Skip to content

5V0-93-22 Carbon Black Cloud Endpoint Standard Skills Practice Questions

Prepare for 5V0-93-22 with more than an answer.

257 questions in the full set20 sample questionsUpdated Mar 13, 2026

Unlock the full exam and previous versions

  • v1Version 1 257 questions Current
  • 5V0-91.20Legacy Carbon Black Portfolio Skills 248 questions Locked
Exam fee
$250 USD
Level
Specialist
Valid for
2 years
Domains covered on the exam 7
  1. Architectures and Technologies10%
  2. VMware Products and Solutions20%
  3. Planning and Designing15%
  4. Installing, Configuring, and Setup25%
  5. Performance-tuning, Optimization, Upgrades5%
  6. Troubleshooting and Repairing5%
  7. Administrative and Operational Tasks20%
  1. 1

    A new malware variant is discovered that uses a specific command-line argument, --exploit-now, with the legitimate Windows utility bitsadmin.exe. An administrator needs to create a rule to block any execution of bitsadmin.exe that includes this specific argument, without blocking its legitimate uses. Which rule configuration is the most precise way to achieve this?

    Show answer details

    Correct answer: B

    Carbon Black Cloud rules can target not only the process name but also specific command-line arguments. Creating a process blocking rule for bitsadmin.exe and adding the condition that the command line must contain --exploit-now provides the necessary precision. This blocks the malicious usage while allowing all other legitimate executions of bitsadmin.exe to proceed.

  2. 2

    True or False: A single Carbon Black Cloud policy can be applied to endpoints running Windows, macOS, and Linux simultaneously.

    Show answer details

    Correct answer: A

    This is true. Carbon Black Cloud policies are designed to be cross-platform. A single policy contains sections for Windows, macOS, and Linux, allowing an administrator to define platform-specific prevention rules and sensor settings within one consolidated policy. This simplifies management in heterogeneous environments.

  3. 3

    An organization wants to integrate Carbon Black Cloud alerts into their Security Information and Event Management (SIEM) platform. They need a secure, API-based method to forward alert data. Which native integration feature should be configured in the Carbon Black Cloud console?

    Show answer details

    Correct answer: B

    The Event Forwarder is the designated feature for sending event and alert data to an external SIEM. It securely pushes data to an AWS S3 bucket, from which the SIEM can then collect it. This provides a scalable and reliable method for data integration. API Access levels and keys are required to set it up, but the feature itself is the Event Forwarder.

  4. 4

    A SOC manager is reviewing the effectiveness of their Carbon Black Cloud policies. They notice a large number of alerts are being generated for legitimate administrative tools used by the IT department, such as psexec.exe. This is causing alert fatigue. Which actions would help reduce these false positive alerts without creating a security hole? (Select TWO)

    Show answer details

    Correct answer: B, D

    The best approach is precise tuning. Creating specific permission rules that allow the tools to run when executed from a specific path or signed by a trusted publisher reduces noise for legitimate use. Additionally, if the alerts are from a watchlist, tuning the watchlist query (e.g., to exclude executions by known IT admin accounts) can significantly reduce false positives. Globally approving the hash could be risky if the tool is ever compromised. Disabling prevention rules weakens security.

  5. 5

    A network architect is reviewing the data flows for a Carbon Black Cloud deployment to create firewall rules. Which diagram accurately represents the primary communication path for a sensor to report events and receive policy updates?

    graph TD subgraph CorporateNetwork["Corporate Network"] Sensor[Endpoint Sensor] end subgraph Internet["Internet"] CBC[Carbon Black Cloud] end Firewall[Firewall] Sensor --> Firewall --> CBC

    Show answer details

    Correct answer: B

    The diagram and standard architecture show that the sensor always initiates the communication. It establishes a secure, persistent outbound connection to the Carbon Black Cloud backend over TCP port 443. This connection is bidirectional in nature, allowing the sensor to stream event data to the cloud and the cloud to push down policy updates, commands, and other instructions without requiring any inbound firewall rules.

  6. 6

    A security architect is designing a Carbon Black Cloud policy for a fleet of developer workstations. The developers frequently use unsigned, internally-developed command-line tools. The security team requires that all known malware is blocked, but wants to avoid disrupting development workflows. Which Reputation Priority configuration within the policy best balances these requirements?

    Show answer details

    Correct answer: B

    Setting Carbon Black Intelligence (Cloud) reputation to the highest priority ensures that known malware and suspicious files identified by VMware's threat intelligence are blocked first. This provides the core security requirement. Since the internal tools are unsigned, prioritizing Company Approved (Signed) would not help and could be complex to manage. Prioritizing IT Tools or ignoring reputation would weaken the security posture unacceptably.

  7. 7

    During an incident investigation, a SOC analyst needs to find all network connections made by the process svchost.exe that did NOT go to a specific internal domain corp.local. Which search query would accomplish this?

    Show answer details

    Correct answer: C

    The correct syntax to exclude a value in a Carbon Black Cloud search query is to prefix the field with a hyphen (-). This query correctly filters for events where the process name is svchost.exe and excludes any events where the network connection domain is corp.local. The NOT operator is not used in this manner for field value exclusion.

  8. 8

    A system administrator notices that the Carbon Black sensor is causing high CPU utilization on a critical database server. The high CPU usage correlates with frequent write operations to a specific log directory, D:\AppLogs\. The security team has confirmed these write operations are benign and part of the application's normal function. What is the most precise and efficient way to resolve the performance issue without weakening the server's overall security posture?

    Show answer details

    Correct answer: B

    A Sensor Operation Exclusion is designed specifically for performance tuning. It instructs the sensor to ignore file, script, and network operations for a specified path or certificate, which directly addresses the high CPU caused by monitoring frequent, benign write operations. Event Reporting Exclusions only stop events from being sent to the cloud, but the sensor still processes them locally. Adding a permission rule doesn't stop the sensor from monitoring the activity, and placing the sensor in bypass mode is a significant security risk.

  9. 9

    An incident responder is using Live Response to investigate a compromised Windows endpoint. They need to retrieve a suspicious file named update.dll from the user's temporary directory for offline analysis. Which sequence of commands should be used?

    Show answer details

    Correct answer: A

    The correct sequence is to first change the current directory to the location of the file using cd %temp%, and then use the get command to retrieve the file from the endpoint to the Carbon Black Cloud. The pull command does not exist. Executing get with the full path is also a valid method, but the cd command is commonly used to simplify paths. The memget command is for retrieving process memory, not files.

  10. 10

    A security policy is configured with a rule to block the execution of powershell.exe. A separate, lower-precedence rule in the same policy adds a permission for a digitally signed PowerShell script, C:\scripts\admin_tool.ps1. When a user attempts to run this signed script, what is the expected outcome?

    Show answer details

    Correct answer: B

    In Carbon Black Cloud's prevention logic, if the interpreter (powershell.exe in this case) is explicitly blocked, any scripts that rely on that interpreter will also be blocked, regardless of permissions on the script file itself. The block on the parent process (powershell.exe) is enforced before the script is even processed.

Create an account to continue.