5V0-91.20 Exam Question 11

An administrator wants to allow files to run from a network share.
Which rule type should the administrator configure?
  • 5V0-91.20 Exam Question 12

    An Enterprise EDR administrator wants to use Watchlists curated by VMware Carbon Black and other threat intelligence specialists.
    How should the administrator add these curated Watchlists from the Watchlists page?
  • 5V0-91.20 Exam Question 13

    An analyst on the security team noticed that several alerts are false positives within Enterprise EDR. The analyst disables the IOC within the report from those alerts.
    Which statement correctly explains what disabling the IOC will accomplish?
  • 5V0-91.20 Exam Question 14

    Which two statements are true regarding Live Response? (Choose two.)
  • 5V0-91.20 Exam Question 15

    An Enterprise EDR administrator is reviewing the Investigate page and believes they are receiving false positive hits from specific watchlist.
    Which three options reduce future false positive hits from this watchlist? (Choose three.)