VMware Carbon Black Cloud Endpoint Standard Skills 5V0-93.22 Question # 7 Topic 1 Discussion

VMware Carbon Black Cloud Endpoint Standard Skills 5V0-93.22 Question # 7 Topic 1 Discussion

5V0-93.22 Exam Topic 1 Question 7 Discussion:
Question #: 7
Topic #: 1

An administrator wants to prevent malicious code that has not been seen before from retrieving credentials from the Local Security Authority Subsystem Service, without causing otherwise good applications from being blocked.

Which rule should be used?


A.

[Unknown application] [Retrieves credentials] [Terminate process]


B.

[**/*.exe] [Scrapes memory of another process] [Terminate process]


C.

[**\lsass.exe] [Scrapes memory of another process] [Deny operation]


D.

[Not listed application] [Scrapes memory of another process] [Terminate process]


Get Premium 5V0-93.22 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.