Pass the IBM IBM Security Systems C1000-162 Questions and answers with CertsForce

Viewing page 2 out of 5 pages
Viewing questions 11-20 out of questions
Questions # 11:

On the Log Activity tab in QRadar. what are the options available when right-clicking an IP address of an event to access more event filter information?

Options:

A.

Filter on. False Positive. More Options. Quick Filter


B.

Filter out, False Negative, More Options, Quick Filter


C.

Filter off, True Positive, Less Options, Quick Search


D.

Filter in, True Negative, Less Options. Quick Search


Expert Solution
Questions # 12:

What right-click menu option can an analyst use to find information about an IP or URL?

Options:

A.

IBM Advanced Threat lookup


B.

Watson Advisor Al IOC Lookup


C.

QRadar Anomaly lookup


D.

X-Force Exchange Lookup


Expert Solution
Questions # 13:

Which statement regarding saved event search criteria is true?

Options:

A.

Saved search criteria expires


B.

Saved search criteria does not expire


C.

Saved search criteria cannot be reused


D.

You cannot define the name of the saved search criteria


Expert Solution
Questions # 14:

From which tabs can a QRadar custom rule be created?

Options:

A.

Log Activity or Network Action tabs


B.

Offenses or Admin tabs


C.

Offenses, Log Activity, or Network Activity tabs


D.

Offenses. Assets, or Log Action tabs


Expert Solution
Questions # 15:

What process is used to perform an IP address X-Force Exchange Lookup in QRadar?

Options:

A.

Offense summary tab > right-click IP address > Plugin Option > X-Force Exchange Lookup


B.

Copy the IP address and go to X-Force Exchange to perform the lookup


C.

Run Autoupdate


D.

Run a query on maxmind db


Expert Solution
Questions # 16:

A Security Analyst was asked to search for an offense on a specific day. The requester was not sore of the time frame, but had Source Host information to use as well as networks involved, Destination IP and username.

Which fitters can the Security Analyst use to search for the information requested?

Options:

A.

Offense ID, Source IP, Username


B.

Magnitude, Source IP, Destination IP


C.

Description, Destination IP. Host Name


D.

Specific Interval, Username, Destination IP


Expert Solution
Questions # 17:

Which two (2) options are at the top level when an analyst right-clicks on the Source IP or Destination IP that is associated with an offense at the Offense Summary?

Options:

A.

Information


B.

Asset Summary page


C.

Navigate


D.

WHOIS Lookup


E.

DNS Lookup


Expert Solution
Questions # 18:

Events can be exported from the QRadar Log Activity tab in which file formats?

Options:

A.

JSON. XML, and CSV


B.

XLS and CSV


C.

JSON and XML


D.

XML and CSV


Expert Solution
Questions # 19:

Which of these statements regarding the deletion of a generated content report is true?

Options:

A.

Only specific reports that were not generated from the report template as well as the report template are deleted.


B.

All reports that were generated from the report template are deleted, but the report template is retained.


C.

All reports that were generated from the report template as well as the report template are deleted.


D.

Only specific reports that were not generated from the report template are deleted, but the report template is retained.


Expert Solution
Questions # 20:

In QRadar. what do event rules test against?

Options:

A.

The parameters of an offense to trigger more responses


B.

Incoming log source data that is processed in real time by the QRadar Event Processor


C.

Incoming flow data that is processed by the QRadar Flow Processor


D.

Event and flow data


Expert Solution
Viewing page 2 out of 5 pages
Viewing questions 11-20 out of questions