IBM C1000-018 IBM QRadar SIEM V7.3.2 Fundamental Analysis Exam Practice Test

Page: 1 / 14
Total 103 questions
Question 1

What is displayed in the status bar of the Log Activity tab when streaming events?



Answer : A

Status bar

When streaming events, the status bar displays the average number of results that are received per second.


Question 2

An analyst wants to find all events where Process name includes reference to exe files. Which quick search will return the expected result?



Answer : B


Question 3

While creating a new custom property, which is a valid property types selection?



Question 4

What happens to a Closed Offense after the offense retention period which defaults to 30 days7



Answer : A


Question 5

An analyst has been asked to present a report of all the incidents that have been detected by QRadar in the last 24 hours.

How can the analyst achieve this?



Answer : A


Question 6

What information is included in flow details but is not in event details?



Answer : A

Flows represent network activity by normalizing IP addresses, ports, byte and packet counts, and other data, into flow records, which effectively are records of network sessions between two hosts.


Question 7

What is the reason for this system notification?

"Time synchronization to primary or Console has failed"



Answer : D

38750129 - Time synchronization to primary or Console has failed.

The managed host cannot synchronize with the console or the secondary HA appliance cannotsynchronize with the primary appliance.

Administrators must allow ntpdatecommunication on port 123.


Page:    1 / 14   
Total 103 questions