5V0-91.20 Exam Question 31
An administrator uses the following Enterprise EDR search query to show web browsers spawning nonbrowser child processes that connect over the network:
(parent_name:chrome.exe OR parent_name:iexplore.exe OR parent_name:firefox.exe) AND (NOT process_name:chrome.exe OR NOT process_name:iexplore.exe OR NOT process_name:firefox.exe) Which field can be added to this query to filter the results by signature status?
(parent_name:chrome.exe OR parent_name:iexplore.exe OR parent_name:firefox.exe) AND (NOT process_name:chrome.exe OR NOT process_name:iexplore.exe OR NOT process_name:firefox.exe) Which field can be added to this query to filter the results by signature status?
5V0-91.20 Exam Question 32
An Enterprise EDR administrator is reviewing the Investigate page and believes they are receiving false positive hits from specific watchlist.
Which three options reduce future false positive hits from this watchlist? (Choose three.)
Which three options reduce future false positive hits from this watchlist? (Choose three.)
5V0-91.20 Exam Question 33
Which statement correctly defines the results of ignoring a feed report?
5V0-91.20 Exam Question 34
Which statement filters data to only return rows where the publisher of the software includes VMware anywhere in the name?
5V0-91.20 Exam Question 35
An Endpoint Standard administrator is working with an IT team to explicitly permit specific applications from the environment using both the IT Tools and Certs Approved List features.
Once applied, which reputation would these applications be classified under for processing?
Once applied, which reputation would these applications be classified under for processing?
