IBM Security QRadar SIEM V7.5 Analysis C1000-162 Question # 24 Topic 3 Discussion

IBM Security QRadar SIEM V7.5 Analysis C1000-162 Question # 24 Topic 3 Discussion

C1000-162 Exam Topic 3 Question 24 Discussion:
Question #: 24
Topic #: 3

An analyst wishes to review an event which has a rules test against both event and flow data.

What kind of rule is this?


A.

Anomaly rules


B.

Threshold rules


C.

Offense rules


D.

Common rules


Get Premium C1000-162 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.