Font size
WorksheetsExam C1000-139 IBM Security QRadar SIEM
Total questions: 37
Worksheet time: 25mins
For a Source IP based offense, which field helps determine relative importance of the targets to the business?
Last Event/Flow
Total number of Events
Duration of the offense
Relative importance of Destination IP(s)
What is a difference between a flow and an event?
A flow occurs at a moment in time while events have a duration from a log source.
An event occur at a moment in time while flows have a duration from the flow source.
An event is a record from a log source, such as a firewall or router device, that describes an action on a network. A flow record provides visibility into layer 7 for applications such as web browsers, NFS, SNMP, Telnet, and FTP.
A flow is a record from a log source, such as a firewall or router device, that describes an action on a network. An event analysis provides visibility into layer 7 for applications such as web browsers, NFS, SNMP, Telnet, and FTP.
At the Offense Summary window, the first row of data shows the level of importance that QRadar assigned to the offense. Which statement is the correct description for Magnitude?
QRadar determines it by the weight that the administrator assigned to the networks and assets.
It indicates the threat that an attack poses in relation to how prepared the destination is for the attack
It indicates the relative importance of the offense, calculated based on the relevance, severity, and credibility ratings
It indicates the integrity of the offense as determined by the credibility rating that is configured in the log source. It increases as multiple sources report the same event.
What information is provided by using the Sharing MITRE-mapping files in Use Case Manager?
Mapping directly to rules
Mapping directly to dependencies
Mapping to the customize template
Mapping to the Use Case Explorer page
Which parameter determines the impact of the offense on the network?
Impact
Severity
Relevance
Credibility
When prioritizing offenses to investigate, what metric is provided on the Offenses tab specifically to help influence which offenses to investigate first?
Severity
Magnitude
Relevance
Credibility
Several counts of the system notification message 38750088 - Performance degradation that were detected in the Event pipeline showed in a report.
In this case, what does the Event collection system do?
Queues events in RAM
Routes data to storage
Bypasses EPS Licensing
Drops events from the pipeline
From which tabs can a QRadar custom rule be created?
Offenses or Admin tabs
Offenses or Log Activity tabs
Log Activity or Network Activity tabs
Offenses, Log Activity or Network Activity tabs
An analyst needs to preserve the data from a search to view later. Which option should they select?
Save Data
Save Search
Save Results
Save Criteria
QRadar uses rules to monitor the events and flows in your network to detect security threats. When the events and flows meet the test criteria that is defined in the rules, an offense is created to show that a security attack or policy breach is suspected. Knowing that an offense occurred is only the first step; identifying the root cause of the offense requires analysis.
These statements refer to what kind of Offense Management?
Offense actions
Offense indexing
Offense retention
Offense investigations
What are the types of reference data collections in QRadar?
Reference set, Reference data and Reference rule
Reference data, Reference table and Reference event
Reference set, Reference map and Reference map of maps
Reference event, Reference map of sets and Reference data
Which two options does a QRadar analyst need to configure in the False Positive window of the QRadar Console to mark an event or flow as False Positive?
Asset and traffic direction
Event or flow property and username
Event or flow property and port number
Event or flow property and traffic direction
Which three (3) statements are capabilities of the Network Hierarchy in QRadar?
Determine and identify local and remote hosts.
Monitor specific logical groups or services in the network, such as marketing, DMZ, or VoIP.
Move users from local to remote network segments.
Generate offenses based on different network zones.
Monitor traffic and profile the behavior of each group and host within the group.
A security analyst using Use Case Manager > Active Rules detected which TOP Rule generating offenses were triggered due to Inbound traffic that was dropped by the Firewall. The company decides that the Rule should only trigger when there are Firewall Permit Events.
Which of these should the analyst implement to meet the above requirement?
Open Rule Wizard add a test condition > and when the context is Local to Local, Local to Remote
Open Rule Wizard add a test condition > and when an event matches any of the following BB:CategoryDefinition: Firewall or ACL Accept
Open Rule Wizard add a test condition > and NOT when an event matches any of the following BB:CategoryDefinition: Firewall or ACL Accept
Open Rule Wizard add a test condition > and when the event category for the event is one of the following Access.Misc Application Action Denied
QRadar rules can utilize reference data to further correlate results. Which term is a valid reference data type?
Reference map
Reference graph
Reference table of sets
Reference table of maps
How are Events that are associated with an offense listed?
Offense Summary window > Destination IPs
Offense Summary window > click Source IPs
Offense Summary window > click Display > Destination IPs
Offense Summary window > click Events from Event/Flow count column
Which are the time criteria in AQL queries?
START, STOP, BETWEEN, LAST
START, STOP, BETWEEN, FIRST
START, STOP, LAST, NOW, PARSEDATETIME
START, BETWEEN, LAST, NOW, PARSEDATETIME
If a security analyst needs to filter Events according to when they occurred, which parameter should be used?
Start Date
Start Time
Storage Time
Log Source Time
Which QRadar app displays time series graphs for queries?
Pulse
Log Management App
Threat Intelligence
Assistant for Watson
What can an analyst use in QRadar to quickly find information about IP addresses and URLs while analyzing an offense or event?
Use the X-Force Exchange lookup plugin.
Export the Event to CSV and upload it to reputation sites.
Verify if the IP address of URL is in any of your reference sets.
Copy the IP address or URL and paste it in any external reputation site.
What does it mean when a custom rule is partially matched in QRadar?
The rule is not fully enabled.
All the tests in the rule were fully matched
Not all the the tests in the rule were fully matched
The AND NOT operator is set incorrectly in the first test.
Which direction value means that an undefined local Source IP accesses an external resource?
R2L
L2L
L2R
R2R
An analyst reviewed an active offense that was many attackers, generating many events in the same category, targeting many systems. Upon further analysis, the analyst determined that the traffic from the attackers is legitimate and should not contribute to the offenses.
Which tuning methodology guideline can the analyst use to tune out this traffic?
Use the False Positive Wizard to tune the specific event.
Use the Log Source Management app to tune the category.
Edit building blocks by using the Custom Rules Editor to tune the category.
Edit the building blocks by using the Custom Rules Editor to tune the specific event.
What file format is supported to perform a bulk load of data into a reference set?
CSV
XML
JSON
TAXII
Which regex statement extracts the DNS host from the cs-host value from the payload?
cs-host=.?www.(.*.?)
cs-host=www.?([^\|]*)\
cs-host=(?:www\.)?([^\|]*)\|(?:http|ftp|tcp|https)\s+(?:www\.)?([^\s]+)
cs-host=(?:www\.)?([^\|]*)\|(?:add|get|query|delete)\s+(?:www\.)?([^\s]+)
An analyst views a dashboard in Pulse, which is not working as expected. Which aggregation type should be selected to ensure the correct configuration for a Pie Chart?
Last
First
Total
Middle
How can an analyst search for all events that include the keyword 'access'?
Go to the Offenses tab and run a quick search with the 'access' keyword.
Go to the Log Activity tab and run a quick search with the 'access' keyword.
Go to the Network Activity tab and run a quick search with the 'access' keyword.
Go to the Log Activity tab and run this AQL: select * from events where eventname like 'access'.
What are the search options available for searching offense data on the By Networks page?
Source IP, Magnitude, VA Risk, and Domain
Network, Magnitude, VA Risk, and Events/Flows
Domain, Destination IP, Magnitude, and Events/Flows
Source IP, Destination IP, Events/Flows, and Magnitude
Analysts can filter searches in QRadar from which three (3) of these locations?
Add Filter dialog
Log Activity toolbar
Admin search pages
Reports search pages
Network Activity toolbar
Which of these procedures duplicates a report from the Reports tab?
Right-click the report to duplicate. Click Duplicate and type a new name for the report.
Click Action > Duplicate Report. Select the report to duplicate and click Finish.
Select the report to duplicate. From the Actions list, click Duplicate and type a new name for the report.
Click Actions, then select the report to duplicate from the pop-up window. Click Duplicate and type a new name for the report.
A QRadar analyst was asked to provide a selection of events for further investigation by somebody who does not have access to the QRadar system.
Which of these approaches provides an accurate copy of the required data in a readable format?
By using the Advanced Search option in the Log Activity tab, run an AQL command: COPY(SELECT * FROM events LAST 2 HOURS) TO 'output_events.csv' WITH CSV.
Log in to the Command Line Interface and use the ACP tool (/opt/qradar/bin/runjava.sh com.q1labs.ariel.io.ACP) with the necessary AQL filters and destination directory.
By using the "Event Export (with AQL)" option in the Log Activity tab, test your query with the Test button. Then, to run the export, click Export to CSV.
By using the Log Activity tab, filter the events until only those that you require are shown. Then, from the Actions list, select Export to CSV > Full Export (All Columns) to download a ZIP file.
Which two (2) file formats are available for exporting offenses?
CSV
XML
TXT
XLSX
What demarcation is added to a custom event property to let you know that this value is held in memory for a set amount of time?
Stored
Indexed
Tabulated
Catalogued
Reports can be organized into groups for efficient utilization. What report groups are available by default in QRadar?
Compliance, Content, Log Sources, Network Management, Security, VoIP, Other
Compliance, Container, Log Sources, Network Management, Security, VoIP, Other
Compliance, Executive, Log Sources, Network Management, Security, VoIP, Other
Compliance, Chart type, Log Sources, Network Management, Security, VoIP, Other
What is the default retention period for an offense after it is closed?
30 days
60 days
90 days
120 days
One of the active offenses that was reviewed by an analyst was one attacker, generating one unique event, targeting one system. Upon further analysis, it was determined that the traffic from this attacker is legitimate and should not contribute to offenses.
Which tuning methodology guideline can be used to tune out this traffic?
Use the False Positive Wizard to tune the specific event.
Use the False Positive Wizard to tune the category.
Edit the building blocks by using the Custom Rules Editor to tune the categories for the host IP address
Edit the building blocks by using the Custom Rules Editor to tune the event.
The Report Wizard provides a step-by-step guide on how to design, schedule, and generate custom reports. Which key elements does the wizard use to generate a report?
Layout, Container, and Content
Content and Chart type
Layout, Chart type, and Event type
Chart type and Container
