Which service provides the threat intelligence framework in VMware Carbon Black?
AThreat Intelligence Service
BBehavioral Analysis Engine
CManaged Detection Service
DEndpoint Protection Service
Explanation
The Threat Intelligence Service is integrated into VMware Carbon Black to provide real-time threat intelligence, while the others focus on different aspects of endpoint protection or detection.
Q2
A company needs to ensure continuous visibility into suspicious processes. Which VMware Carbon Black feature should they enable?
ALive Query
BEvent Monitoring
CIncident Response
DTask Scheduling
Explanation
Live Query allows real-time checks on suspicious processes, while the other options are related to event management and response operations.
Q3
You are configuring rules for preventing malware execution. What happens when a 'blocking' rule is triggered in Carbon Black?
AMalware is quarantined immediately
BExecution is blocked based on the rule
CUser is notified instantly
DEvent is logged for review
Explanation
When a 'blocking' rule triggers, the execution of the flagged process is stopped immediately, unlike the other options which describe different actions outside the scope of blocking rules.
Q4
Which service in VMware Carbon Black is responsible for continuous monitoring and threat detection?
AEndpoint Detection and Response (EDR)
BCloud Security Posture Management
CNetwork Security Analysis
DData Loss Prevention
Explanation
EDR is designed specifically for monitoring and detecting threats on endpoints; the others serve different purposes.
Q5
A company needs to ensure that all endpoints are compliant with preset security policies. What should they configure in Carbon Black?
APolicy Monitoring
BThreat Intelligence Alerts
CEndpoint Isolation
DMalware Isolation
Explanation
Policy Monitoring enables compliance with security policies; the others do not directly enforce policy adherence.
Q6
What happens when a previously whitelisted file has its status changed to blacklisted in Carbon Black?
AIt is automatically deleted from endpoints.
BEndpoints will block the execution.
CUsers will receive a notification only.
DNo action is taken on it.
Explanation
Changing a file to blacklisted status blocks execution on endpoints; the other options do not reflect correct actions taken.
Q7
Which service can integrate with VMware Carbon Black EDR for enhanced endpoint visibility?
AVMware vSphere
BTanzu Kubernetes
CCarbon Black App Control
DVMware Cloud Director
Explanation
Carbon Black App Control specifically complements EDR features, enhancing endpoint visibility and management.
Q8
A company needs to ensure its endpoint policies apply to new devices automatically. Which feature should they use?
AStatic Policies
BDynamic Rules
CPolicy Templates
DUser Group Policies
Explanation
Dynamic Rules automatically apply to new devices based on specific criteria, ensuring real-time policy enforcement.
Q9
What happens when a Windows endpoint is quarantined in VMware Carbon Black EDR?
AIt deletes all malware instantly
BIt isolates the device from network
CIt adds it to another group
DIt loses all configurations instantly
Explanation
Quarantining isolates the device from the network to prevent further threats while allowing investigation and resolution.
Q10
Which service in VMware Carbon Black is responsible for real-time monitoring?
AContinuous Monitoring
BStatic Analysis
CThreat Intelligence
DIncident Response
Explanation
Continuous Monitoring provides real-time endpoint data; the others focus on different operational aspects.