This course is in active development. Preview the scope below and create a free account to be notified the moment it goes live.
5V09122 CB Audit Specialist (5V0-91.22)
VMware Carbon Black Cloud Audit and Remediation Specialist (5V0-91.22) teaches learners to design audit architecture, craft and run queries, and implement compliance strategies using the Cloud platform.
Who Should Take This
It is ideal for security analysts, threat investigators, and compliance engineers who already manage VMware Carbon Black Cloud environments and need deeper expertise. Candidates should have at least two years of experience with endpoint security and incident response, and they aim to lead audit and remediation initiatives across their organization.
What's Covered
1
Domain 1: Audit Architecture
2
Domain 2: Query Development
3
Domain 3: Live Queries
4
Domain 4: Scheduled Queries
5
Domain 5: Compliance
6
Domain 6: Remediation
7
Domain 7: Troubleshooting
What's Included in AccelaStudy® AI
Course Outline
70 learning goals
1
Domain 1: Audit Architecture
2 topics
Platform Architecture
- Apply CB Cloud Audit and Remediation architecture including osquery engine, query scheduling, and result collection configuration and operational procedures for enterprise VMware environments.
- Apply CB Cloud Audit and Remediation architecture including osquery engine, query scheduling, and result collection best practices including deployment standards and integration with related components.
- Analyze CB Cloud Audit and Remediation architecture including osquery engine, query scheduling, and result collection configuration and data to identify issues, performance bottlenecks, and optimization opportunities.
- Analyze CB Cloud Audit and Remediation architecture including osquery engine, query scheduling, and result collection tradeoffs between different implementation approaches evaluating complexity, cost, and operational impact.
- Design a CB Cloud Audit and Remediation architecture including osquery engine, query scheduling, and result collection strategy that satisfies enterprise requirements for scalability, performance, security, and governance.
Query Framework
- Apply osquery SQL framework including table schema, cross-platform differences, and query optimization techniques for complex scenarios requiring multi-component coordination and integration.
- Apply osquery SQL framework including table schema, cross-platform differences, and query optimization integration with monitoring, automation, and third-party systems for unified management.
- Analyze osquery SQL framework including table schema, cross-platform differences, and query optimization failures and degradation using diagnostic tools, logs, and metrics to determine root causes.
- Analyze the operational impact of osquery SQL framework including table schema, cross-platform differences, and query optimization changes on dependent services and infrastructure stability.
- Design comprehensive osquery SQL framework including table schema, cross-platform differences, and query optimization procedures including automation, monitoring, escalation, and documentation.
2
Domain 2: Query Development
2 topics
SQL Queries
- Apply osquery SQL query development for system inventory, configuration assessment, and security posture checks configuration and operational procedures for enterprise VMware environments.
- Apply osquery SQL query development for system inventory, configuration assessment, and security posture checks best practices including deployment standards and integration with related components.
- Analyze osquery SQL query development for system inventory, configuration assessment, and security posture checks configuration and data to identify issues, performance bottlenecks, and optimization opportunities.
- Analyze osquery SQL query development for system inventory, configuration assessment, and security posture checks tradeoffs between different implementation approaches evaluating complexity, cost, and operational impact.
- Design a osquery SQL query development for system inventory, configuration assessment, and security posture checks strategy that satisfies enterprise requirements for scalability, performance, security, and governance.
Advanced Queries
- Apply advanced query techniques including JOINs, subqueries, and platform-conditional logic techniques for complex scenarios requiring multi-component coordination and integration.
- Apply advanced query techniques including JOINs, subqueries, and platform-conditional logic integration with monitoring, automation, and third-party systems for unified management.
- Analyze advanced query techniques including JOINs, subqueries, and platform-conditional logic failures and degradation using diagnostic tools, logs, and metrics to determine root causes.
- Analyze the operational impact of advanced query techniques including JOINs, subqueries, and platform-conditional logic changes on dependent services and infrastructure stability.
- Design comprehensive advanced query techniques including JOINs, subqueries, and platform-conditional logic procedures including automation, monitoring, escalation, and documentation.
3
Domain 3: Live Queries
2 topics
Execution
- Apply Live Query execution for real-time endpoint assessment including scope selection and result analysis configuration and operational procedures for enterprise VMware environments.
- Apply Live Query execution for real-time endpoint assessment including scope selection and result analysis best practices including deployment standards and integration with related components.
- Analyze Live Query execution for real-time endpoint assessment including scope selection and result analysis configuration and data to identify issues, performance bottlenecks, and optimization opportunities.
- Analyze Live Query execution for real-time endpoint assessment including scope selection and result analysis tradeoffs between different implementation approaches evaluating complexity, cost, and operational impact.
- Design a Live Query execution for real-time endpoint assessment including scope selection and result analysis strategy that satisfies enterprise requirements for scalability, performance, security, and governance.
Response Analysis
- Apply Live Query result analysis including data filtering, export, and actionable finding identification techniques for complex scenarios requiring multi-component coordination and integration.
- Apply Live Query result analysis including data filtering, export, and actionable finding identification integration with monitoring, automation, and third-party systems for unified management.
- Analyze Live Query result analysis including data filtering, export, and actionable finding identification failures and degradation using diagnostic tools, logs, and metrics to determine root causes.
- Analyze the operational impact of Live Query result analysis including data filtering, export, and actionable finding identification changes on dependent services and infrastructure stability.
- Design comprehensive Live Query result analysis including data filtering, export, and actionable finding identification procedures including automation, monitoring, escalation, and documentation.
4
Domain 4: Scheduled Queries
2 topics
Scheduling
- Apply scheduled query configuration for continuous compliance monitoring and configuration drift detection configuration and operational procedures for enterprise VMware environments.
- Apply scheduled query configuration for continuous compliance monitoring and configuration drift detection best practices including deployment standards and integration with related components.
- Analyze scheduled query configuration for continuous compliance monitoring and configuration drift detection configuration and data to identify issues, performance bottlenecks, and optimization opportunities.
- Analyze scheduled query configuration for continuous compliance monitoring and configuration drift detection tradeoffs between different implementation approaches evaluating complexity, cost, and operational impact.
- Design a scheduled query configuration for continuous compliance monitoring and configuration drift detection strategy that satisfies enterprise requirements for scalability, performance, security, and governance.
Alerting
- Apply query-based alerting for compliance violations and security posture degradation techniques for complex scenarios requiring multi-component coordination and integration.
- Apply query-based alerting for compliance violations and security posture degradation integration with monitoring, automation, and third-party systems for unified management.
- Analyze query-based alerting for compliance violations and security posture degradation failures and degradation using diagnostic tools, logs, and metrics to determine root causes.
- Analyze the operational impact of query-based alerting for compliance violations and security posture degradation changes on dependent services and infrastructure stability.
- Design comprehensive query-based alerting for compliance violations and security posture degradation procedures including automation, monitoring, escalation, and documentation.
5
Domain 5: Compliance
2 topics
Assessment
- Apply endpoint compliance assessment using queries for CIS benchmarks, patch levels, and security configuration configuration and operational procedures for enterprise VMware environments.
- Apply endpoint compliance assessment using queries for CIS benchmarks, patch levels, and security configuration best practices including deployment standards and integration with related components.
- Analyze endpoint compliance assessment using queries for CIS benchmarks, patch levels, and security configuration configuration and data to identify issues, performance bottlenecks, and optimization opportunities.
- Analyze endpoint compliance assessment using queries for CIS benchmarks, patch levels, and security configuration tradeoffs between different implementation approaches evaluating complexity, cost, and operational impact.
- Design a endpoint compliance assessment using queries for CIS benchmarks, patch levels, and security configuration strategy that satisfies enterprise requirements for scalability, performance, security, and governance.
Reporting
- Apply compliance reporting and dashboard creation for security posture visibility and trend analysis techniques for complex scenarios requiring multi-component coordination and integration.
- Apply compliance reporting and dashboard creation for security posture visibility and trend analysis integration with monitoring, automation, and third-party systems for unified management.
- Analyze compliance reporting and dashboard creation for security posture visibility and trend analysis failures and degradation using diagnostic tools, logs, and metrics to determine root causes.
- Analyze the operational impact of compliance reporting and dashboard creation for security posture visibility and trend analysis changes on dependent services and infrastructure stability.
- Design comprehensive compliance reporting and dashboard creation for security posture visibility and trend analysis procedures including automation, monitoring, escalation, and documentation.
6
Domain 6: Remediation
2 topics
Remediation Workflows
- Apply remediation workflow design using Live Response scripts triggered by query findings configuration and operational procedures for enterprise VMware environments.
- Apply remediation workflow design using Live Response scripts triggered by query findings best practices including deployment standards and integration with related components.
- Analyze remediation workflow design using Live Response scripts triggered by query findings configuration and data to identify issues, performance bottlenecks, and optimization opportunities.
- Analyze remediation workflow design using Live Response scripts triggered by query findings tradeoffs between different implementation approaches evaluating complexity, cost, and operational impact.
- Design a remediation workflow design using Live Response scripts triggered by query findings strategy that satisfies enterprise requirements for scalability, performance, security, and governance.
Automation
- Apply automated remediation using API integration, CB Cloud actions, and third-party orchestration techniques for complex scenarios requiring multi-component coordination and integration.
- Apply automated remediation using API integration, CB Cloud actions, and third-party orchestration integration with monitoring, automation, and third-party systems for unified management.
- Analyze automated remediation using API integration, CB Cloud actions, and third-party orchestration failures and degradation using diagnostic tools, logs, and metrics to determine root causes.
- Analyze the operational impact of automated remediation using API integration, CB Cloud actions, and third-party orchestration changes on dependent services and infrastructure stability.
- Design comprehensive automated remediation using API integration, CB Cloud actions, and third-party orchestration procedures including automation, monitoring, escalation, and documentation.
7
Domain 7: Troubleshooting
2 topics
Query Issues
- Apply query troubleshooting for timeout errors, permission issues, and platform-specific table availability configuration and operational procedures for enterprise VMware environments.
- Apply query troubleshooting for timeout errors, permission issues, and platform-specific table availability best practices including deployment standards and integration with related components.
- Analyze query troubleshooting for timeout errors, permission issues, and platform-specific table availability configuration and data to identify issues, performance bottlenecks, and optimization opportunities.
- Analyze query troubleshooting for timeout errors, permission issues, and platform-specific table availability tradeoffs between different implementation approaches evaluating complexity, cost, and operational impact.
- Design a query troubleshooting for timeout errors, permission issues, and platform-specific table availability strategy that satisfies enterprise requirements for scalability, performance, security, and governance.
Integration Issues
- Apply Audit and Remediation integration troubleshooting for API connectivity and data forwarding techniques for complex scenarios requiring multi-component coordination and integration.
- Apply Audit and Remediation integration troubleshooting for API connectivity and data forwarding integration with monitoring, automation, and third-party systems for unified management.
- Analyze Audit and Remediation integration troubleshooting for API connectivity and data forwarding failures and degradation using diagnostic tools, logs, and metrics to determine root causes.
- Analyze the operational impact of Audit and Remediation integration troubleshooting for API connectivity and data forwarding changes on dependent services and infrastructure stability.
- Design comprehensive Audit and Remediation integration troubleshooting for API connectivity and data forwarding procedures including automation, monitoring, escalation, and documentation.
Scope
Included Topics
- Carbon Black Cloud Audit and Remediation (osquery-based), SQL queries, live query execution, scheduled queries, compliance assessment, endpoint posture, and remediation workflows.
- Enterprise-level VMware technology knowledge for VMware Carbon Black Cloud Audit and Remediation Specialist.
Not Covered
- Implementation details beyond stated certification scope.
- Vendor-specific third-party configurations.
- Current pricing and partner program details.
Official Exam Page
Learn more at VMware/Broadcom
5V0-91.22 is coming soon
Adaptive learning that maps your knowledge and closes your gaps.
Create Free Account to Be Notified