What is an example of the use of a flow data that provides more information than an event data?
Answer : D
Explanation:
References:
http://www-01.ibm.com/support/docview.wss?uid=swg21682445
When QRadar processes an event it extracts normalized properties and custom properties.
Which list includes only Normalized properties?
Answer : C
What is a common purpose for looking at flow data?
Answer : D
Where can a user add a note to an offense in the user interface?
Answer : B
Explanation:
References:
IBM Security QRadar SIEM Users Guide. Page: 34
What is the default reason for closing an Offense within QRadar?
Answer : B
Explanation:
References:
https://www.ibm.com/support/knowledgecenter/SS42VS_7.2.1/com.ibm.qradar.doc_7.2.1/t
_qradar_closing_offenses.html?pos=2
What is a primary goal with the use of building blocks?
Answer : B
Which set of information is provided on the asset profile page on the assets tab in addition to ID?
Answer : C
Explanation:
References:
https://www.ibm.com/support/knowledgecenter/SS42VS_7.2.1/com.ibm.qradar.doc_7.2.1/c
_qradar_ug_asset_sum.html
Which three log sources are supported by QRadar? (Choose three.)
Answer : DEF
What is the primary goal of data categorization and normalization in QRadar?
Answer : A
What is accessible from the Offenses Tab but is not used to present a sorted list of offenses?
Answer : A
Given these default options for dashboards on the QRadar Dashboard Tab:
Answer : D
Which QRadar add-on component can generate a list of the unencrypted protocols that can communicate from a DMZ to an internal network?
Answer : A
What is the key difference between Rules and Building Blocks in QRadar?
Answer : A
A Security Analyst found multiple connection attempts from suspicious remote IP addresses to a local host on the DMZ over port 80. After checking related events no successful exploits were detected.
Upon checking international documentation, this activity was part of an expected penetration test which requires no immediate investigation.
How can the Security Analyst ensure results of the penetration test are retained?
Answer : B
Explanation:
References:
http://www.ibm.com/support/knowledgecenter/SSKMKU/com.ibm.qradar.doc/c_qradar_Off
_Retention.html
Which type of tests are recommended to be placed first in a rule to increase efficiency?
Answer : B
Have any questions or issues ? Please dont hesitate to contact us