5V0-91.20 Exam Question 6
What is the meaning, if any, of the event Report write (removable media)?
5V0-91.20 Exam Question 7
An Enterprise EDR administrator sees the process in the graphic on the Investigate page but does not see an alert for this process:

How can the administrator generate an alert for future hits against this watchlist?

How can the administrator generate an alert for future hits against this watchlist?
5V0-91.20 Exam Question 8
An administrator viewed and filtered the results of a completed query within the User Interface for Audit and Remediation. The administrator exported the results to create charts and other visuals for reporting. When viewing the exported results, the administrator noticed some results were missing from the data set.
Why did the administrator not have the full data set from the query?
Why did the administrator not have the full data set from the query?
5V0-91.20 Exam Question 9
Examine the following EDR query:
file_desc:"Windows Command Processor" AND -process_name:cmd.exe
Which process will show in the query results?
file_desc:"Windows Command Processor" AND -process_name:cmd.exe
Which process will show in the query results?
5V0-91.20 Exam Question 10
An analyst is reviewing an alert in Enterprise EDR from a custom watchlist. The analyst disagrees with the alert severity rating.
How can the analyst change the alert severity value, if this is possible?
How can the analyst change the alert severity value, if this is possible?