What happens when a detected threat is quarantined in Carbon Black?
AThe threat is deleted immediately
BUser cannot access the affected file
CThe file is restored automatically
DSystem performance is improved
Explanation
Quarantining a threat restricts user access to high-risk items, while the other options misrepresent the function of quarantine.
Q172
Which service provides advanced threat detection in VMware Carbon Black?
AThreat Intelligence
BData Protection
CNetwork Configuration
DUser Management
Explanation
Threat Intelligence offers insights into advanced threats, while others do not address threat detection directly.
Q173
A company needs to manage endpoint security policies efficiently. Which VMware Carbon Black feature should they utilize?
APolicy Management
BIncident Response
CCloud Backup
DUser Training
Explanation
Policy Management enables the efficient configuration of security policies for endpoints, unlike the other options.
Q174
You are configuring an endpoint detection rule. What happens when 'Observe' action is set for a suspicious process?
ASystem is isolated immediately
BNo action taken beyond monitoring
CAlerts are sent to admins
DProcess is terminated
Explanation
'Observe' allows monitoring without active intervention; other actions imply immediate responses.
Q175
Which service helps prevent unauthorized application execution in VMware Carbon Black?
AApplication Control
BThreat Intelligence
CIncident Response
DLogging and Monitoring
Explanation
Application Control specifically restricts unauthorized applications while others focus on different aspects.
Q176
You are configuring a policy in Carbon Black. What setting determines how long to retain event logs?
ARetention period
BLog expiry
CData lifecycle
DEvent archiving
Explanation
Retention period directly specifies the duration for event log storage.
Q177
What happens when a device fails to report to the Carbon Black server within the defined heartbeat interval?
ADevice is permanently disconnected
BAlert triggered for administrator
CLogging continues without alert
DDevice automatically reboots
Explanation
Failure to report within heartbeat triggers an alert, while other options are not accurate responses to the situation.
Q178
Which service does VMware Carbon Black use for threat intelligence?
ACloud Threat Library
BOn-Premise Analyzer
CLocal Intelligence Repository
DAPI-Based Threat Index
Explanation
The Cloud Threat Library aggregates threat intelligence from multiple sources, while other options are either local or not used for this purpose.
Q179
A company needs to deploy VMware Carbon Black across multiple platforms. What should they focus on first?
AUser interface customization
BCompatibility with operating systems
CMaximizing storage on endpoints
DDeveloping incident response plans
Explanation
Ensuring compatibility with operating systems is essential before deployment.
Q180
What happens when you set a high sensitivity level for a threat alert in Carbon Black?
AFewer alerts generated
BIncreased performance overhead
COnly critical threats reported
DMore events deemed safe
Explanation
Higher sensitivity increases detection but can lead to performance overhead due to more frequent scans.