Pre-Summer Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: validbest

Pass the IBM Security Systems C1000-162 Questions and answers with ValidTests

Exam C1000-162 All Questions
Exam C1000-162 Premium Access

View all detail and faqs for the C1000-162 exam

Viewing page 3 out of 5 pages
Viewing questions 21-30 out of questions
Questions # 21:

Create a list that stores Username as the first key. Source IP as the second key with an assigned cidr data type, and Source Port as the value.

The example above refers to what kind of reference data collections?

Options:

A.

Reference map of sets

B.

Reference store

C.

Reference table

D.

Reference map

Expert Solution
Questions # 22:

Which property types can be used to reduce the overall data volume searched and shorten search time to address searches taking longer than expected?

Options:

A.

Tabled properties

B.

Indexed properties

C.

Stored properties

D.

Common properties

Expert Solution
Questions # 23:

A Security Analyst has noticed that an offense has been marked inactive.

How long had the offense been open since it had last been updated with new events or flows?

Options:

A.

1 day + 30 minutes

B.

5 days + 30 minutes

C.

10 days + 30 minutes

D.

30 days + 30 minutes

Expert Solution
Questions # 24:

Which QRadar component provides the user interface that delivers real-time flow views?

Options:

A.

QRadar Viewer

B.

QRadar Console

C.

QRadar Flow Collector

D.

QRadar Flow Processor

Expert Solution
Questions # 25:

A QRadar analyst wants to limit the time period for which an AOL query is evaluated. Which functions and clauses could be used for this?

Options:

A.

START, BETWEEN. LAST. NOW. PARSEDATETIME

B.

START, STOP. LAST, NOW, PARSEDATETIME

C.

START. STOP. BETWEEN, FIRST

D.

START, STOP. BETWEEN, LAST

Expert Solution
Questions # 26:

New vulnerability scanners are deployed in the company's infrastructure and generate a high number of offenses. Which function in the Use Case Manager app does an analyst use to update the list of vulnerability scanners?

Question # 26

Options:

Expert Solution
Questions # 27:

A new log source was configured to send events to QRadar to help detect a malware outbreak. A security analyst has to create an offense based on properties from this payload but not all the information is parsed correctly.

What is the sequence of steps to ensure that the correct information is pulled from the payload to use in a rule?

Question # 27

Options:

Expert Solution
Questions # 28:

What are two (2) axis types available when creating a time series chart?

Options:

A.

Circular

B.

Crossed

C.

Linear

D.

Log

E.

Flat''

Expert Solution
Questions # 29:

After conducting a thorough analysis, it was discovered that the traffic generated by an attacker targeting one system through many unique events in different categories is legitimate and should not be classified as an offense.

Which tuning methodology guideline can be used to tune out this traffic?

Options:

A.

Edit the Log Source Management app to tune the category

B.

Edit the buildingblocks byusingtheCustomRulesEditor to tune the category

C.

Edit the buildingblocks byusingtheCustomRulesEditor to tune the specific event

D.

Edit the buildingblocks byusingtheCustomRulesEditor to tune the destinationIP address

Expert Solution
Questions # 30:

Offense chaining is based on which field that is specified in the rule?

Options:

A.

Rule action field

B.

Offense response field

C.

Rule response field

D.

Offense index field

Expert Solution
Viewing page 3 out of 5 pages
Viewing questions 21-30 out of questions