1V0-91.22 Certified Technical Associate - Security (VCTA-Security 2024) Practice Questions
Prepare for 1V0-91.22 with more than an answer.
- Exam fee
- $250 USD
- Level
- Associate
- Valid for
- 2 years
Domains covered on the exam 6
- Architecture and Technologies20%
- Products and Solutions20%
- Planning and Designing15%
- Installing, Configuring, and Setup20%
- Performance-tuning, Optimization, and Upgrades15%
- Troubleshooting and Administrative Tasks10%
- 1
A company has deployed the VMware Carbon Black Cloud sensor to its VDI environment using a golden image. After deployment, administrators notice that new VDI desktops are not registering correctly in the console or are appearing as duplicates of the golden image. Which step was likely missed during the preparation of the golden image?
Show answer details
Correct answer: A
When installing the Carbon Black Cloud sensor on a golden image for non-persistent VDI, it is critical to use the
VDI=1flag during installation. This tells the sensor to perform a de-registration clean-up process before the image is sealed. When a new desktop is cloned from this image, the sensor will then generate a unique identity and register itself as a new device in the console, preventing duplication issues. - 2
The term 'Intrinsic Security' is central to VMware's security philosophy. What does this concept primarily mean?
Show answer details
Correct answer: B
Intrinsic Security refers to leveraging the hypervisor, network virtualization layer, and management platforms to deliver security services that are built-in, distributed, and context-aware. Instead of adding separate security appliances (firewalls, IPS, etc.), the security functions are inherent to the platform itself (e.g., NSX DFW running in the hypervisor kernel). This reduces complexity, eliminates security gaps, and leverages the platform's unique visibility.
- 3
A security administrator needs to create a watchlist in VMware Carbon Black Cloud to detect the use of a specific hacking tool,
mimikatz.exe. The watchlist should trigger an alert whenever this process is observed running on any endpoint. Which type of Indicator of Compromise (IOC) should be used in the watchlist report?Show answer details
Correct answer: B
To detect a specific process by its name, the watchlist query should use the
process_namefield. The queryprocess_name:mimikatz.exewill search all incoming process event data for an exact match to that process name and trigger an alert when found. Using the MD5 hash is also effective but would only match a specific version of the tool, whereas the process name is more general. - 4
The command
New-Az____ -Name 'MyDfwRule' -Source 'WebAppSG' -Destination 'DbAppSG' -Service 'MS-SQL' -Action 'Allow'is used to create an NSX-T Distributed Firewall rule via PowerShell. Which term correctly fills in the blank for the PowerShell cmdlet?Show answer details
Correct answer: C
While this question tests knowledge of a specific command, it reflects the type of automation and scripting familiarity expected. The correct cmdlet family for interacting with NSX-T via the PowerNSX module would typically follow a
Verb-NsxtNounformat.New-NsxtFirewallRuleis the plausible and correctly formatted cmdlet for creating a new DFW rule. Note: The actual module might differ, but this tests the logical naming convention used in PowerShell automation for VMware products. - 5
Case Study
A global retail company, OmniMart, is migrating its e-commerce platform to a new vSphere environment and wants to enhance its security. The platform's backend consists of hundreds of microservices running on virtual machines. The development team frequently deploys new services and updates existing ones, causing the communication patterns between services to change constantly.
The current security model relies on VLANs and a perimeter firewall, which has proven ineffective at preventing threats from spreading within the data center. The security team spends an excessive amount of time manually updating firewall rules to accommodate the dynamic nature of the microservices, leading to delays and potential security gaps. They have acquired the full VMware security stack.
Key Challenges:
- The security policy cannot keep up with the dynamic application environment.
- There is no visibility into the actual network flows between microservices.
- Creating a least-privilege security policy for hundreds of services is manually unfeasible.
Goal:
Automate the creation of a baseline micro-segmentation policy that reflects the actual, required communication paths between microservices and can adapt to changes in the environment.Which VMware security feature is specifically designed to address OmniMart's challenges?
Show answer details
Correct answer: B
NSX Intelligence is the correct solution. It provides deep visibility into network traffic flows within the data center, visualizing communication patterns between workloads (addressing challenge 2). Most importantly, it analyzes these flows and provides automated recommendations for DFW security policies and groups based on the observed traffic. This directly solves the problem of manually creating and updating rules for a dynamic microservices environment (addressing challenges 1 and 3).
- 6
A security analyst is investigating a threat alert in VMware Carbon Black Cloud. They need to understand the full execution chain of a suspicious binary, including all parent and child processes, network connections, and registry modifications initiated by the threat. Which feature within the Carbon Black Cloud console provides this detailed, chronological visualization?
Show answer details
Correct answer: C
The Process Analysis Tree is the specific feature in Carbon Black Cloud designed to provide a graphical, interactive visualization of an entire event chain. It shows the root cause, parent/child process relationships, network connections, and file modifications, which is exactly what the analyst needs for a deep investigation. Live Query is for ad-hoc querying of endpoints, and the Alerts Triage page provides a high-level list of alerts, not the detailed event chain.
- 7
A company is implementing a Zero Trust security model for its data center using VMware NSX-T. The primary goal is to prevent lateral movement of threats by isolating every workload. Which NSX-T feature is the most fundamental component for achieving this level of granular, workload-centric isolation?
Show answer details
Correct answer: B
The NSX Distributed Firewall (DFW) is the core component for implementing micro-segmentation. It operates at the vNIC level of each virtual machine, allowing for stateful firewalling between individual workloads on the same logical network segment. This capability is essential for creating a Zero Trust environment by enforcing least-privilege access and preventing lateral movement. The Gateway Firewall protects North-South traffic, while IDS/IPS and N/S Service Insertion are additional security services, not the fundamental isolation mechanism.
- 8
A Workspace ONE administrator needs to configure a compliance policy that automatically performs an enterprise wipe on any jailbroken or rooted Android device as soon as it is detected. Which two components must be configured in the Workspace ONE UEM console to achieve this? (Select TWO)
Show answer details
Correct answer: A, C
A compliance rule is needed to define the trigger condition. In this case, the rule must be set to detect the 'Compromised Status' of a device, which identifies jailbroken or rooted devices.
An action must be configured to specify what happens when the compliance rule is violated. For this requirement, the action must be set to 'Enterprise Wipe' to remove corporate data and management from the device.
- 9
True or False: VMware Carbon Black Cloud's Next-Generation Antivirus (NGAV) capabilities rely solely on signature-based detection to identify and block malware.
Show answer details
Correct answer: B
This statement is false. A key differentiator of NGAV solutions like Carbon Black Cloud is that they go beyond traditional signature-based detection. They heavily utilize behavioral analysis, machine learning models, and threat intelligence to detect both known and unknown (zero-day) threats based on their actions and patterns, not just their file hash.
- 10
A financial services firm is deploying VMware Carbon Black Cloud. Due to strict data residency regulations, all endpoint telemetry data must be stored and processed within the European Union. During the initial setup of the Carbon Black Cloud organization, which setting determines the geographical location of the data storage?
Show answer details
Correct answer: C
Data residency for Carbon Black Cloud is determined by the specific cloud instance the organization is provisioned on. VMware operates multiple instances in different geographic regions (e.g., prod.eu.confer.net for Europe). This selection is made during the initial organization setup and registration process and dictates where all data for that organization will reside. It cannot be changed after the organization is created.
