IBM Certified Analyst - Security QRadar SIEM V7.5 C1000-162 Exam Questions

Page: 1 / 14
Total 64 questions
Question 1

Which two (2) options are used to search offense data on the By Networks page?



Answer : B, E

To search offense data on the By Networks page, an analyst can use the options 'Events/Flows' to filter based on the types of data points, and 'Network' to specify the network they want to search for. This allows for a focused search on specific networks and types of data.


Question 2

Which parameters are used to calculate the magnitude rating of an offense?



Answer : B

The magnitude rating of an offense in IBM Security QRadar SIEM V7.5 is calculated based on three key parameters: severity, relevance, and credibility. Severity indicates the level of threat, relevance determines the offense's impact on the network, and credibility reflects the integrity of the offense as determined by the credibility rating configured in the log source. This combination of factors helps prioritize offenses and guide analysts on which ones to investigate first.


Question 3

A QRadar analyst wants to limit the time period for which an AOL query is evaluated. Which functions and clauses could be used for this?



Answer : B

In QRadar, to limit the time period for which an AQL (Ariel Query Language) query is evaluated, the functions and clauses that can be used include START, STOP, LAST, NOW, and PARSEDATETIME. Specifically, the LAST function is used to define a relative time range for the query, such as 'LAST 2 DAYS'.


Question 4

Which type of rule requires a saved search that must be grouped around a common parameter



Answer : B


Question 5

Events can be exported from the QRadar Log Activity tab in which file formats?



Answer : D

Events can be exported from the QRadar Log Activity tab in XML (Extensible Markup Language) or CSV (Comma-Separated Values) formats, providing flexibility in how data is extracted and used for further analysis outside of QRadar.


Question 6

How can an analyst search for all events that include the keyword "access"?



Answer : B

In IBM Security QRadar SIEM V7.5, to search for all events containing a specific keyword such as 'access', an analyst should navigate to the 'Log Activity' tab. This section of the QRadar interface is dedicated to viewing and analyzing log data collected from various sources. By running a quick search with the 'access' keyword in the Log Activity tab, the analyst can filter out events that contain this term in any part of the log data. This functionality is crucial for identifying specific activities or incidents within the vast amounts of log data QRadar processes, allowing analysts to quickly hone in on relevant information for further investigation or action.


Question 7

A task is set up to identify events that were missed by the Custom Rule Engine. Which two (2) types of events does an analyst look for?



Answer : A, D

To identify events that were missed by the Custom Rule Engine (CRE) in IBM Security QRadar SIEM, an analyst would primarily look for 'Log Only Events sent to a Data Store' and 'High Level Category Unknown Events.' Log Only Events are those that are stored directly without being processed by the CRE, indicating they might have been overlooked or not matched by any existing rules. High Level Category Unknown Events are those that do not fit into any of the predefined categories in QRadar, suggesting that the CRE might not have rules to handle or categorize these events properly. These types of events are crucial for analysts to review to ensure that no significant incidents are missed and to refine the rule set for better detection in the future.


Page:    1 / 14   
Total 64 questions