C1000-162 IBM Security QRadar SIEM V7.5 Analysis Questions and Answers
Which are two (2) types of charts that can be configured in QRadar to display data on the dashboard?
azureindia.starttest.com says
Which parameter should be used if a security analyst needs to filter events based on the time when they occurred on the endpoints?
After conducting a thorough analysis, it was discovered that the traffic generated by an attacker targeting one system through many unique events in different categories is legitimate and should not be classified as an offense.
Which tuning methodology guideline can be used to tune out this traffic?
A Security Analyst was asked to search for an offense on a specific day. The requester was not sore of the time frame, but had Source Host information to use as well as networks involved, Destination IP and username.
Which fitters can the Security Analyst use to search for the information requested?
Which type of rule requires a saved search that must be grouped around a common parameter
Which log source and protocol combination delivers events to QRadar in real time?
From the Offense Summary window, how is the list of rules that contributed to a chained offense identified?
Which two (2) aggregation types ate available for the pie chart in the Pulse app?
What type of building blocks would you use to categorize assets and server types into CIDR/IP ranges to exclude or include entire asset categories in rule tests?
An analyst wishes to review an event which has a rules test against both event and flow data.
What kind of rule is this?
How can an analyst identify the top rules that generated offenses in the previous week and were closed as false positives or tuned?
What does this example of a YARA rule represent?
rule ibm_forensics : qradar
meta:
description = “Complex Yara rule.“
strings:
Shexl = {4D 2B 68 00 ?? 14 99 F9 B? 00 30 Cl 8D}
Sstrl = " IBM Security! "
condition:
Shexl and (#strl > 3)
An analyst runs a search with correct AQL. but no errors or results are shown.
What is one reason this could occur?
How do events appear in QRadar if there was an error in the JSON parser for a new log source to which a custom log source extension was created?
Which condition is required to display the " Include in my Dashboard " parameter in the Log Activity tab while saving a search?
Which two (2) of these custom property expression types are supported in QRadar?
After analyzing an active offense where many source systems were observed connecting to a specific destination via local-to-local LDAP traffic, an ^lyst discovered that the targeted system is a legitimate LDAP server within the organization.
x avoid confusion in future analyses, how can this type of traffic to the target system be flagged as expected and be excluded from further offense ation?
Which IBM X-Force Exchange feature could be used to query QRadar to see if any of the lOCs were detected for COVID-19 activities?
The Use Case Manager app has an option to see MITRE heat map.
Which two (2) factors are responsible for the different colors in MITRE heat map?
What type of rules will test events or flows for volume changes that occur in regular patterns to detect outliers?
A QRadar analyst develops an advanced search on the Log Activity tab and presses the shortcut " Ctrl + Space " in the search field. What information is displayed?
A QRadar analyst is investigating the events of an offense. For a particular event on the list, the analyst wants to know which rules were fully ditched for the event.
where can the analyst check to see if the event has any fully matched rules?
Which parameter is calculated based on the relevance, severity, and credibility of an offense?
What feature in QRadar uses existing asset profile data so administrators can define unknown server types and assign them to a server definition in building blocks and in the network hierarchy?
When you create a report, you must choose a chart type for each chart that is included in the report.
Which two (2) chart types can you include in a report?
How can adding indexed properties to QRadar improve the efficiency of searches?
Which two (2) options are at the top level when an analyst right-clicks on the Source IP or Destination IP that is associated with an offense at the Offense Summary?
QRadar analysts can download different types of content extensions from the IBM X-Force Exchange portal. Which two (2) types of content extensions are supported by QRadar?
