New Year Special Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: scxmas70

C1000-162 Exam Dumps - IBM Security QRadar SIEM V7.5 Analysis

Go to page:
Question # 25

To verify whether the login ID that was used to log in to QRadar is assigned to a user, create a list with the LoginlD parameter.

This example refers to what kind of reference data collections?

A.

Reference map of maps

B.

Reference login

C.

Reference map

D.

Reference set

Full Access
Question # 26

What is the name of the data collection set used in QRadar that can be populated with lOCs or other external data?

A.

Index set

B.

Reference set

C.

IOC set

D.

Data set

Full Access
Question # 27

After how much time will QRadar mark an Event offense dormant if no new events or flows occur?

A.

2 hours

B.

30 minutes

C.

24 hours

D.

5 minutes

Full Access
Question # 28

What is the effect of toggling the Global/Local option to Global in a Custom Rule?

A.

It allows a rule to compare events & flows in real time.

B.

It allows a rule to analyze the geographic location of the event source.

C.

It allows rules to be tracked by the central processor for detection by any Event Processor.

D.

It allows a rule to inject new events back into the pipeline to affect and update other incoming events.

Full Access
Question # 29

Which type of rule requires a saved search that must be grouped around a common parameter

A.

Flow Rule

B.

Event Rule

C.

Common Rule

D.

Anomaly Rule

Full Access
Question # 30

Which action is performed in Edit Search to create a report from Offense data?

A.

Under Search Parameters, select "Use Offense Data".

B.

In the Select Data Source for report field, select "Offense".

C.

In the Data Source field, type offense.

D.

Under Search Parameters, select "Associated With Offense Equals True".

Full Access
Question # 31

What is an effective method to fix an event that is parsed an determined to be unknown or in the wrong QReader category/

A.

Create a DSM extension to extract the category from the payload

B.

Create a Custom Property to extract the proper Category from the payload

C.

Open the event details, select map event, and assign it to the correct category

D.

Write a Custom Rule, and use Rule Response to send a new event in the proper category

Full Access
Question # 32

Which of these statements regarding the deletion of a generated content report is true?

A.

Only specific reports that were not generated from the report template as well as the report template are deleted.

B.

All reports that were generated from the report template are deleted, but the report template is retained.

C.

All reports that were generated from the report template as well as the report template are deleted.

D.

Only specific reports that were not generated from the report template are deleted, but the report template is retained.

Full Access
Go to page: