IBM C1000-156 - IBM Security QRadar SIEM V7.5 Administration
Which is the default port for the first NetFlow flow source that is configured in QRadar?
Which User Management option manages the QRadar functions that the user can access?
How can an administrator configure a rule response to add event data to a reference set?
Which two (2) open standards does the QRadar Threat Intelligence app use for feeds?
Which profile database does the Server Discovery function use to discover several types of servers on a network?
An administrator is reviewing the system notifications and discovers this error:
Insufficient disk space to complete data export request.
The Export Directory property in the System Settings has the default configuration.
Which disk partition does the administrator need to check?
An administrator wants to export a list of events to a CSV file. Which items are in the default columns of the search result?
Which is a valid routing rule combination?
How can you configure a log source to provide events to different domains?
You analyzed network flows and decided that you want to track any network bandwidth violations by any application that comes from your network source. You want to report on all applications that create traffic and the amount of data (total bytes) from each IP. You want to store the IP address, the application, and the amount of data in the reference data collection.
What type of reference data collection must you create to support this use case?