New Year Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

VMware Carbon Black Cloud Endpoint Standard Skills 5V0-93.22 Question # 11 Topic 2 Discussion

VMware Carbon Black Cloud Endpoint Standard Skills 5V0-93.22 Question # 11 Topic 2 Discussion

5V0-93.22 Exam Topic 2 Question 11 Discussion:
Question #: 11
Topic #: 2

An organization has found application.exe running on some machines in their Workstations policy. Application.exe has a SUSPECT_MALWARE reputation and runs from C:\Program Files\IT\Tools. The Workstations policy has the following rules which could apply:

Blocking and Isolation Rule

5V0-93.22 Question 11Application on the company banned list > Runs or is running > Deny

5V0-93.22 Question 11Known malware > Runs or is running > Deny

5V0-93.22 Question 11Suspect malware > Runs or is running > Terminate

Permissions Rule

5V0-93.22 Question 11C:\Program Files\IT\Tools\* > Performs any operation > Bypass

Which action, if any, should an administrator take to ensure application.exe cannot run?


A.

Change the reputation to KNOWN MALWARE to a higher priority.


B.

No action needs to be taken as the file will be blocked based on reputation alone.


C.

Remove the Permissions rule for C:\Program FilesMTVToolsV.


D.

Add the hash to the company banned list at a higher priority.


Get Premium 5V0-93.22 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.