New Year Special Limited Time Flat 70% Discount offer - Ends in 0d 00h 00m 00s - Coupon code: 70spcl

IBM C1000-156 IBM Security QRadar SIEM V7.5 Administration Exam Practice Test

Page: 1 / 6
Total 62 questions

IBM Security QRadar SIEM V7.5 Administration Questions and Answers

Question 1

Which is a benefit of a lazy search?

Options:

A.

Getting results that are limited to a specific range

B.

Providing every result no matter the quantity of the search results

C.

Finding lOCs quickly

D.

Searching across domains for any configured user

Question 2

Which two (2) data sources can be assigned to a domain in the Domain Management function?

Options:

A.

Users

B.

Rules

C.

Flow collectors

D.

Log sources

E.

X-Force Integration Feed

Question 3

Which User Management option manages the QRadar functions that the user can access?

Options:

A.

Security Profile

B.

Admin Role

C.

Security Options

D.

User Role

Question 4

To detect outliers, which Anomaly Detection Engine rule tests events or flows for volume changes that occur in regular patterns?

Options:

A.

Behavioral rules

B.

Threshold rules

C.

Anomaly rules

D.

Building block rules

Question 5

What parameter contributes to the magnitude score of an offense?

Options:

A.

Confidentiality

B.

Availability

C.

Integrity

D.

Credibility

Question 6

In the QRadar GUI. you notice that no new offenses were generated today. A review of the notifications shows:

MPC: Unable to create new offense. The maximum number of active offenses has been reached.

What is the default value of the maximum number?

Options:

A.

3500

B.

1500

C.

5000

D.

2500

Question 7

A QRadar administrator creates a new saved search in QRadar.

Which option does the administrator enable to allow this search to be opened as the Log Activity tab is opened?

Options:

A.

Set as Default

B.

Include in my Quick Searches

C.

Include in my Dashboard

D.

Share with Everyone

Question 8

The Report wizard provides a step-by-step guide to design, schedule, and generate reports. Which three (3) key elements does the report wizard use to help you create a report?

Options:

A.

Content

B.

Format

C.

Container

D.

Display

E.

Banner

F.

Layout

Question 9

Which user role is defined by default in QRadar?

Options:

A.

Event and Logs

B.

QRadar Users

C.

WinCollect

D.

QRadar Managers

Question 10

Which is a valid routing rule combination?

Options:

A.

Drop and Bypass Correlation

B.

Drop and Log Only

C.

Forward and Bypass Correlation

D.

Bypass Correlation and Log Only

Question 11

On which managed hosts is QRadar event data stored in the Ariel database?

Options:

A.

On the Event Collector and attached Data Node

B.

On the Data Gateway and attached Data Node

C.

On the Event Processor and attached Data Node

D.

On the App Host and attached Data Node

Question 12

When restoring backups of your apps in a QRadar environment, what information is restored?

Options:

A.

The last known good version of your apps configuration, your application data, and any apps that were configured on an App Host are restored.

B.

The applications that are installed on the Console are restored, and any applications that are installed on an AppHost must be backed up separately.

C.

The apps configuration, the console configuration, and app data are restored.

D.

The apps configuration and app data are restored.

Question 13

How can an administrator configure a rule response to add event data to a reference set?

Options:

A.

Write a custom script.

B.

Use AQL functions.

C.

Use the "add the following data to a reference set" rule test.

D.

Use the "add to reference set" rule response.

Question 14

Which two (2) pieces of information from the MaxMind account must be included in QRadar for geographic data updates?

Options:

A.

Account/User ID

B.

API key

C.

License Key

D.

MaxMind username

E.

API password

Question 15

Which is a valid statement about the process of restoring a backup archive?

Options:

A.

A configuration restore must be performed on a console where the IP address matches the IP address of a managed host in the backup.

B.

A backup archive can only be restored for the same software version, including fix pack versions.

C.

When restoring all configuration items included in the backup archive, only configuration information, offense data, and asset data are restored.

D.

A restoration might fail if you restore the configuration backup before the data backup.

Question 16

From which site can you download software updates for QRadar?

Options:

A.

IBM Fix Central

B.

IBM X-Force Exchange

C.

IBM Passport Advantage Online

D.

QRadar 101

Question 17

You analyzed network flows and decided that you want to track any network bandwidth violations by any application that comes from your network source. You want to report on all applications that create traffic and the amount of data (total bytes) from each IP. You want to store the IP address, the application, and the amount of data in the reference data collection.

What type of reference data collection must you create to support this use case?

Options:

A.

Reference map

B.

Reference map of maps

C.

Reference set

D.

Reference map of sets

Question 18

Which two (2) open standards does the QRadar Threat Intelligence app use for feeds?

Options:

A.

TAXII

B.

AQL

C.

STIX

D.

JSON

E.

OSINT

Page: 1 / 6
Total 62 questions