Summer Special 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: bestdeal

Free IBM C1000-162 Practice Exam with Questions & Answers

Questions 1

Which two (2) options are at the top level when an analyst right-clicks on the Source IP or Destination IP that is associated with an offense at the Offense Summary?

Options:
A.

Information

B.

DNS Lookup

C.

Navigate

D.

WHOIS Lookup

E.

Asset Summary page

IBM C1000-162 Premium Access
Questions 2

What are two characteristics of a SIEM? (Choose two.)

Options:
A.

Log Management

B.

System Deployment

C.

Endpoint Software patching

D.

Enterprise User management

E.

Event Normalization & Correlation

Questions 3

Which parameter is calculated based on the relevance, severity, and credibility of an offense?

Options:
A.

Magnitude rating

B.

Severity age

C.

Impact rating

Questions 4

Where can you view a list of events associated with an offense in the Offense Summary window?

Options:
A.

Destination IPs

B.

Events from Event/Flow count column

C.

Display > Destination IPs

D.

Source IPs

Questions 5

Many offenses are generated and an analyst confirms that they match some kind of vulnerability scanning.

Which building block group needs to be updated to include the source IP of the vulnerability assessment (VA) scanner to reduce the number of offenses that are being generated?

Options:
A.

Host reference

B.

Host definitions

C.

Behavior definition

D.

Device definition

Questions 6

What is the default number of notifications that the System Notification dashboard can display?

Options:
A.

50 notifications

B.

20 notifications

C.

10 notifications

D.

5 notifications

Questions 7

What is the effect of toggling the Global/Local option to Global in a Custom Rule?

Options:
A.

It allows a rule to compare events & flows in real time.

B.

It allows a rule to analyze the geographic location of the event source.

C.

It allows rules to be tracked by the central processor for detection by any Event Processor.

D.

It allows a rule to inject new events back into the pipeline to affect and update other incoming events.

Questions 8

In QRadar. what are building blocks?

Options:
A.

A rule under the rule group "System”

B.

A collection of tests that don't result in a response or an action

C.

A network hierarchy node

D.

An entry in the reference set named "System Entries"

Questions 9

Which two (2) values are valid for the Offense Type field when a search is performed in the My Offenses or All Offenses tabs?

Options:
A.

QID

B.

Any

C.

Risk Score

D.

DDoS

E.

Source IP

Questions 10

Which statement regarding the Assets tab is true?

Options:
A.

The display is populated with all discovered assets in your network.

B.

It displays flow information to determine how and what network traffic is communicated.

C.

It displays connection information to determine how different network devices are connected.

D.

The display is populated with all eliminated and recreated assets in your network.