IBM Security QRadar SIEM V7.5 Analysis C1000-162 Question # 31 Topic 4 Discussion

IBM Security QRadar SIEM V7.5 Analysis C1000-162 Question # 31 Topic 4 Discussion

C1000-162 Exam Topic 4 Question 31 Discussion:
Question #: 31
Topic #: 4

How can an analyst identify the top rules that generated offenses in the previous week and were closed as false positives or tuned?


A.

From Reports > Offenses Report > Weekly reports > False positives reports


B.

Use Case Manager app > Active Rules > Filter Offenses with start date > Closure Reason > Select False-Positive, Tuned


C.

Use Case Manager app > CRE Report > Filter Offenses with the following direction > R2R > Select False-Positive, Tuned.


D.

From Reports > CRE Report > Weekly reports > False positives reports


Get Premium C1000-162 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.