Weekend Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: xmas50

IBM C1000-156 - IBM Security QRadar SIEM V7.5 Administration

Page: 2 / 2
Total 62 questions

On which managed hosts is QRadar event data stored in the Ariel database?

A.

On the Event Collector and attached Data Node

B.

On the Data Gateway and attached Data Node

C.

On the Event Processor and attached Data Node

D.

On the App Host and attached Data Node

When adjusting a custom email template, which two elements do you edit to include the customizations?

A.

B.

C.

D.

Which field is mandatory when you use the DSM Editor to map an event to a OID?

A.

High-level Category

B.

Low-level Category

C.

Event Category

D.

Event ID

An administrator would like to optimize event and flow payload searches for log data that is stored for up to a month. What does an administrator need to do to achieve that requirement?

A.

Perform a clean on the search model.

B.

Configure the retention period for property indexes.

C.

Configure the retention period for payload indexes.

D.

Configure the retention period for search indexes.

A user reports that some data points are missing from a generated report. The logs show these notifications, which are determined to be the root

cause of the problem:

The accumulator was unable to aggregate all events/flows for this interval.

In what timeframe does this system need to complete data aggregation for it to be deemed successful?

A.

30 seconds

B.

5 seconds

C.

120 seconds

D.

60 seconds

Which three (3) resource restriction types are available in QRadar?

A.

Role-based restrictions

B.

Tenant-based restrictions

C.

User-based restrictions

D.

Service-based restrictions

E.

Event-based restrictions

F.

Domain-based restrictions

Which command in QRadar allows you to run a specific command inside of a specific container, when given an app ID. or a combination of workload, service, and container?

A.

ifconfig -a

B.

recon ps

C.

recon connect

D.

yum info

When do you consider reconfiguring your QRadar environment to a distributed deployment?

A.

When flow sources reach a threshold of 20 Mbps

B.

When processing or storage expands beyond capacity on your single deployed appliance

C.

When you need to upgrade the Log Source Manager application

D.

When your combined log sources are less than 2000 events per second