5V0-91.20 Sample Questions & Answers
Four areas tie for the heaviest weight: managing App Control users and enforcement, Carbon Black EDR's architecture and sensors, Cloud Endpoint Standard communication, and Enterprise EDR watchlists and alerts, next to OSQuery basics for audit and remediation.
Launch the full 5V0-91.20 simulator →Showing 10 of 20 free samples.
- Question 1Beginner
VMware Products and Solutions · Given an App Control use case, identify the required rule type that should be used
True or False: In VMware Carbon Black App Control, a rule set to 'Allow & Log' for an unapproved application will permit the application to execute but will not generate an event visible on the console.
Show answer & explanation
Correct answer: B
The statement is false. The 'Allow & Log' action explicitly permits the execution AND generates a corresponding event that is recorded and visible in the App Control console. This is used to permit specific actions while maintaining an audit trail.
- Question 2Intermediate
VMware Carbon Black Cloud Endpoint Standard · Given a scenario about an alert, identify how to respond using a Cloud Endpoint response option.
An organization is using Carbon Black Cloud Endpoint Standard. A security administrator has configured a policy that places devices into quarantine upon detecting a high-severity threat. What is the effect of this quarantine action on the endpoint?
graph TD subgraph Endpoint [Quarantined Endpoint] A[Sensor] --> B{CBC Cloud} C(Internal Network) -.-> D{No Connection} E(Internet) -.-> D end B -- Manages --> A A -. Blocks .-> C A -. Blocks .-> EShow answer & explanation
Correct answer: C
When a device is quarantined by Carbon Black Cloud, the sensor blocks all inbound and outbound network connections. However, it explicitly maintains its own connection to the Carbon Black Cloud. This allows administrators to continue managing the sensor, collect data via Live Query, or perform remediation actions via Live Response, while preventing the compromised endpoint from communicating with other systems or attackers.
- Question 3IntermediateSelect 3
VMware Carbon Black Cloud Enterprise EDR · Given a scenario about an alert including the process and binary analysis pages, identify the components of the alert.
A SOC manager is reviewing the alert triage process for their team, who use Carbon Black Cloud Enterprise EDR. The manager wants to ensure analysts can quickly pivot from an alert to proactively hunt for related activity on other endpoints. Which three features, directly accessible from the alert triage page, facilitate this workflow? (Choose THREE)
Show answer & explanation
Correct answers: A, B, C
This option allows an analyst to quickly check the reputation of a hash against a third-party intelligence source, which can inform subsequent hunting queries.
This allows the analyst to immediately run OSQuery against all endpoints to hunt for indicators of compromise (IOCs) or other artifacts related to the alert.
The 'Go Hunt' feature pre-populates the Investigate page with key telemetry from the alert (like process name, hash, command line), allowing the analyst to instantly search for that activity across the entire fleet.
- Question 4Intermediate
VMware Carbon Black EDR · Identify the EDR components and dataflows.
A consultant is deploying on-premises Carbon Black EDR for a client with a large, geographically distributed network connected by high-latency WAN links. To optimize performance and reduce data transfer over the WAN, sensor data from remote sites should be processed locally before being forwarded to the central EDR cluster. Which EDR component should be deployed at the remote sites to achieve this?
Show answer & explanation
Correct answer: C
In an on-premises Carbon Black EDR clustered environment, Minion nodes are responsible for receiving raw sensor event data, processing it, and storing it. By deploying Minion nodes at remote sites, sensors at those sites can send their data to the local Minion, which processes it before forwarding the indexed results to the central Master node. This significantly reduces the amount of raw data traversing the WAN link.
- Question 5Intermediate
VMware Carbon Black Cloud Audit and Remediation · Identify Cloud Audit Live Response capabilities, limitations, and features.
An administrator needs to use Live Response to remove a persistence mechanism created by malware on a Windows endpoint. The malware created a scheduled task named
MicrosoftUpdater. Which Live Response command should be used to delete this task?Show answer & explanation
Correct answer: B
Live Response does not have a native
delete taskcommand. To interact with system services like the Task Scheduler, you must use theexecfg(execute foreground) command to run native OS binaries.schtasks.exeis the correct Windows command-line utility for managing scheduled tasks, and the/delete /tn ... /farguments will correctly and forcefully remove the specified task. - Question 6Advanced
VMware Carbon Black Cloud Audit and Remediation · Given a scenario about an environment, and an example and a goal, identify the query that should be created to accomplish the goal.
Case Study:
A healthcare organization, HealthCorp, uses VMware Carbon Black across its portfolio to protect patient data and ensure HIPAA compliance. They use App Control on critical Electronic Health Record (EHR) servers, Cloud Endpoint Standard on clinical workstations, and Audit & Remediation for compliance checks.
During a routine audit, an analyst needs to prove that no unauthorized USB devices have been connected to the EHR servers in the past 6 months. The App Control policy on these servers is in High Enforcement, and USB device access is controlled via specific rules. The analyst must use Live Query to verify that the controls are working as expected and to list any USB devices that were connected.
The security policy states that only company-issued, encrypted USB drives are permitted. These drives are from a specific vendor (VID 0x0781) and have a specific product ID (PID 0x5581). All other USB devices should be blocked and logged.
Which Live Query query would provide the auditor with a comprehensive list of all USB devices connected to the EHR servers, allowing them to easily identify any non-compliant devices?
Show answer & explanation
Correct answer: C
This query is the most effective for the auditor. It selects the key identifiable information from the
usb_devicestable and, crucially, uses aWHERE NOT (...)clause to filter out the compliant, company-issued devices. The result set will therefore only contain USB devices that do not match the approved vendor and product IDs, immediately highlighting all non-compliant connections for the audit report. This directly answers the auditor's need. - Question 7Beginner
VMware Products and Solutions · Given an App Control use case, identify the required rule type that should be used
When configuring a custom rule in VMware Carbon Black App Control, what is the primary function of the 'Perform any operation' condition?
Show answer & explanation
Correct answer: C
The 'Performs any operation' condition is a wildcard that covers all possible actions an application can take. This includes execution ('Runs or is running'), file modifications, registry modifications, and network connections. It is used to create broad rules, such as bypassing all activity from a trusted updater or blocking all activity from a known malicious tool.
- Question 8Intermediate
VMware Carbon Black Cloud Endpoint Standard · Identify the impact of reputation on rules in Cloud Endpoint.
In Carbon Black Cloud Endpoint Standard, an administrator creates a policy with a blocking rule for any process that injects code into another process. They also create a permission rule for a trusted internal monitoring tool that is known to use code injection for legitimate performance analysis. If both rules are applied to an endpoint, what will happen when the monitoring tool runs?
Show answer & explanation
Correct answer: B
In Carbon Black Cloud's policy evaluation logic, permission rules (allow lists) are always evaluated before blocking and isolation rules (deny lists). If an application's behavior matches a permission rule, it is allowed, and processing for that event stops. The blocking rule for code injection will not be evaluated for the trusted tool. This ensures that specific exceptions can be made without weakening the overall security posture.
- Question 9Beginner
VMware Carbon Black Cloud Enterprise EDR · Identify the structure of an alert in Cloud Enterprise EDR.
A new analyst is reviewing an alert in Carbon Black Cloud Enterprise EDR. They observe a process with a reputation of 'ADAPTIVE_WHITE'. What does this reputation signify?
Show answer & explanation
Correct answer: C
'ADAPTIVE_WHITE' is a cloud-derived reputation. It indicates that the binary is seen frequently across many organizations, is typically signed by a reputable publisher, and exhibits no malicious behaviors. This helps analysts quickly filter out noise from common, known-good applications like operating system components or popular software.
- Question 10Intermediate
VMware Carbon Black EDR · Identify how and when to use and configure feeds in EDR.
True or False: The on-premises VMware Carbon Black EDR server requires an active internet connection to receive threat intelligence from the Carbon Black Threat Analysis Unit (TAU).
Show answer & explanation
Correct answer: A
The statement is true. The on-premises EDR server relies on threat intelligence feeds for context and detection. The default feeds, including critical intelligence from the TAU, are downloaded from the Carbon Black Alliance feed server over the internet. While EDR can function in an air-gapped environment, it would lose this critical, up-to-date threat intelligence context unless feeds are manually imported.
Ready for the real thing?
The full 5V0-91.20 simulator has every exam-style question, timed mode, and instant scoring.