Font size
WorksheetsExam C1000-162: IBM Security QRadar SIEM V7.5 Analysis
Total questions: 40
Worksheet time: 20mins
Which two (2) statements about offense chaining are true?
Offense chaining causes performance issues in IBM QRadar
Offense chaining is based on the offense index field that is specified on the rule
Offense chaining is based on the generated CRE event that is specified in the rule response
A chained offense is identifiable when "preceded by" is in the Descriptions field on the Offense Summary page
If the rule is configured to use the Source IP address as the offense index field, there is only one offense that has that Source IP address, regardless of the offense status
Offense chaining is possible based on which parameter?
Rule type
Rule response
Offense index field
Rule response limiter
In QRadar, where is a list of offenses displaying associated source IP addresses?
Offense Summary > By Source IP
Offense Summary > New Search > Advanced Search
Log Activity > Offense Source Summary > Offenses
Log Activity > Add Filter > Source IP > offense_assigned
A QRadar analyst can export MITRE mappings, which can later be imported into another QRadar deployment. What is another use for the exported MITRE mappings?
Mappings can be a log source configuration backup solution
The export can be a log source group configuration backup solution
MITRE coverage file can be imported into MITRE ATT&CK Navigator
The export contains event details which can be re-run by using the QRadar Experience Center app
Which parameter indicates the reliability of an offense configured in the log source, and is boosted when multiple sources report the same event?
Relevance
Credibility
Event severity
Trustworthiness log
Which two (2) types of information are taken into consideration when calculating the magnitude of an offense?
The number of rules matched to the offense
The number of searches associated with the offense
The CVSS score of the log sources that are involved in the offense
The number of events and flows that are associated with the offense
The categories, severity, relevance, and credibility of the events and flows that contribute to the offense
What are events called when they are classified in the proper log source?
Stored events
Parsed events
Payload events
Unknown events
Which of these statements regarding the network activity tab is true?
You can not display interactive time series charts that represent the records that are matched by a specific time interval search
You can not save configured search criteria so that you can reuse the criteria and use the saved search criteria in other components, such as reports. Saved search criteria does not expire.
You can search, monitor, and investigate flow data in real time. You also can run advanced searches to filter the displayed flows. View flow information to determine how and what network traffic is communicated.
You can search, monitor, and investigate events data in real time. You also can run advanced searches to filter the displayed events. View event information to determine how and what database traffic is communicated.
Which two (2) options are valid to exclude offenses from offense search results?
Single Offenses
Closed Offenses
Active Offenses
Reopen Offenses
Forwarded Offenses
Based on which factors will the magistrate prioritize the offenses and assign the magnitude values?
Relevance, severity, and risk
Severity, relevance, and credibility
Risk, severity, and number of events
Credibility, priority, and number of events
What parameters can an analyst define while configuring a new reference set in Admin Tab in Reference Set Management?
Name, Type, Origin, Response
Rule Name, Response, Value, Origin
Name, Type, Time to Live, Expiration
Category Name, Group, Date Last Seen, Value
How can a QRadar analyst identify the gap between the rules deployed on QRadar and rules needed to cover the security use cases?
Use the QRadar Assistant app
Use the Offense tab to add new rules
Use the IBM X-Force Exchange portal
Use the content extension filters on Use Case Manager app
In QRadar, what do threshold rules test events and flows for?
Test against incoming flow data that is processed by the QRadar Flow Processor
Test events or flows for activity that is greater than or less than a specified range
Test events or flows for volume changes that occur in regular patterns to detect outliers
Test event and flow traffic for changes in short-term events when you are comparing against a longer timeframe
Which type of values can you add to host definition building blocks?
Only IPs
IPs and ports
IPs and reference sets
IPs and building blocks
What must be configured for QRadar to determine flow traffic directions and benefit to from useful building blocks in rules?
Asset database
Automatic updates
Network hierarchy
X-Force Indicators of Compromise
Which report can you run to find rules or building blocks that use performance-intensive tests that are not at the end of the test list?
CRE report
R2R report
Active Rules report
Tuning Finding report
Which type of QRadar rule would you select to test the parameters of an offense to trigger more responses?
Flow rules
Event rules
Common rules
Offense rules
Which two (2) wildcard options are supported for LIKE clauses to retrieve partial string matches from the Ariel database?
%
.*
\w+
_
?
How much time is covered by the Last Interval (auto refresh) option that is selected by an analyst when saving search criteria in the Log Activity tab?
30 seconds
10 seconds
1 minute
5 minutes
To take advantage of lazy search, what must the analyst's profile contain?
Configured permission to access the network tab
Configured domain for the type of data being searched and non-administrator security profile
Configured tenant for the data searched and required resource restriction for the search query
Configured permission precedence to no restrictions and access to all networks and log sources
What would a QRadar analyst call a custom rule when all the tests in the rule are fully matched except a stateful test has failed to reach its threshold value.
Disabled
Partially enabled
Unmatched
Partially matched
An analyst reviewed an active offense that was conducted by many users, generating many events in the same category, targeting many systems. Upon further analysis, the analyst determined that the traffic from the Source IP is a new legitimate Nessus scanner and should not contribute to the offenses. Which tuning methodology guideline can the analyst use to tune out this traffic?
Add the IP to the Exclude from Analytics Reference Set
Add a Routing Rule to drop the events seen from the Source IP
Add the hostname to the BB: VA Scanner Source Host building block
Add the IP address to the BB: VA Scanner Source IP building block
When a QRadar QFlow Collector is combined with QRadar and flow processors, what is the highest OSI layer visible in Network Activity?
Layer 1
Layer 4
Layer 5
Layer 7
What type of custom property should be created when an analyst wants to do calculations on existing numeric event and flow properties?
AQL-based property
Weight-based property
Extraction-based property
Calculation-based property
What is the correct order of the steps for configuring a dashboard item?
Click the Dashboard tab
Configure the chart parameters
On the header of the dashboard item you want to configure, click the Settings icon
Select the dashboard that contains the item you want to customize
Which statement about shared dashboards in the Pulse app is true?
Users can see the default dashboard parameter values
Shared dashboards can be shared again to additional users
The shared dashboard has the privileges of the original user
Any updates that you make to the shared dashboard are seen by other users
What are IBM Security QRadar Pulse workspaces composed of?
Tabs and endpoints
Lists and overviews
Dashboards and widgets
Extensions and time series
Which two (2) of these categories can be used for Ariel Query Language?
Assets
Widget
Network
Keyword
Database
What option must be selected to use a custom property to index an offense?
Enable for use in Rules, Forwarding Profiles, and Search Indexing.
Enable for use in Routing Rules, Event Forwarding, and Flow Indexing.
Ensure the detected event is part of an offense and the property type must be extraction based.
Ensure the detected event is part of an offense and the custom property field type must be alphanumeric.
An analyst copied a query from a Microsoft Word document that the team manager provided. Select Qidname(qid) as ‘Event Name’ From events Last 1 hours When the analyst attempted to run the query an error occurred. What is the cause of the error?
A semi-colon must be used between each line.
Single quotation marks need to be retyped when copied.
Queries copied from outside QRadar must be in one line.
The query is using SQL language syntax and need to be adapted to the updated AQL v.420
Which search parameter performs a Quick Search for the phrase "Firewall Deny"?
Firewall Deny
"Firewall Deny"
Firewall && Deny
\"Firewall Deny\"
What is the procedure for duplicating a report from the Reports tab?
Click Action > Duplicate Report Select the report to duplicate and click Finish
Right-click the report to duplicate Click Duplicate and type a new name for the report
Click Actions, then select the report to duplicate from the pop-up window Click Duplicate and type a new name for the report
Highlight the report to duplicate by left-clicking on it once. From the Actions list, click Duplicate and type a new name for the report
An analyst is investigating rules that are deployed in the QRadar deployment. Where does the analyst determine which rules are most active in generating offenses?
In the Offenses tab, on the All Offenses menu, checking the Flows column
In the Offenses tab, on the My Offenses menu, checking the Events column
In the Offenses tab, on the Rules menu, checking the Offense Count column
In the Offenses tab, on the Rules menu, checking the Events/Flow Count column
What are two (2) reasons for using the QRadar Use Case Manager app?
Communicate insights and analysis about your network
Present data in graph format, so you can quickly assess the vulnerabilities in your network.
Ensure that QRadar is optimally configured to accurately detect threats throughout the attack chain
Expose pre-defined mappings to system rules and helps you map your own custom rules to MITRE ATT&CK tactics and techniques.
Determine the risk profiles of users inside your network and to take action when the app alerts you to threat.
A security analyst needs to filter events according to when QRadar received them. What parameter is used?
Start Time
Storage Time
Recorder Time
Log Source Time
An analyst wants to run a weekly report of the offenses before the required accumulated data is available. Which Reports toolbar option generates this report?
Run Report on All Data
Run Report on Raw Data
Run Report on Dynamic Data
Run Report on Statistical Data
Which two (2) file formats are available for exporting offenses?
CSV
XML
TXT
XLSX
An analyst enabled the Source Network property index one month ago. What is the reason that the "% of Searches Using Property" column is zero?
The index was deleted.
The index was not saved correctly.
The index is not used in the searches.
Percentages might not roll-up correctly due to rounding error.
How can a QRadar analyst quickly locate results when searching for a specific result from large data sets or long time frames?
Start the searches without any filters.
Add only a payload filter to the search.
Add any filter that does not have [Indexed] appended to it.
Add an indexed filter, such as a Log Source Type, Event Name, or Source IP.
What are the key elements used by the Report wizard in QRadar to create a report?
Font, color, and size
Content, style, and design
Layout, container, and content
Schedule, generate, and export
