IBM Security QRadar SIEM V7.5 Administration - C1000-156 Exam Practice Test
An administrator opens the Offenses section and goes to Rules to edit the system notification rule. What is the rule name for system notifications?
Correct Answer: B
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
You analyzed network flows and decided that you want to track any network bandwidth violations by any application that comes from your network source. You want to report on all applications that create traffic and the amount of data (total bytes) from each IP. You want to store the IP address, the application, and the amount of data in the reference data collection.
What type of reference data collection must you create to support this use case?
What type of reference data collection must you create to support this use case?
Correct Answer: B
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
How many vulnerability processors can you have in your deployment?
Correct Answer: A
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
Which User Management option manages the QRadar functions that the user can access?
Correct Answer: B
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
You are using the command line interface (CLI) and need to fix a storage issue. What command do you use to verify disk usage levels?
Correct Answer: C
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
Which is a valid statement about the process of restoring a backup archive?
Correct Answer: B
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
Which two (2) open standards does the QRadar Threat Intelligence app use for feeds?
Correct Answer: A,E
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).