Weekend Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: xmas50

IBM C1000-156 - IBM Security QRadar SIEM V7.5 Administration

Page: 1 / 2
Total 62 questions

Which is the default port for the first NetFlow flow source that is configured in QRadar?

A.

8413

B.

21

C.

2055

D.

514

Which User Management option manages the QRadar functions that the user can access?

A.

Security Profile

B.

Admin Role

C.

Security Options

D.

User Role

How can an administrator configure a rule response to add event data to a reference set?

A.

Write a custom script.

B.

Use AQL functions.

C.

Use the "add the following data to a reference set" rule test.

D.

Use the "add to reference set" rule response.

Which two (2) open standards does the QRadar Threat Intelligence app use for feeds?

A.

TAXII

B.

AQL

C.

STIX

D.

JSON

E.

OSINT

Which profile database does the Server Discovery function use to discover several types of servers on a network?

A.

Flow profile database

B.

Network profile database

C.

Domain profile database

D.

Asset profile database

An administrator is reviewing the system notifications and discovers this error:

Insufficient disk space to complete data export request.

The Export Directory property in the System Settings has the default configuration.

Which disk partition does the administrator need to check?

A.

/store/ariel/events/exports

B.

/var/log/exports

C.

/storetmp/exports

D.

/store/exports

An administrator wants to export a list of events to a CSV file. Which items are in the default columns of the search result?

A.

Log Source. Event Count. High Level Category. Related Offense

B.

Event Name. Application, Username, Log Source

C.

Username. Source Port. Event Count, Magnitude

D.

Protocol. Storage Time, Destination Port, Source Port

Which is a valid routing rule combination?

A.

Drop and Bypass Correlation

B.

Drop and Log Only

C.

Forward and Bypass Correlation

D.

Bypass Correlation and Log Only

How can you configure a log source to provide events to different domains?

A.

Create a saved search on the Network Activity tab to view events in specific domains.

B.

Use the Assistant app to update the domain information for the log source.

C.

Use custom properties to assign events from a single log source to different domains.

D.

Use the Use Case Manager app to update building blocks to support multi domain events.

You analyzed network flows and decided that you want to track any network bandwidth violations by any application that comes from your network source. You want to report on all applications that create traffic and the amount of data (total bytes) from each IP. You want to store the IP address, the application, and the amount of data in the reference data collection.

What type of reference data collection must you create to support this use case?

A.

Reference map

B.

Reference map of maps

C.

Reference set

D.

Reference map of sets