5V0-91.20 Exam Question 26

Given an event rule: Approve nVidia Drivers, changes the local state to Approved for file writes or execution blocks when the publisher is NVIDIA Corporation.
How is an alert created that is triggered whenever an nVidia driver is approved by the event rule?
  • 5V0-91.20 Exam Question 27

    Refer to the exhibit:

    Which statement is true in regards to communication between the sensor and server?
  • 5V0-91.20 Exam Question 28

    Review this result after executing a query in the Process Search page, noting the circled black dot:

    What is the meaning of the black dot shown under Tags?
  • 5V0-91.20 Exam Question 29

    An analyst wants to block an application's specific behavior but does not want to kill the process entirely as it is heavily used on workstations. The analyst needs to use a Blocking and Isolation Action to ensure that the process is kept alive while blocking further unwanted activity.
    Which Blocking and Isolation Action should the analyst use to accomplish this goal?
  • 5V0-91.20 Exam Question 30

    A security policy states to enable Live Response by default across the enterprise. However, the team identified critical systems which should not support Live Response due to risk. The team needs to disable Live Response on selected systems.
    From which page can this goal be accomplished?