Which options assign the “contextA” logs to DomainA and the “contextB” logs to domain B? (Choose two.)
An administrator is about to integrate logs from a custom firewall in a QRadar deployment using syslog. The SIEM has two domains, namely Domain A and Domain B. While reviewing the following sample logs, the administrator notices a “context” keyword: May 14 11:05:01 192.168.1.23 20190514 11:05:00 context=contextA permit 192.168.1.24 source: 10.10.1.15; source_port: 64094; destination: 10.10.13.34; […]
Which file type can be used with the import function in the reference set editor window?
An administrator needs to import a list of HR staff logins into a reference set. Which file type can be used with the import function in the reference set editor window? A. xml B. csv C. xls D. json Reference: https://www.ibm.com/support/knowledgecenter/en/SS42VS_7.3.2/com.ibm.qradar.doc/c_qradar_adm_refdata_ui.html
What is a valid user action to this issue?
An administrator is seeing the following system notification: 38750057 – A protocol source configuration may be stopping events from being collected. What is a valid user action to this issue? A. Re-install the QRadar Console B. Review the /var/log/qradar.log file for more information C. Restart the QRadar Console D. Review the /var/log/error.log file for more […]
Which event routing rule is required to add QRadar Data Store (QDS) capability to a deployment?
Which event routing rule is required to add QRadar Data Store (QDS) capability to a deployment? A. Log Only (exclude Analytics) B. Delete data When storage space is required C. Bypass Correlation D. Delete data immediately after the retention period has expired Reference: https://www.ibm.com/support/knowledgecenter/en/SS42VS_7.3.2/com.ibm.qradar.doc/t_qradar_adm_data_store.html
Which commands can be used to verify the crossover status? (Choose two.)
A QRadar administrator added High Availability (HA) to the Event Processor and needs to verify the crossover link status between the primary and secondary hosts. Which commands can be used to verify the crossover status? (Choose two.) A. /opt/qradar/ha/bin/ha_getstate.sh B. /opt/qradar/ha/bin/getStatus crossover C. /opt/qradar/ha/bin/qradar_nettune.pl crossover status D. /opt/qradar/ha/bin/qradar_nettune.pl linkaggr status E. /opt/qradar/ha/bin/ha cstate F. cat […]
In which QRadar section can the administrator find the asset retention settings?
To comply with specific regulations, an administrator has been requested to increase asset retention to 365 days. In which QRadar section can the administrator find the asset retention settings? A. Admin Tab / Asset Retention B. Assets Tab / Retention settings C. Admin Tab / System settings D. Assets Tab / Asset Retention Reference: https://www.ibm.com/support/knowledgecenter/en/SS42VS_7.3.2/com.ibm.qradar.doc/t_qradar_adm_asset_tuning_ip_retention.html
Which command should the administrator use?
An administrator needs to collect logs from the Command Line Interface (CLI). Which command should the administrator use? A. /opt/bin/qradar/support/get_logs.sh B. /opt/support/get_logs.sh C. /opt/support/qradar/get_logs.sh D. /opt/qradar/support/get_logs.sh Reference: https://www.ibm.com/support/pages/getting-help-what-information-should-be-submitted-qradar-service-request
Which QRadar component is responsible for this process?
An administrator needs to know if a custom rule is being correlated correctly. Which QRadar component is responsible for this process? A. QRadar Event Collector B. QRadar Console C. Magistrate D. QRadar Event Processor Reference: https://www.ibm.com/support/pages/qradar-global-correlation
Which type of data collection must the administrator create?
An administrator needs to import data into QRadar for a specific use case. The data that has been provided to the administrator is stored in records that map a key to a value. Which type of data collection must the administrator create? A. Reference set B. Reference map of sets C. Reference map D. Reference […]
Which IBM FlashSystem A9000 function enables the division of storage system administration tasks into logical
Which IBM FlashSystem A9000 function enables the division of storage system administration tasks into logical domains? A. Storage-based permissions B. Access-based permissions C. Multi-tenant-based permissions D. Role-based permissions Reference: http://www.redbooks.ibm.com/redpapers/pdfs/redp5474.pdf