최신IBM QRadar SIEM V7.3.2 Fundamental Analysis - C1000-018무료샘플문제
문제1
An analyst has been assigned a number of Offenses to review and a new event occurs, review and manage.
While reviewing an inactive offense, a new event occurs.
Which statement applies to the Offense?
An analyst has been assigned a number of Offenses to review and a new event occurs, review and manage.
While reviewing an inactive offense, a new event occurs.
Which statement applies to the Offense?
정답: D
문제2
An analyst needs to investigate an Offense and navigates to the attached rule(s).
Where in the rule details would the analyst investigate the reason for why the rule was triggered?
An analyst needs to investigate an Offense and navigates to the attached rule(s).
Where in the rule details would the analyst investigate the reason for why the rule was triggered?
정답: D
문제3
An analyst noticed that from a particular subnet (203.0.113.0/24), all IP addresses are simultaneously trying to reach out to the company's publicly hosted FTP server.
The analyst also noticed that this activity has resulted in a Type B Superflow on the Network Activity tab-Under which category, should the analyst report this issue to the security administrator?
An analyst noticed that from a particular subnet (203.0.113.0/24), all IP addresses are simultaneously trying to reach out to the company's publicly hosted FTP server.
The analyst also noticed that this activity has resulted in a Type B Superflow on the Network Activity tab-Under which category, should the analyst report this issue to the security administrator?
정답: B
설명: (ExamPassdump 회원만 볼 수 있음)
문제4
To provide insight into why QRadar considers the event to be threatening, what does QRadar add to the Offense that users cannot edit or delete?
To provide insight into why QRadar considers the event to be threatening, what does QRadar add to the Offense that users cannot edit or delete?
정답: C
설명: (ExamPassdump 회원만 볼 수 있음)
문제5
What are the different flow types in QRadar?
What are the different flow types in QRadar?
정답: B
문제6
Which filter would an analyst apply in the Log Activity tab to get a list of log sources not reporting to QRadar?
Which filter would an analyst apply in the Log Activity tab to get a list of log sources not reporting to QRadar?
정답: B