wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Exam C1000-162: IBM Security QRadar SIEM V7.5 Analysis

Total questions: 40

Worksheet time: 20mins

Name
Class
Date
1.

Which two (2) statements about offense chaining are true?

a)

Offense chaining causes performance issues in IBM QRadar

b)

Offense chaining is based on the offense index field that is specified on the rule

c)

Offense chaining is based on the generated CRE event that is specified in the rule response

d)

A chained offense is identifiable when "preceded by" is in the Descriptions field on the Offense Summary page

e)

If the rule is configured to use the Source IP address as the offense index field, there is only one offense that has that Source IP address, regardless of the offense status

2.

Offense chaining is possible based on which parameter?

a)

Rule type

b)

Rule response

c)

Offense index field

d)

Rule response limiter

3.

In QRadar, where is a list of offenses displaying associated source IP addresses?

a)

Offense Summary > By Source IP

b)

Offense Summary > New Search > Advanced Search

c)

Log Activity > Offense Source Summary > Offenses

d)

Log Activity > Add Filter > Source IP > offense_assigned

4.

A QRadar analyst can export MITRE mappings, which can later be imported into another QRadar deployment. What is another use for the exported MITRE mappings?

a)

Mappings can be a log source configuration backup solution

b)

The export can be a log source group configuration backup solution

c)

MITRE coverage file can be imported into MITRE ATT&CK Navigator

d)

The export contains event details which can be re-run by using the QRadar Experience Center app

5.

Which parameter indicates the reliability of an offense configured in the log source, and is boosted when multiple sources report the same event?

a)

Relevance

b)

Credibility

c)

Event severity

d)

Trustworthiness log

6.

Which two (2) types of information are taken into consideration when calculating the magnitude of an offense?

a)

The number of rules matched to the offense

b)

The number of searches associated with the offense

c)

The CVSS score of the log sources that are involved in the offense

d)

The number of events and flows that are associated with the offense

e)

The categories, severity, relevance, and credibility of the events and flows that contribute to the offense

7.

What are events called when they are classified in the proper log source?

a)

Stored events

b)

Parsed events

c)

Payload events

d)

Unknown events

8.

Which of these statements regarding the network activity tab is true?

a)

You can not display interactive time series charts that represent the records that are matched by a specific time interval search

b)

You can not save configured search criteria so that you can reuse the criteria and use the saved search criteria in other components, such as reports. Saved search criteria does not expire.

c)

You can search, monitor, and investigate flow data in real time. You also can run advanced searches to filter the displayed flows. View flow information to determine how and what network traffic is communicated.

d)

You can search, monitor, and investigate events data in real time. You also can run advanced searches to filter the displayed events. View event information to determine how and what database traffic is communicated.

9.

Which two (2) options are valid to exclude offenses from offense search results?

a)

Single Offenses

b)

Closed Offenses

c)

Active Offenses

d)

Reopen Offenses

e)

Forwarded Offenses

10.

Based on which factors will the magistrate prioritize the offenses and assign the magnitude values?

a)

Relevance, severity, and risk

b)

Severity, relevance, and credibility

c)

Risk, severity, and number of events

d)

Credibility, priority, and number of events

11.

What parameters can an analyst define while configuring a new reference set in Admin Tab in Reference Set Management?

a)

Name, Type, Origin, Response

b)

Rule Name, Response, Value, Origin

c)

Name, Type, Time to Live, Expiration

d)

Category Name, Group, Date Last Seen, Value

12.

How can a QRadar analyst identify the gap between the rules deployed on QRadar and rules needed to cover the security use cases?

a)

Use the QRadar Assistant app

b)

Use the Offense tab to add new rules

c)

Use the IBM X-Force Exchange portal

d)

Use the content extension filters on Use Case Manager app

13.

In QRadar, what do threshold rules test events and flows for?

a)

Test against incoming flow data that is processed by the QRadar Flow Processor

b)

Test events or flows for activity that is greater than or less than a specified range

c)

Test events or flows for volume changes that occur in regular patterns to detect outliers

d)

Test event and flow traffic for changes in short-term events when you are comparing against a longer timeframe

14.

Which type of values can you add to host definition building blocks?

a)

Only IPs

b)

IPs and ports

c)

IPs and reference sets

d)

IPs and building blocks

15.

What must be configured for QRadar to determine flow traffic directions and benefit to from useful building blocks in rules?

a)

Asset database

b)

Automatic updates

c)

Network hierarchy

d)

X-Force Indicators of Compromise

16.

Which report can you run to find rules or building blocks that use performance-intensive tests that are not at the end of the test list?

a)

CRE report

b)

R2R report

c)

Active Rules report

d)

Tuning Finding report

17.

Which type of QRadar rule would you select to test the parameters of an offense to trigger more responses?

a)

Flow rules

b)

Event rules

c)

Common rules

d)

Offense rules

18.

Which two (2) wildcard options are supported for LIKE clauses to retrieve partial string matches from the Ariel database?

a)

%

b)

.*

c)

\w+

d)

_

e)

?

19.

How much time is covered by the Last Interval (auto refresh) option that is selected by an analyst when saving search criteria in the Log Activity tab?

a)

30 seconds

b)

10 seconds

c)

1 minute

d)

5 minutes

20.

To take advantage of lazy search, what must the analyst's profile contain?

a)

Configured permission to access the network tab

b)

Configured domain for the type of data being searched and non-administrator security profile

c)

Configured tenant for the data searched and required resource restriction for the search query

d)

Configured permission precedence to no restrictions and access to all networks and log sources

21.

What would a QRadar analyst call a custom rule when all the tests in the rule are fully matched except a stateful test has failed to reach its threshold value.

a)

Disabled

b)

Partially enabled

c)

Unmatched

d)

Partially matched

22.

An analyst reviewed an active offense that was conducted by many users, generating many events in the same category, targeting many systems. Upon further analysis, the analyst determined that the traffic from the Source IP is a new legitimate Nessus scanner and should not contribute to the offenses. Which tuning methodology guideline can the analyst use to tune out this traffic?

a)

Add the IP to the Exclude from Analytics Reference Set

b)

Add a Routing Rule to drop the events seen from the Source IP

c)

Add the hostname to the BB: VA Scanner Source Host building block

d)

Add the IP address to the BB: VA Scanner Source IP building block

23.

When a QRadar QFlow Collector is combined with QRadar and flow processors, what is the highest OSI layer visible in Network Activity?

a)

Layer 1

b)

Layer 4

c)

Layer 5

d)

Layer 7

24.

What type of custom property should be created when an analyst wants to do calculations on existing numeric event and flow properties?

a)

AQL-based property

b)

Weight-based property

c)

Extraction-based property

d)

Calculation-based property

25.

What is the correct order of the steps for configuring a dashboard item?

a)

Click the Dashboard tab

b)

Configure the chart parameters

c)

On the header of the dashboard item you want to configure, click the Settings icon

d)

Select the dashboard that contains the item you want to customize

26.

Which statement about shared dashboards in the Pulse app is true?

a)

Users can see the default dashboard parameter values

b)

Shared dashboards can be shared again to additional users

c)

The shared dashboard has the privileges of the original user

d)

Any updates that you make to the shared dashboard are seen by other users

27.

What are IBM Security QRadar Pulse workspaces composed of?

a)

Tabs and endpoints

b)

Lists and overviews

c)

Dashboards and widgets

d)

Extensions and time series

28.

Which two (2) of these categories can be used for Ariel Query Language?

a)

Assets

b)

Widget

c)

Network

d)

Keyword

e)

Database

29.

What option must be selected to use a custom property to index an offense?

a)

Enable for use in Rules, Forwarding Profiles, and Search Indexing.

b)

Enable for use in Routing Rules, Event Forwarding, and Flow Indexing.

c)

Ensure the detected event is part of an offense and the property type must be extraction based.

d)

Ensure the detected event is part of an offense and the custom property field type must be alphanumeric.

30.

An analyst copied a query from a Microsoft Word document that the team manager provided. Select Qidname(qid) as ‘Event Name’ From events Last 1 hours When the analyst attempted to run the query an error occurred. What is the cause of the error?

a)

A semi-colon must be used between each line.

b)

Single quotation marks need to be retyped when copied.

c)

Queries copied from outside QRadar must be in one line.

d)

The query is using SQL language syntax and need to be adapted to the updated AQL v.420

31.

Which search parameter performs a Quick Search for the phrase "Firewall Deny"?

a)

Firewall Deny

b)

"Firewall Deny"

c)

Firewall && Deny

d)

\"Firewall Deny\"

32.

What is the procedure for duplicating a report from the Reports tab?

a)

Click Action > Duplicate Report Select the report to duplicate and click Finish

b)

Right-click the report to duplicate Click Duplicate and type a new name for the report

c)

Click Actions, then select the report to duplicate from the pop-up window Click Duplicate and type a new name for the report

d)

Highlight the report to duplicate by left-clicking on it once. From the Actions list, click Duplicate and type a new name for the report

33.

An analyst is investigating rules that are deployed in the QRadar deployment. Where does the analyst determine which rules are most active in generating offenses?

a)

In the Offenses tab, on the All Offenses menu, checking the Flows column

b)

In the Offenses tab, on the My Offenses menu, checking the Events column

c)

In the Offenses tab, on the Rules menu, checking the Offense Count column

d)

In the Offenses tab, on the Rules menu, checking the Events/Flow Count column

34.

What are two (2) reasons for using the QRadar Use Case Manager app?

a)

Communicate insights and analysis about your network

b)

Present data in graph format, so you can quickly assess the vulnerabilities in your network.

c)

Ensure that QRadar is optimally configured to accurately detect threats throughout the attack chain

d)

Expose pre-defined mappings to system rules and helps you map your own custom rules to MITRE ATT&CK tactics and techniques.

e)

Determine the risk profiles of users inside your network and to take action when the app alerts you to threat.

35.

A security analyst needs to filter events according to when QRadar received them. What parameter is used?

a)

Start Time

b)

Storage Time

c)

Recorder Time

d)

Log Source Time

36.

An analyst wants to run a weekly report of the offenses before the required accumulated data is available. Which Reports toolbar option generates this report?

a)

Run Report on All Data

b)

Run Report on Raw Data

c)

Run Report on Dynamic Data

d)

Run Report on Statistical Data

37.

Which two (2) file formats are available for exporting offenses?

a)

CSV

b)

XML

c)

PDF

d)

TXT

e)

XLSX

38.

An analyst enabled the Source Network property index one month ago. What is the reason that the "% of Searches Using Property" column is zero?

a)

The index was deleted.

b)

The index was not saved correctly.

c)

The index is not used in the searches.

d)

Percentages might not roll-up correctly due to rounding error.

39.

How can a QRadar analyst quickly locate results when searching for a specific result from large data sets or long time frames?

a)

Start the searches without any filters.

b)

Add only a payload filter to the search.

c)

Add any filter that does not have [Indexed] appended to it.

d)

Add an indexed filter, such as a Log Source Type, Event Name, or Source IP.

40.

What are the key elements used by the Report wizard in QRadar to create a report?

a)

Font, color, and size

b)

Content, style, and design

c)

Layout, container, and content

d)

Schedule, generate, and export