Weekend Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: xmas50

IBM C1000-162 - IBM Security QRadar SIEM V7.5 Analysis

Page: 1 / 5
Total 139 questions

What is the primary use of viewing the Magnitude metric on the Offenses tab?

A.

Determine which events to investigate last.

B.

Determine the credibility rating that is configured in the log source.

C.

Understand the type of offense we are facing.

D.

Identify the importance of the offense in your environment.

Several systems were initially reviewed as active offenses, but further analysis revealed that the traffic generated by these source systems is legitimate and should not contribute to offenses.

How can the activity be fine-tuned when multiple source systems are found to be generating the same event and targeting several systems?

A.

Edit the building blocks by using the Custom Rules Editor to tune out a destination IP

B.

Use the Log Source Management app to tune the event

C.

Edit the building blocks by using the Custom Rules Editor to tune out the specific event

D.

Edit the building blocks by using the Custom Rules Editor to tune out a source IP

What is the benefit of using default indexed properties for searching in QRadar?

A.

It increases the amount of data required to be searched.

B.

It improves the speed of searches.

C.

It returns fewer results than non-indexed properties.

D.

It reduces the number of indexed search values.

Which reference set data element attribute governs who can view its value?

A.

Tenant Assignment

B.

Origin

C.

Reference Set Management MSSP

D.

Domain

Which two (2) options are at the top level when an analyst right-clicks on the Source IP or Destination IP that is associated with an offense at the Offense Summary?

A.

Information

B.

Asset Summary page

C.

Navigate

D.

WHOIS Lookup

E.

DNS Lookup

Which statement regarding the Assets tab is true?

A.

The display is populated with all discovered assets in your network.

B.

It displays flow information to determine how and what network traffic is communicated.

C.

It displays connection information to determine how different network devices are connected.

D.

The display is populated with all eliminated and recreated assets in your network.

How can adding indexed properties to QRadar improve the efficiency of searches?

A.

By reducing the size of the data set required to find non-indexed search values

B.

By increasing the size of the data set required to find non-indexed search values

C.

By slowing down the search process

D.

By reducing the number of indexed search values

An analyst wants to share a dashboard in the Pulse app with colleagues.

The analyst exports the dashboard by using which format?

A.

CSV

B.

JSON

C.

XML

D.

PHP

How do events appear in QRadar if there was an error in the JSON parser for a new log source to which a custom log source extension was created?

A.

SIM events

B.

Parsed events

C.

Stored events

D.

CRE events

Which two (2) components are necessary for generating a report using the QRadar Report wizard?

A.

Saved search

B.

Dynamic search

C.

Layout

D.

Quick search

E.

Email address