Pass the IBM IBM Security Systems C1000-156 Questions and answers with CertsForce

Viewing page 2 out of 2 pages
Viewing questions 11-20 out of questions
Questions # 11:

What is the default day and time setting for when QRadar generates weekly reports?

Options:

A.

Sunday 01:00 AM


B.

Monday 02:00 AM


C.

Sunday 02:00 AM


D.

Monday 01:00 AM


Expert Solution
Questions # 12:

A ORadar administrator needs to upgrade the system to patch a vulnerability. In what order does the administrator upgrade the managed hosts?

Options:

A.

Any order


B.

Console followed by remaining hosts


C.

Flow Processor followed by remaining hosts


D.

Event Processor followed by remaining hosts


Expert Solution
Questions # 13:

Which is a benefit of a lazy search?

Options:

A.

Getting results that are limited to a specific range


B.

Providing every result no matter the quantity of the search results


C.

Finding lOCs quickly


D.

Searching across domains for any configured user


Expert Solution
Questions # 14:

When configuring a log source, which protocols are used when receiving data into the event ingress component?

Options:

A.

SFTR HTTP Receiver, SNMP


B.

Syslog, HTTP Receiver, SNMP


C.

Syslog, FTP Receiver, SNMP


D.

Syslog, HTTP Receiver, JDBC


Expert Solution
Questions # 15:

Which three (3) resource restriction types are available in QRadar?

Options:

A.

Role-based restrictions


B.

Tenant-based restrictions


C.

User-based restrictions


D.

Service-based restrictions


E.

Event-based restrictions


F.

Domain-based restrictions


Expert Solution
Questions # 16:

Which two (2) data sources can be assigned to a domain in the Domain Management function?

Options:

A.

Users


B.

Rules


C.

Flow collectors


D.

Log sources


E.

X-Force Integration Feed


Expert Solution
Questions # 17:

An administrator is reviewing the system notifications and discovers this error:

Insufficient disk space to complete data export request.

The Export Directory property in the System Settings has the default configuration.

Which disk partition does the administrator need to check?

Options:

A.

/store/ariel/events/exports


B.

/var/log/exports


C.

/storetmp/exports


D.

/store/exports


Expert Solution
Questions # 18:

An administrator is evaluating domain criteria based on an event. The result of a regular expression that was defined in a custom property does not match a domain mapping, and the event was automatically assigned to the default domain.

What is the order of precedence if the event does not match the domain definition for custom properties?

Options:

A.

Log source. Log source group, App Hosts


B.

Log source, Log source group, Event collector or data gateway, DDS


C.

DLC. Log source, Log source group, Event collector or data gateway


D.

DLS, Log source, Event collector or data gateway. Log source group


Expert Solution
Viewing page 2 out of 2 pages
Viewing questions 11-20 out of questions