner
Installing, Configuring, and Setup · Carbon Black Cloud Policy Modes
A new administrator is trying to understand the different policy modes in VMware Carbon Black Cloud. They need to configure a policy for a group of critical servers that should block all known malware but only report on, not block, potentially unwanted programs (PUPs). Which policy mode should be used?
Show answer & explanation
Correct answer: B
The 'Standard' policy mode is designed for this exact scenario. It automatically blocks processes that are identified as known malware but will only generate alerts (report) for processes that are classified as PUPs or suspicious, allowing an administrator to review them before taking action. 'Advanced' would also block PUPs, and 'Disabled' or 'Non-Malware' would not provide the necessary malware protection.
- Question 5Advanced
Planning and Designing · Integrated VMware Security Solutions
Case Study
A healthcare organization, HealthFirst, is modernizing its security posture to protect sensitive patient data (ePHI) and comply with HIPAA regulations. Their environment consists of a vSphere-based private cloud hosting their Electronic Health Record (EHR) system and a mix of corporate-owned and BYOD mobile devices used by clinicians to access patient information. The CISO has mandated a move to a Zero Trust architecture.
The EHR system is a classic three-tier application (Web, Application, Database). Currently, all servers for this application reside on the same VLAN, allowing unrestricted communication between them. Clinicians use a variety of iOS and Android devices to access a web portal for the EHR system. The security team has identified lateral movement within the data center and unmanaged, non-compliant mobile devices as their two biggest risks.
Requirements:
- Prevent lateral threat movement between the EHR application tiers.
- Ensure that only compliant and trusted mobile devices can access the EHR web portal.
- Provide detailed visibility into any attempted attacks on the EHR servers.
- The solution must be centrally managed and integrated.
Which combination of VMware products best fulfills all of HealthFirst's requirements?
Show answer & explanation
Correct answer: B
This combination directly addresses all requirements. NSX-T's Distributed Firewall provides micro-segmentation to stop lateral movement (Req 1). Workspace ONE UEM and Access enforce device compliance checks and apply conditional access policies to control access to the EHR portal (Req 2). Carbon Black Cloud deployed on the EHR servers provides advanced threat detection, EDR capabilities for visibility into attacks (Req 3), and integrates with the other solutions for a centrally managed posture (Req 4).
- Question 6Intermediate
Products and Solutions · Carbon Black Cloud Live Query
A security operator needs to quickly determine if any endpoints in their environment have a specific vulnerable version of a logging library (e.g., log4j). They need to query the file system of all online Windows and Linux endpoints for the presence of a file named
log4j-core-2.14.1.jar. Which VMware Carbon Black Cloud feature allows for this type of ad-hoc, real-time query across the entire fleet?Show answer & explanation
Correct answer: B
Live Query is the feature designed for this purpose. It uses osquery to allow administrators to run SQL-like queries against endpoints in real-time to gather information about their current state, such as installed applications, running processes, and, in this case, the presence of specific files on the file system. This is a powerful tool for incident response and vulnerability assessment.
- Question 7Advanced
Troubleshooting and Administrative Tasks · NSX-T DFW Troubleshooting
An administrator has configured an NSX-T Distributed Firewall policy to block all SMB traffic (TCP/445) between virtual machines. However, a monitoring tool shows that VMs in the 'Development' security group are still able to communicate with each other over SMB. What is the most likely reason for this policy failure?
Show answer & explanation
Correct answer: B
NSX-T DFW rules are processed in a top-down, first-match order within a policy section. If a rule with a higher precedence (lower sequence number) explicitly allows SMB traffic between the 'Development' VMs, that rule will be matched first, and processing will stop. The lower-precedence 'block' rule will never be evaluated for that traffic flow. This is a common cause of policy misconfiguration.
- Question 8Beginner
Products and Solutions · Carbon Black Cloud Live Response
What is the primary function of the 'Live Response' feature in VMware Carbon Black Cloud?
Show answer & explanation
Correct answer: C
Live Response provides security analysts with direct, secure access to an endpoint from the Carbon Black Cloud console. It establishes a remote shell, allowing the analyst to perform deep investigations by browsing the file system, uploading/downloading files (like forensic tools or malware samples), killing processes, and inspecting system state. It is a critical tool for hands-on incident response.
- Question 9Intermediate
Architecture and Technologies · NSX-T Security Groups
True or False: In an NSX-T micro-segmentation deployment, virtual machines must have different IP subnets to be placed in different security groups.
Show answer & explanation
Correct answer: B
This statement is false. A core benefit of NSX-T micro-segmentation is that it decouples security policy from network topology. Security groups can be defined based on various criteria, such as VM names, tags, OS type, or Active Directory groups, irrespective of their IP address or VLAN/subnet. This allows for granular segmentation of workloads that reside on the same Layer 2 network segment.
- Question 10AdvancedSelect 3
Troubleshooting and Administrative Tasks · Workspace ONE Compliance Troubleshooting
A user reports they are unable to access a corporate application that is protected by Workspace ONE Access. The administrator confirms the user's credentials are correct. Access policies require the user's device to be managed and compliant. Upon checking the device in Workspace ONE UEM, the administrator sees its status is 'Non-Compliant'. Which of the following are valid reasons for the device to be marked as non-compliant? (Select THREE)
Show answer & explanation
Correct answers: A, C, D
Compliance policies frequently include rules that check for a minimum OS version to ensure security patches are applied.
Compliance policies can enforce the presence of specific applications, such as the VMware Hub client or a mobile threat defense app.
A common compliance rule is to require that the device's local storage be encrypted.
Ready for the real thing?
The full 1V0-91.22 simulator has every exam-style question, timed mode, and instant scoring.