Weekend Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: xmas50

IBM C1000-162 - IBM Security QRadar SIEM V7.5 Analysis

Page: 2 / 5
Total 139 questions

Which parameters are used to calculate the magnitude rating of an offense?

A.

Relevance, credibility, time

B.

Severity, relevance, credibility

C.

Relevance, urgency, credibility

D.

Severity, impact, urgency

Which two (2) of these custom property expression types are supported in QRadar?

A.

XLS

B.

YAML

C.

JSON

D.

Regex

E.

HTML

For a rule containing the test "and when the source is located in this geographic location" to work properly, what must a QRadar analyst configure?

A.

IBM X-Force Exchange updates

B.

MaxMind updates

C.

IBM X-Force Exchange ATP updates

D.

Watson updates

What two (2) guidelines should you follow when you define your network hierarchy?

A.

Do not configure a network group with more than 15 objects.

B.

Organize your systems and networks by role or similar traffic patterns.

C.

Use the autoupdates feature to automatically populate the network hierarchy.

D.

Import scan results into QRadar.

E.

Use flow data to build the asset database.

A QRadar analyst would like to search for events that have fully matched rules which triggered offenses.

What parameter and value should the analyst add as filter in the event search?

A.

Associated with Offense is True

B.

Associated with Rule is True

C.

Associated with Rule is False

D.

Associated with Offense is False

A QRadar analyst is investigating the events of an offense. For a particular event on the list, the analyst wants to know which rules were fully ditched for the event.

where can the analyst check to see if the event has any fully matched rules?

A.

On default dashboard

B.

On offense details

C.

On Pulse dashboard

D.

On event details page

What Is the result of the following AQL statement?

A.

Returns all fields where the username contains the ERS string and is case-sensitive

B.

Returns all fields where the username contains the ERS string and is case-insensitive

C.

Returns all fields where the username is different from the ERS string and is case-insensitive

D.

Returns all fields where the username is different from the ERS string and is case-sensitive

What are two (2) Y-axis types that are available in the scatter chart type in the Pulse app?

A.

Linear

B.

Log

C.

General

D.

Threshold

E.

Dynamic

What are the behavioral rule test parameter options?

A.

Behavioral rule. Current traffic level, Predicted value

B.

Season, Anomaly detection. Current traffic trend

C.

Season, Current traffic level, Predicted value

D.

Current traffic behavior. Behavioral rule. Current traffic level

An analyst is looking at flow payload. The analyst noted the payload is truncated.

|at default value size for the payload is exceeded where the payload might contain additional information that is not shown in the QRadar surface?

A.

32 bytes

B.

64 bytes

C.

256 bytes

D.

128 bytes