What is the difference between a watchlist and a report?
What section is Reputation found under?
Enforce
A red triangle symbol in an Endpoint's row indicates what?
Signature Out Of Date
Alert Severity is measured on:
A scale of 1 through 10
How do you switch customers in Carbon Black?
Drop down via top left corner
When should a CoreSOC analyst create a watchlist?
NEVER*
*Unless otherwise specified
What are the required fields to add a reputation for a Hash?
1. SHA-256
2. Name
Enabling the "______" mode removes all policy enforcement on the device.
bypass
Do the search fields vary between the "Alerts" and "Investigate" page?
Yes
Name a Carbon Black license.
Endpoint Standard
Enterprise EDR
Where can you find the purpose of a report?
Locate the report in the respective watchlist and click on it. There will be a summary of its purpose.
When adding a file hash to Reputation, what list is selected by default?
Approved List
Assuming a standard Windows 10 x64 machine, when going live what is the default directory you are first dropped into?
C:\WINDOWS\system32
A "modload" type event describes what process action?
Process loading a DLL.
Name a difference between Endpoint Standard and Enterprise EDR license?
1. Enriched events
2. Watchlist reports
3. Live Response
Which license is needed to have watchlists available?
Enterprise EDR
What type of hash is required when adding Reputation?
SHA-256
A "dir" reveals the following files in the current directory. What are these files most likely to be?
#B36C9550.doc
#C0A01807.jpg
$1CBFDBED.xls
$570A22BB.pptx
Canary Files
In the search guide, which page has the search field for "USB Device"?
Alerts
Which customer in Carbon Black are MSI users created under?
deltarisk
Which team creates custom MSI watchlists?
ATR
When should you add a reputation for a Cert?
NEVER
The following command will do this:
execfg powershell.exe /c get-childitem -path C:\ -include Alabama -recurse
Run a recursive search in the C drive for files containing "Alabama"
A process is terminated because it tried to access "lsass.exe". What is the most common and likely reason the process tried to access lsass, and why was it terminated?
Querying lsass in relation to some sort of authentication operation. Lsass is a common target by threat actors for scraping credentials.
Where can you check the status of a quarantine request?
Settings -> Inbox