Pre-Summer Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: validbest

Pass the IBM Security Systems C1000-156 Questions and answers with ValidTests

Exam C1000-156 All Questions
Exam C1000-156 Premium Access

View all detail and faqs for the C1000-156 exam

Viewing page 2 out of 2 pages
Viewing questions 11-20 out of questions
Questions # 11:

You want to use a quick filter search to look for certain elements:

. 10.100.100.*

• BlueCoat

• TCP_REFRESH_MIS

Which string provides the correct results?

Options:

A.

(10.100.100.- Bluecoat TCP_REFRESH_MIS)

B.

10.100.100.*%Bluecoat%TCP_REFRESH_MIS

C.

"10.100.100.*%AND%Bluecoat%AND%TCP_REFRESH_MIS"

D.

(10.100.100/ AND Bluecoat AND TCP_REFRESH_MIS)

Expert Solution
Questions # 12:

An administrator is evaluating domain criteria based on an event. The result of a regular expression that was defined in a custom property does not match a domain mapping, and the event was automatically assigned to the default domain.

What is the order of precedence if the event does not match the domain definition for custom properties?

Options:

A.

Log source. Log source group, App Hosts

B.

Log source, Log source group, Event collector or data gateway, DDS

C.

DLC. Log source, Log source group, Event collector or data gateway

D.

DLS, Log source, Event collector or data gateway. Log source group

Expert Solution
Questions # 13:

In which QRadar section can the administrator view the license giveback rate?

Options:

A.

Admin tab > system settings

B.

Log Activity tab > AQL query in the Advanced Search "select LicenseGiveback from license"

C.

Admin tab > License pool management

D.

Log Activity tab by searching for the term "giveback" in the Quick Filter

Expert Solution
Questions # 14:

When restoring backups of your apps in a QRadar environment, what information is restored?

Options:

A.

The last known good version of your apps configuration, your application data, and any apps that were configured on an App Host are restored.

B.

The applications that are installed on the Console are restored, and any applications that are installed on an AppHost must be backed up separately.

C.

The apps configuration, the console configuration, and app data are restored.

D.

The apps configuration and app data are restored.

Expert Solution
Questions # 15:

When creating an identity exclusion search, what time range do you select?

Options:

A.

Previous 7 days

B.

Real time (streaming)

C.

Previous 30 days

D.

Previous 5 minutes

Expert Solution
Questions # 16:

In a single domain QRadar deployment, which IP addresses are considered local?

Options:

A.

Any private IP address

B.

Any public IP address

C.

Any IP address that is defined in the network hierarchy

D.

Any IP address that is not defined in the network hierarchy

Expert Solution
Questions # 17:

How can you configure a log source to provide events to different domains?

Options:

A.

Create a saved search on the Network Activity tab to view events in specific domains.

B.

Use the Assistant app to update the domain information for the log source.

C.

Use custom properties to assign events from a single log source to different domains.

D.

Use the Use Case Manager app to update building blocks to support multi domain events.

Expert Solution
Questions # 18:

An administrator is reviewing the system notifications and discovers this error:

Insufficient disk space to complete data export request.

The Export Directory property in the System Settings has the default configuration.

Which disk partition does the administrator need to check?

Options:

A.

/store/ariel/events/exports

B.

/var/log/exports

C.

/storetmp/exports

D.

/store/exports

Expert Solution
Viewing page 2 out of 2 pages
Viewing questions 11-20 out of questions