Which service does VMware Carbon Black Cloud use for threat detection?
ABehavioral Analysis
BStatic Analysis
CManual Review
DUser Feedback
Explanation
Behavioral Analysis is used for real-time threat detection; other options do not provide instant detection.
Q2
You are configuring application control policies in Carbon Black Cloud. What is the primary benefit of using whitelisting?
ABlocks all applications automatically
BReduces false positives
CSimplifies incident response process
DAllows unverified apps to run
Explanation
Whitelisting reduces false positives by only allowing approved applications; other options are incorrect regarding whitelisting's function.
Q3
A company needs to respond to an incident in Carbon Black Cloud; which feature should they primarily utilize for investigation?
ACloud Entitlements
BThreat Graph
CLive Query
DEndpoint Isolation
Explanation
Live Query allows real-time data investigation; the other features do not provide immediate investigative capabilities.
Q4
Which service provides real-time incident response capabilities?
AVMware Carbon Black Cloud
BVMware vSphere
CVMware NSX
DVMware Horizon
Explanation
VMware Carbon Black Cloud is specifically designed for real-time incident response, while the others focus on virtualization and network security.
Q5
A company needs to block access to a specific website. What is the best approach using VMware Carbon Black?
ACreate a technical support ticket
BSet up a policy to block URLs
CEnable network traffic analysis
DInstall a firewall appliance
Explanation
Setting up a policy in Carbon Black specifically allows blocking of URLs effectively, unlike the others.
Q6
What happens when an endpoint fails a security check in Carbon Black?
ANothing occurs; checks are periodic
BEndpoint is isolated automatically
CAlert triggered for investigation
DEndpoint is deleted from network
Explanation
An alert is triggered for investigation when a security check fails, while isolation and deletion are not standard actions without human intervention.
Q7
Which service provides endpoint detection and response in VMware Carbon Black Cloud?
AThreat Detection
BCloud Compliance
CIncident Response
DComputer Management
Explanation
Threat Detection service identifies advanced threats; others serve different purposes.
Q8
A company needs to ensure that users receive alerts for unauthorized software installations. What should they implement?
APolicy Management
BThreat Hunting
CApplication Control
DUser Activity Monitoring
Explanation
Application Control prevents unauthorized software; others do not enforce installation policies.
Q9
You are configuring an alert for suspicious file modifications. What happens when this alert triggers?
AAutomated file restoration occurs
BAnalysis of the event starts
CNotifications are sent to IT admins
DUser access is immediately revoked
Explanation
Notifications inform admins of issues; relevant analysis follows, but auto-restoration or revocation doesn't happen.
Q10
Which service within VMware Carbon Black Cloud focuses on endpoint detection and response?
AAdvanced Threat Detection
BThreat Intelligence
CEndpoint Detection and Response
DBehavioral Analysis
Explanation
Endpoint Detection and Response is specifically designed for detecting and responding to threats on endpoints, while others focus on different aspects of security.