An administrator needs to fully analyze the relevant information of an event stored in the VMware Carbon Black Cloud.
On which page can this information be found?
Correct Answer: B
Explanation
The Investigate page in VMware Carbon Black Cloud Endpoint Standard is where the administrator can fully analyze the relevant information of an event stored in the VMware Carbon Black Cloud. The Investigate page allows the administrator to search for events based on various criteria, such as process name, hash, device name, policy, alert, and Carbon Black TTPs. The administrator can also use the New Investigate Experience toggle to switch to the Observations view, which provides more granular and enriched data about the events.
The Investigate page also provides access to the Process Analysis page, which is a graphical view of the event that shows the process tree, the event timeline, and the event details. The Process Analysis page can help the administrator to understand the context and impact of the event, as well as to take actions such as isolating the device, banningthe hash, or creating a watchlist. References: Carbon Black Cloud Endpoint Standard - Technical Overview, New Enriched Events Experience for Endpoint Standard Customers, Investigate Page