When using the Dynamic Search window on the Admin tab, which two (2) data sources are available?
What is the benefit of using default indexed properties for searching in QRadar?
How can an analyst identify the top rules that generated offenses in the previous week and were closed as false positives or tuned?
How can an analyst search for all events that include the keyword "access"?
A QRadar analyst is using the Log Activity screen to investigate the events that triggered an offense.
How can the analyst differentiate events that are associated with an offense?
A QRadar analyst is investigating the events of an offense. For a particular event on the list, the analyst wants to know which rules were fully ditched for the event.
where can the analyst check to see if the event has any fully matched rules?
What process is used to perform an IP address X-Force Exchange Lookup in QRadar?
Which reference set data element attribute governs who can view its value?
Which type of rule should you use to test events or (lows for activities that are greater than or less than a specified range?
A QRadar analyst wants predefined searches, reports, custom rules, and custom properties for HIPAA compliance.
Which option does the QRadar analyst use to look for HIPAA compliance on QRadar?
Which two (2) statements regarding indexed custom event properties are true?
When investigating an offense, how does one find the number of flows or events associated with it?
The Use Case Manager app has an option to see MITRE heat map.
Which two (2) factors are responsible for the different colors in MITRE heat map?
Several systems were initially reviewed as active offenses, but further analysis revealed that the traffic generated by these source systems is legitimate and should not contribute to offenses.
How can the activity be fine-tuned when multiple source systems are found to be generating the same event and targeting several systems?
An analyst runs a search with correct AQL. but no errors or results are shown.
What is one reason this could occur?
Which two (2) options are at the top level when an analyst right-clicks on the Source IP or Destination IP that is associated with an offense at the Offense Summary?
To verify whether the login ID that was used to log in to QRadar is assigned to a user, create a list with the LoginlD parameter.
This example refers to what kind of reference data collections?
What is the name of the data collection set used in QRadar that can be populated with lOCs or other external data?
After how much time will QRadar mark an Event offense dormant if no new events or flows occur?
What is the effect of toggling the Global/Local option to Global in a Custom Rule?
Which type of rule requires a saved search that must be grouped around a common parameter
Which action is performed in Edit Search to create a report from Offense data?
What is an effective method to fix an event that is parsed an determined to be unknown or in the wrong QReader category/
Which of these statements regarding the deletion of a generated content report is true?
To test for authorized access to a patent, create a list that uses a custom event property for Patent id as the key, and the username parameter as the value. Data is stored in records that map a key to multiple values and every key is unique. Use this list to populate a list of authorized users.
The example above refers to what kind of reference data collections?
A Security Analyst was asked to search for an offense on a specific day. The requester was not sore of the time frame, but had Source Host information to use as well as networks involved, Destination IP and username.
Which fitters can the Security Analyst use to search for the information requested?
Which two (2) are valid options available for configuring the frequency of report execution in the QRadar Report wizard?
A QRadar analyst would like to search for events that have fully matched rules which triggered offenses.
What parameter and value should the analyst add as filter in the event search?
How do events appear in QRadar if there was an error in the JSON parser for a new log source to which a custom log source extension was created?
Which two (2) options are at the top level when an analyst right-clicks on the Source IP or Destination IP that is associated with an offense at the Offense Summary?
On the Reports tab in QRadar. what does the message "Queued (position in the queue)" indicate when generating a report?
New vulnerability scanners are deployed in the company's infrastructure and generate a high number of offenses. Which function in the Use Case Manager app does an analyst use to update the list of vulnerability scanners?