최신 IBM Security C1000-163 무료샘플문제:
1. QRadar uses rules to monitor the events and flows in your network to detect security threats. When the events and flows meet the test criteria that is defined in the rules, an offense is created to show that a security attack or policy breach is suspected. Knowing that an offense occurred is only the first step; identifying the root cause of the offense requires analysis.
These statements refer to what kind of Offense Management?
A) Offense indexing
B) Offense investigations
C) Offense actions
D) Offense retention
2. In a multidomain and multitenant environment, how is event visibility provided to users?
A) An event is allocated to a tenant, and a tenant is referenced in the security profile of the user.
B) An event is allocated to a tenant, a tenant is attached to a domain, and a domain is referenced in the security profile of the user.
C) An event is in a domain, a domain is attached to a tenant, and a tenant is referenced in the security profile of the user.
D) An event is in a domain, and a domain is referenced in the security profile of the user.
3. An analyst views a dashboard in Pulse, which is not working as expected.
Which aggregation type should be selected to ensure the correct configuration for a Pie Chart?
A) Last
B) Total
C) First
D) Middle
4. If it is not tuned properly, custom rules can cause performance issues.
Which tool allows you to troubleshoot if a rule causes performance issues?
A) findExpensiveCustomRules.sh
B) threadTop.sh
C) collectGvStats.sh
D) validate_ecs_service.sh
5. Which QRadar app displays time series graphs for queries?
A) Log Management App
B) Assistant for Watson
C) Pulse
D) Threat Intelligence
질문과 대답:
질문 # 1 정답: B | 질문 # 2 정답: C | 질문 # 3 정답: C | 질문 # 4 정답: A | 질문 # 5 정답: C |