Pass the IBM IBM Security Systems C1000-162 Questions and answers with CertsForce

Viewing page 4 out of 5 pages
Viewing questions 31-40 out of questions
Questions # 31:

How can an analyst identify the top rules that generated offenses in the previous week and were closed as false positives or tuned?

Options:

A.

From Reports > Offenses Report > Weekly reports > False positives reports


B.

Use Case Manager app > Active Rules > Filter Offenses with start date > Closure Reason > Select False-Positive, Tuned


C.

Use Case Manager app > CRE Report > Filter Offenses with the following direction > R2R > Select False-Positive, Tuned.


D.

From Reports > CRE Report > Weekly reports > False positives reports


Expert Solution
Questions # 32:

Many offenses are generated and an analyst confirms that they match some kind of vulnerability scanning.

Which building block group needs to be updated to include the source IP of the vulnerability assessment (VA) scanner to reduce the number of offenses that are being generated?

Options:

A.

Host reference


B.

Host definitions


C.

Behavior definition


D.

Device definition


Expert Solution
Questions # 33:

A QRadar analyst develops an advanced search on the Log Activity tab and presses the shortcut "Ctrl + Space" in the search field. What information is displayed?

Options:

A.

The full list of AQL databases, functions and fields (properties) is displayed.


B.

The full list of AQL tables and relationships from a database is displayed.


C.

The full list of AOL functions, fields (properties), and keywords is displayed.


D.

The full list of AQL functions, tables, and views from a database is displayed.


Expert Solution
Questions # 34:

a selection of events for further investigation to somebody who does not have access to the QRadar system.

Which of these approaches provides an accurate copy of the required data in a readable format?

Options:

A.

Log in to the Command Line Interface and use the ACP tool (/opt/qradar/bin/runjava.sh com.qllabs .ariel. Io.acp) with the necessary AQLfilters and destination directory.


B.

Use the Advanced Search option in the Log Activity tab, run an AQL command: copy (select * from events last 2 hours) to ’output_events.csv’ WITH CSV.


C.

Use the "Event Export (with AQL)" option in the Log Activity tab, test your query with the Test button. Then, to run the export, click Export to CSV.


D.

Use the Log Activity tab, filter the events until only those that you require are shown. Then, from the Actions list, select Export to CSV > Full Export (All Columns).


Expert Solution
Questions # 35:

New vulnerability scanners are deployed in the company's infrastructure and generate a high number of offenses. Which function in the Use Case Manager app does an analyst use to update the list of vulnerability scanners?

Question # 35


Expert Solution
Questions # 36:

Which parameter is calculated based on the relevance, severity, and credibility of an offense?

Options:

A.

Magnitude rating


B.

Severity age


C.

Impact rating


Expert Solution
Questions # 37:

A Security Analyst has noticed that an offense has been marked inactive.

How long had the offense been open since it had last been updated with new events or flows?

Options:

A.

1 day + 30 minutes


B.

5 days + 30 minutes


C.

10 days + 30 minutes


D.

30 days + 30 minutes


Expert Solution
Questions # 38:

Which two high level Event Categories are used by QRadar? (Choose two.)

Options:

A.

Policy


B.

Direction


C.

Localization


D.

Justification


E.

Authentication


Expert Solution
Questions # 39:

Which two (2) components are necessary for generating a report using the QRadar Report wizard?

Options:

A.

Saved search


B.

Dynamic search


C.

Layout


D.

Quick search


E.

Email address


Expert Solution
Questions # 40:

Which two (2) options are at the top level when an analyst right-clicks on the Source IP or Destination IP that is associated with an offense at the Offense Summary?

Options:

A.

Information


B.

DNS Lookup


C.

Navigate


D.

WHOIS Lookup


E.

Asset Summary page


Expert Solution
Viewing page 4 out of 5 pages
Viewing questions 31-40 out of questions