What event information within an offense would provide the analyst with a deep insight as to how it was create
What event information within an offense would provide the analyst with a deep insight as to how it was created? A. Event Category B. Event QID C. Event Payload D. Event Magnitude
An analyst needs to create a new custom dashboard to view dashboard items that meet a particular requirement.
An analyst needs to create a new custom dashboard to view dashboard items that meet a particular requirement. What are the main steps in the process? A. Select New Dashboard and enter unique name, description, add items and save. B. Select New Dashboard and copy name, add description, items and save. C. Request the administrator […]
What is the maximum time period for 3 subsequent events to be coalesced?
What is the maximum time period for 3 subsequent events to be coalesced? A. 10 minutes B. 10 seconds C. 5 minutes D. 60 seconds Explanation: Event coalescing starts after three events have been found with matching properties within a 10 second window. Reference: https://www.ibm.com/support/pages/qradar-how-does-coalescing-work-qradar
An analyst is encountering a large number of false positive results.
An analyst is encountering a large number of false positive results. Legitimate internal network traffic contains valid flows and events which are making it difficult to identify true security incidents. What can the analyst do to reduce these false positive indicators? A. Create X-Force rules to detect false positive events. B. Create an anomaly rule […]
When an analyst sees the system notification “The appliance exceeded the EPS or FPM allocation within the la
When an analyst sees the system notification “The appliance exceeded the EPS or FPM allocation within the last hour”, how does the analyst resolve this issue? (Choose two.) A. Delete the volume of events and flows received in the last hour. B. Adjust the license pool allocations to increase the EPS and FPM capacity for […]
What is the reason for this system notification?
What is the reason for this system notification? A. Deny ntpdate communication on port 423. B. Deny ntpdate communication on port 223. C. Deny ntpdate communication on port 323. D. Deny ntpdate communication on port 123. Explanation: 38750129 – Time synchronization to primary or Console has failed. The managed host cannot synchronize with the console […]
After working with an Offense, an analyst set the Offense as hidden.
After working with an Offense, an analyst set the Offense as hidden. What does the analyst need to do to view the Offense at a later time? A. In the all Offenses view, at the top of the view, select “Show hidden” from the “Select an option” drop-down. B. Search for all Offenses owned by […]
Why would an analyst update host definition building blocks in QRadar?
Why would an analyst update host definition building blocks in QRadar? A. To reduce false positives. B. To narrow a search. C. To stop receiving events from the host. D. To close an Offense Explanation: Building blocks to reduce the number of offenses that are generated by high volume traffic servers. Reference: https://www.ibm.com/docs/en/qsip/7.4?topic=phase-qradar-building-blocks
When ordering these tests in an event rule, which of them is the best test to place at the top of the list for
When ordering these tests in an event rule, which of them is the best test to place at the top of the list for rule performance? A. When the source is [local or remote] B. When the destination is [local or remote] C. When the event(s) were detected by one or more of [these log […]
An analyst wants to analyze the long-term trending of data from a search.
An analyst wants to analyze the long-term trending of data from a search. Which chart would be used to display this data on a dashboard? A. Bar Graph B. Time Series chart C. Pie Chart D. Scatter Chart Explanation: You could use a bar graph if you want to track change over time as long […]