wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Exam C1000-139 IBM Security QRadar SIEM

Total questions: 37

Worksheet time: 25mins

Name
Class
Date
1.

For a Source IP based offense, which field helps determine relative importance of the targets to the business?

a)

Last Event/Flow

b)

Total number of Events

c)

Duration of the offense

d)

Relative importance of Destination IP(s)

2.

What is a difference between a flow and an event?

a)

A flow occurs at a moment in time while events have a duration from a log source.

b)

An event occur at a moment in time while flows have a duration from the flow source.

c)

An event is a record from a log source, such as a firewall or router device, that describes an action on a network. A flow record provides visibility into layer 7 for applications such as web browsers, NFS, SNMP, Telnet, and FTP.

d)

A flow is a record from a log source, such as a firewall or router device, that describes an action on a network. An event analysis provides visibility into layer 7 for applications such as web browsers, NFS, SNMP, Telnet, and FTP.

3.

At the Offense Summary window, the first row of data shows the level of importance that QRadar assigned to the offense. Which statement is the correct description for Magnitude?

a)

QRadar determines it by the weight that the administrator assigned to the networks and assets.

b)

It indicates the threat that an attack poses in relation to how prepared the destination is for the attack

c)

It indicates the relative importance of the offense, calculated based on the relevance, severity, and credibility ratings

d)

It indicates the integrity of the offense as determined by the credibility rating that is configured in the log source. It increases as multiple sources report the same event.

4.

What information is provided by using the Sharing MITRE-mapping files in Use Case Manager?

a)

Mapping directly to rules

b)

Mapping directly to dependencies

c)

Mapping to the customize template

d)

Mapping to the Use Case Explorer page

5.

Which parameter determines the impact of the offense on the network?

a)

Impact

b)

Severity

c)

Relevance

d)

Credibility

6.

When prioritizing offenses to investigate, what metric is provided on the Offenses tab specifically to help influence which offenses to investigate first?

a)

Severity

b)

Magnitude

c)

Relevance

d)

Credibility

7.

Several counts of the system notification message 38750088 - Performance degradation that were detected in the Event pipeline showed in a report.

In this case, what does the Event collection system do?

a)

Queues events in RAM

b)

Routes data to storage

c)

Bypasses EPS Licensing

d)

Drops events from the pipeline

8.

From which tabs can a QRadar custom rule be created?

a)

Offenses or Admin tabs

b)

Offenses or Log Activity tabs

c)

Log Activity or Network Activity tabs

d)

Offenses, Log Activity or Network Activity tabs

9.

An analyst needs to preserve the data from a search to view later. Which option should they select?

a)

Save Data

b)

Save Search

c)

Save Results

d)

Save Criteria

10.

QRadar uses rules to monitor the events and flows in your network to detect security threats. When the events and flows meet the test criteria that is defined in the rules, an offense is created to show that a security attack or policy breach is suspected. Knowing that an offense occurred is only the first step; identifying the root cause of the offense requires analysis.

These statements refer to what kind of Offense Management?

a)

Offense actions

b)

Offense indexing

c)

Offense retention

d)

Offense investigations

11.

What are the types of reference data collections in QRadar?

a)

Reference set, Reference data and Reference rule

b)

Reference data, Reference table and Reference event

c)

Reference set, Reference map and Reference map of maps

d)

Reference event, Reference map of sets and Reference data

12.

Which two options does a QRadar analyst need to configure in the False Positive window of the QRadar Console to mark an event or flow as False Positive?

a)

Asset and traffic direction

b)

Event or flow property and username

c)

Event or flow property and port number

d)

Event or flow property and traffic direction

13.

Which three (3) statements are capabilities of the Network Hierarchy in QRadar?

a)

Determine and identify local and remote hosts.

b)

Monitor specific logical groups or services in the network, such as marketing, DMZ, or VoIP.

c)

Move users from local to remote network segments.

d)

Generate offenses based on different network zones.

e)

Monitor traffic and profile the behavior of each group and host within the group.

14.

A security analyst using Use Case Manager > Active Rules detected which TOP Rule generating offenses were triggered due to Inbound traffic that was dropped by the Firewall. The company decides that the Rule should only trigger when there are Firewall Permit Events.

Which of these should the analyst implement to meet the above requirement?

a)

Open Rule Wizard add a test condition > and when the context is Local to Local, Local to Remote

b)

Open Rule Wizard add a test condition > and when an event matches any of the following BB:CategoryDefinition: Firewall or ACL Accept

c)

Open Rule Wizard add a test condition > and NOT when an event matches any of the following BB:CategoryDefinition: Firewall or ACL Accept

d)

Open Rule Wizard add a test condition > and when the event category for the event is one of the following Access.Misc Application Action Denied

15.

QRadar rules can utilize reference data to further correlate results. Which term is a valid reference data type?

a)

Reference map

b)

Reference graph

c)

Reference table of sets

d)

Reference table of maps

16.

How are Events that are associated with an offense listed?

a)

Offense Summary window > Destination IPs

b)

Offense Summary window > click Source IPs

c)

Offense Summary window > click Display > Destination IPs

d)

Offense Summary window > click Events from Event/Flow count column

17.

Which are the time criteria in AQL queries?

a)

START, STOP, BETWEEN, LAST

b)

START, STOP, BETWEEN, FIRST

c)

START, STOP, LAST, NOW, PARSEDATETIME

d)

START, BETWEEN, LAST, NOW, PARSEDATETIME

18.

If a security analyst needs to filter Events according to when they occurred, which parameter should be used?

a)

Start Date

b)

Start Time

c)

Storage Time

d)

Log Source Time

19.

Which QRadar app displays time series graphs for queries?

a)

Pulse

b)

Log Management App

c)

Threat Intelligence

d)

Assistant for Watson

20.

What can an analyst use in QRadar to quickly find information about IP addresses and URLs while analyzing an offense or event?

a)

Use the X-Force Exchange lookup plugin.

b)

Export the Event to CSV and upload it to reputation sites.

c)

Verify if the IP address of URL is in any of your reference sets.

d)

Copy the IP address or URL and paste it in any external reputation site.

21.

What does it mean when a custom rule is partially matched in QRadar?

a)

The rule is not fully enabled.

b)

All the tests in the rule were fully matched

c)

Not all the the tests in the rule were fully matched

d)

The AND NOT operator is set incorrectly in the first test.

22.

Which direction value means that an undefined local Source IP accesses an external resource?

a)

R2L

b)

L2L

c)

L2R

d)

R2R

23.

An analyst reviewed an active offense that was many attackers, generating many events in the same category, targeting many systems. Upon further analysis, the analyst determined that the traffic from the attackers is legitimate and should not contribute to the offenses.

Which tuning methodology guideline can the analyst use to tune out this traffic?

a)

Use the False Positive Wizard to tune the specific event.

b)

Use the Log Source Management app to tune the category.

c)

Edit building blocks by using the Custom Rules Editor to tune the category.

d)

Edit the building blocks by using the Custom Rules Editor to tune the specific event.

24.

What file format is supported to perform a bulk load of data into a reference set?

a)

CSV

b)

XML

c)

JSON

d)

TAXII

25.

Which regex statement extracts the DNS host from the cs-host value from the payload?

a)

cs-host=.?www.(.*.?)

b)

cs-host=www.?([^\|]*)\

c)

cs-host=(?:www\.)?([^\|]*)\|(?:http|ftp|tcp|https)\s+(?:www\.)?([^\s]+)

d)

cs-host=(?:www\.)?([^\|]*)\|(?:add|get|query|delete)\s+(?:www\.)?([^\s]+)

26.

An analyst views a dashboard in Pulse, which is not working as expected. Which aggregation type should be selected to ensure the correct configuration for a Pie Chart?

a)

Last

b)

First

c)

Total

d)

Middle

27.

How can an analyst search for all events that include the keyword 'access'?

a)

Go to the Offenses tab and run a quick search with the 'access' keyword.

b)

Go to the Log Activity tab and run a quick search with the 'access' keyword.

c)

Go to the Network Activity tab and run a quick search with the 'access' keyword.

d)

Go to the Log Activity tab and run this AQL: select * from events where eventname like 'access'.

28.

What are the search options available for searching offense data on the By Networks page?

a)

Source IP, Magnitude, VA Risk, and Domain

b)

Network, Magnitude, VA Risk, and Events/Flows

c)

Domain, Destination IP, Magnitude, and Events/Flows

d)

Source IP, Destination IP, Events/Flows, and Magnitude

29.

Analysts can filter searches in QRadar from which three (3) of these locations?

a)

Add Filter dialog

b)

Log Activity toolbar

c)

Admin search pages

d)

Reports search pages

e)

Network Activity toolbar

30.

Which of these procedures duplicates a report from the Reports tab?

a)

Right-click the report to duplicate. Click Duplicate and type a new name for the report.

b)

Click Action > Duplicate Report. Select the report to duplicate and click Finish.

c)

Select the report to duplicate. From the Actions list, click Duplicate and type a new name for the report.

d)

Click Actions, then select the report to duplicate from the pop-up window. Click Duplicate and type a new name for the report.

31.

A QRadar analyst was asked to provide a selection of events for further investigation by somebody who does not have access to the QRadar system.

Which of these approaches provides an accurate copy of the required data in a readable format?

a)

By using the Advanced Search option in the Log Activity tab, run an AQL command: COPY(SELECT * FROM events LAST 2 HOURS) TO 'output_events.csv' WITH CSV.

b)

Log in to the Command Line Interface and use the ACP tool (/opt/qradar/bin/runjava.sh com.q1labs.ariel.io.ACP) with the necessary AQL filters and destination directory.

c)

By using the "Event Export (with AQL)" option in the Log Activity tab, test your query with the Test button. Then, to run the export, click Export to CSV.

d)

By using the Log Activity tab, filter the events until only those that you require are shown. Then, from the Actions list, select Export to CSV > Full Export (All Columns) to download a ZIP file.

32.

Which two (2) file formats are available for exporting offenses?

a)

CSV

b)

XML

c)

PDF

d)

TXT

e)

XLSX

33.

What demarcation is added to a custom event property to let you know that this value is held in memory for a set amount of time?

a)

Stored

b)

Indexed

c)

Tabulated

d)

Catalogued

34.

Reports can be organized into groups for efficient utilization. What report groups are available by default in QRadar?

a)

Compliance, Content, Log Sources, Network Management, Security, VoIP, Other

b)

Compliance, Container, Log Sources, Network Management, Security, VoIP, Other

c)

Compliance, Executive, Log Sources, Network Management, Security, VoIP, Other

d)

Compliance, Chart type, Log Sources, Network Management, Security, VoIP, Other

35.

What is the default retention period for an offense after it is closed?

a)

30 days

b)

60 days

c)

90 days

d)

120 days

36.

One of the active offenses that was reviewed by an analyst was one attacker, generating one unique event, targeting one system. Upon further analysis, it was determined that the traffic from this attacker is legitimate and should not contribute to offenses.

Which tuning methodology guideline can be used to tune out this traffic?

a)

Use the False Positive Wizard to tune the specific event.

b)

Use the False Positive Wizard to tune the category.

c)

Edit the building blocks by using the Custom Rules Editor to tune the categories for the host IP address

d)

Edit the building blocks by using the Custom Rules Editor to tune the event.

37.

The Report Wizard provides a step-by-step guide on how to design, schedule, and generate custom reports. Which key elements does the wizard use to generate a report?

a)

Layout, Container, and Content

b)

Content and Chart type

c)

Layout, Chart type, and Event type

d)

Chart type and Container