5V0-93-22 Sample Questions

5V0-93-22 Sample Questions & Answers

Implementing rules plus scanner and sensor configuration carries the most weight, next to response capabilities and reputation notifications, search, investigation and alert management, policy planning, basic architecture, and performance tuning.

Launch the full 5V0-93-22 simulator →

Showing 10 of 20 free samples.

  1. Question 1Beginner

    Architectures and Technologies · Identify the functionality of sensor vs. cloud.

    True or False: The Carbon Black Cloud sensor on a macOS endpoint can function and apply prevention policies even when it cannot communicate with the Carbon Black Cloud backend.

    Show answer & explanation

    Correct answer: A

    This is true. The Carbon Black Cloud sensor is designed to operate autonomously. It downloads the latest policy and threat intelligence, allowing it to enforce prevention rules and block threats even when the endpoint is offline or unable to reach the cloud. When connectivity is restored, it uploads the queued event data.

  2. Question 2IntermediateSelect 2

    Administrative and Operational Tasks · Given a security incident scenario, identify the first response that should be used within the VMware Carbon Black Cloud.

    A security analyst receives a high-severity alert for lsass.exe being accessed by a non-system process on a domain controller. This is a strong indicator of a credential dumping attack. According to best practices, what are the most critical initial response actions to take directly from the Carbon Black Cloud console? (Select TWO)

    Show answer & explanation

    Correct answers: A, B

  3. Question 3Advanced

    Installing, Configuring, and Setup · Given organizational requirements, identify how to implement the Carbon Black Cloud Endpoint Standard rules to prevent and mitigate attacks.

    A financial services company is deploying Carbon Black Cloud Endpoint Standard. Due to regulatory compliance, they must prevent any process from writing files with the extension .dat to any external USB storage device. Which type of rule should an administrator create to enforce this specific requirement?

    Show answer & explanation

    Correct answer: D

    This requirement calls for controlling a specific operation (write) based on file path and device type. An 'operation' blocking rule is the correct tool. It can be configured to target the 'write' operation, specify the file pattern (*\*.dat), and apply this logic only when the target media is 'removable'. This provides precise control without blocking legitimate use of USB devices or processes.

  4. Question 4Beginner

    Administrative and Operational Tasks · Given the scenario including the status of a sensor, identify the correct action for a sensor.

    While reviewing the sensor status on the Endpoints page, an administrator sees a device with the status 'Deregistered'. What does this status indicate about the sensor and the device?

    Show answer & explanation

    Correct answer: A

    The 'Deregistered' status means that the sensor has been properly uninstalled from the endpoint using the command-line with the company deregistration code. The console record is maintained for a short period before being automatically purged. This is different from a sensor that is merely offline or has been manually deleted from the console.

  5. Question 5Intermediate

    Administrative and Operational Tasks · Given a scenario, identify the proper Reputation override option.

    A company has a custom-built legacy application that is unsigned and frequently flagged as 'SUSPICIOUS' by Carbon Black Cloud, causing business interruptions. The application is known to be safe. The security team wants to ensure this specific application can always run without being blocked, across all policies, without affecting the reputation evaluation of any other applications. What is the most appropriate global override to apply?

    Show answer & explanation

    Correct answer: A

    Adding the application's SHA-256 hash to the 'Approved List' (a reputation override) is the most specific and secure method. This action globally designates that specific binary as trusted, ensuring it will run regardless of policy settings or its cloud reputation. Banning it is incorrect. Adding it to the 'IT Tool' list is less definitive and can be overridden by policy. A permission rule is policy-specific, not global.

  6. Question 6IntermediateSelect 2

    Architectures and Technologies · Identify the functionality of sensor vs. cloud.

    Which two data types are processed primarily by the sensor on the endpoint itself rather than requiring real-time analysis in the Carbon Black Cloud? (Select TWO)

    Show answer & explanation

    Correct answers: A, B

  7. Question 7Advanced

    Planning and Designing · Given organizational requirements, identify how to implement the Carbon Black Cloud Enpoint Standard policies to meet the requirements.

    A hospital is implementing Carbon Black Cloud to protect endpoints that run critical medical imaging software. The software vendor has stated that their application, MedView.exe, must not be subject to any delays or interference from security software. However, the hospital's security policy must be set to the highest prevention level for all other applications. How can an administrator configure a policy to meet these conflicting requirements?

    Show answer & explanation

    Correct answer: C

    The 'Bypass' policy action within a permission rule is specifically designed for this use case. It allows the specified process (MedView.exe) to run while instructing the sensor to perform no monitoring or prevention on that process or any of its children. This completely avoids interference with the critical application while the rest of the policy can remain at the highest prevention level for all other processes on the system.

  8. Question 8Intermediate

    Installing, Configuring, and Setup · Given a set of rules, identify intended impacts on the endpoints.

    An administrator is creating a custom policy and wants to ensure that if a user attempts to run a file with a TRUSTED_WHITE reputation, it is always allowed to run, but its child processes are still monitored for suspicious behavior. Which permission rule configuration achieves this?

    Show answer & explanation

    Correct answer: C

    The 'Allow' action in a permission rule ensures the target application can run, but the sensor continues to monitor its behavior and the behavior of any child processes it spawns. 'Allow & Log' is not a standard action. 'Bypass' would prevent monitoring of child processes, which violates the requirement. 'Deny' is the opposite of what is needed.

  9. Question 9Beginner

    Installing, Configuring, and Setup · Given a scenario, identify the proper configuration of the local scanner.

    What is the primary function of the 'local scanner' component within the Carbon Black Cloud sensor?

    Show answer & explanation

    Correct answer: C

    The local scanner is a core component of Carbon Black's NGAV (Next-Generation Antivirus) capabilities. Its primary function is to perform deep analysis on files that are not already known to be good or bad. It uses local machine learning models and heuristics to determine if a file is malicious, providing protection even when the endpoint is offline and cannot query the cloud reputation service.

  10. Question 10Beginner

    Administrative and Operational Tasks · Given a scenario, identify how to respond to an alert.

    An administrator is investigating an alert and wants to understand the full execution chain leading up to the suspicious event. They need to visualize the parent-child process relationships, network connections, and file modifications associated with the alert. Which feature in the Carbon Black Cloud console is specifically designed for this type of analysis?

    Show answer & explanation

    Correct answer: B

    The Alert Triage Page contains the process analysis tree, which is the primary tool for this purpose. It provides a graphical representation of the entire event chain, showing process ancestry, command-line arguments, network connections, file modifications, and registry changes, all in a single, interactive view. The Investigate page is for free-form searching, not visualizing a specific alert's context.

Ready for the real thing?

The full 5V0-93-22 simulator has every exam-style question, timed mode, and instant scoring.