5V0-91.20 Exam Question 26
Given an event rule: Approve nVidia Drivers, changes the local state to Approved for file writes or execution blocks when the publisher is NVIDIA Corporation.
How is an alert created that is triggered whenever an nVidia driver is approved by the event rule?
How is an alert created that is triggered whenever an nVidia driver is approved by the event rule?
5V0-91.20 Exam Question 27
Refer to the exhibit:

Which statement is true in regards to communication between the sensor and server?

Which statement is true in regards to communication between the sensor and server?
5V0-91.20 Exam Question 28
Review this result after executing a query in the Process Search page, noting the circled black dot:

What is the meaning of the black dot shown under Tags?

What is the meaning of the black dot shown under Tags?
5V0-91.20 Exam Question 29
An analyst wants to block an application's specific behavior but does not want to kill the process entirely as it is heavily used on workstations. The analyst needs to use a Blocking and Isolation Action to ensure that the process is kept alive while blocking further unwanted activity.
Which Blocking and Isolation Action should the analyst use to accomplish this goal?
Which Blocking and Isolation Action should the analyst use to accomplish this goal?
5V0-91.20 Exam Question 30
A security policy states to enable Live Response by default across the enterprise. However, the team identified critical systems which should not support Live Response due to risk. The team needs to disable Live Response on selected systems.
From which page can this goal be accomplished?
From which page can this goal be accomplished?