Summer Special 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: bestdeal

Free IBM C1000-162 Practice Exam with Questions & Answers | Set: 2

Questions 11

What happens when you select "False Positive" from the right-click menu in the Log Activity tab?

Options:
A.

You can tune out events that are known to be false positives.

B.

You can investigate an IP address or a user name.

C.

Items are filtered that match or do not match the selection.

D.

The selected event is filtered based on the selected parameter in the event.

IBM C1000-162 Premium Access
Questions 12

In QRadar. what do event rules test against?

Options:
A.

The parameters of an offense to trigger more responses

B.

Incoming log source data that is processed in real time by the QRadar Event Processor

C.

Incoming flow data that is processed by the QRadar Flow Processor

D.

Event and flow data

Questions 13

The Use Case Manager app has an option to see MITRE heat map.

Which two (2) factors are responsible for the different colors in MITRE heat map?

Options:
A.

Number of offenses generated

B.

Number of events associated to offense

C.

Number of rules mapped

D.

Level of mapping confidence

E.

Number of log sources associated

Questions 14

The Pulse app contains which two (2) widget chart types?

Options:
A.

Small number chart

B.

Hexadecimal chart

C.

Binary chart

D.

Scatter chart

E.

Big number chart

Questions 15

AQRadar analyst can check the rule coverage of MITRE ATT&CK tactics and techniques by using Use Case Manager.

In the Use Case Manager app, how can a QRadar analyst check the offenses triggered and mapped to MITRE ATT&CK framework?

Options:
A.

By navigating to "CRE Report"

B.

From Offenses tab

C.

By clicking on "Tuning Home"

D.

By navigating to "Detected in timeframe"

Questions 16

An analyst is looking at flow payload. The analyst noted the payload is truncated.

|at default value size for the payload is exceeded where the payload might contain additional information that is not shown in the QRadar surface?

Options:
A.

32 bytes

B.

64 bytes

C.

256 bytes

D.

128 bytes

Questions 17

Which parameters are used to calculate the magnitude rating of an offense?

Options:
A.

Relevance, credibility, time

B.

Severity, relevance, credibility

C.

Relevance, urgency, credibility

D.

Severity, impact, urgency

Questions 18

Which kind of information do log sources provide?

Options:
A.

User login actions

B.

Operating system updates

C.

Flows generated by users

D.

Router configuration exports.

Questions 19

From which tabs can a QRadar custom rule be created?

Options:
A.

Log Activity or Network Action tabs

B.

Offenses or Admin tabs

C.

Offenses, Log Activity, or Network Activity tabs

D.

Offenses. Assets, or Log Action tabs

Questions 20

An analyst wishes to review an event which has a rules test against both event and flow data.

What kind of rule is this?

Options:
A.

Anomaly rules

B.

Threshold rules

C.

Offense rules

D.

Common rules