Skip to main content

C1000-018 Online Practice Questions

IBM QRadar SIEM V7.3.2 Fundamental Analysis

60 questions available · Page 1 of 6

Updated Exam DumpsVerified AnswersPass Guarantee

Get Complete Exam Dumps
Question 1 Single choice

An analyst needs to review additional information about the Offense top contributors, including notes and annotations that are collected about the Offense.

Where can the analyst review this information?

  1. A

    In the top portion of the Offense Summary window

  2. B

    In the bottom portion of the Offense main view

  3. C

    In the bottom portion of the Offense Summary window

  4. D

    In the top portion of the Offense main view

Show answer and explanation

Correct answer: C

Explanation

Explanation:
In the bottom portion of the Offense Summary window, review additional information about the offense top contributors, including notes and annotations that are collected about the offense.

References:
https://www.ibm.com/docs/en/qsip/7.4?topic=investigations-investigating-offense-by-using-
summary-information

Question 2 Single choice

What event information within an offense would provide the analyst with a deep insight as to how it was created?

  1. A

    Event Category

  2. B

    Event QID

  3. C

    Event Payload

  4. D

    Event Magnitude

Show answer and explanation

Correct answer: D

Question 3 Single choice

What does the Assets tab provide?

A unified view of the information that is known about:

  1. A

    network devices.

  2. B

    triggered Offenses.

  3. C

    log sources.

  4. D

    events and flows.

Show answer and explanation

Correct answer: D

Explanation

References:
https://www.ibm.com/support/pages/identity-and-how-log-source-events-update-assets-qradar-siem

Question 4 Single choice

An analyst wants to view information about repeated offenders and IP addresses that generate many attacks or are subject to many attacks.

What should the analyst choose from the navigation options in the Offense tab?

  1. A

    By Event Category or By Event Source

  2. B

    By Source IP or By Destination IP

  3. C

    By Log Source IP or By Event Source

  4. D

    By Event or By Flows

Show answer and explanation

Correct answer: B

Explanation

Explanation:
Use the navigation options on the left to view the offenses from different perspectives. For example, select
By Source IP or By Destination IP.

References:
https://www.ibm.com/docs/en/SS42VS_7.3.3/com.ibm.qradar.doc/b_qradar_users_guide.pdf

Question 5 Single choice

What are the different flow types in QRadar?

  1. A

    L2L, L2R, R2R, R2L

  2. B

    Standard, Type A, Type B, Type C

  3. C

    Standard, Type 1, Type2, Type 3

  4. D

    Type 1, Type 2, Type 3, Type 4

Show answer and explanation

Correct answer: B

Explanation

References:
https://docplayer.net/19071559-Qradar-siem-7-2-flows-overview.html

Question 6 Single choice

While creating a new custom property, which is a valid property type selection?

  1. A

    Flow Based

  2. B

    Event Based

  3. C

    AQL Based

  4. D

    Regular Expressions Based

Show answer and explanation

Correct answer: D

Question 7 Single choice

An analyst needs to use a new custom property in a rule.

What must be the mandatory characteristic of the custom property?

  1. A

    It must be shared.

  2. B

    It must be boolean.

  3. C

    It must be stored.

  4. D

    It must be extracted.

Show answer and explanation

Correct answer: B

Question 8 Single choice

Which filter would an analyst apply in the Log Activity tab to get a list of log sources not reporting to QRadar?

  1. A

    Log source status does not equal active

  2. B

    Custom rule equals device stopped sending events

  3. C

    Log source type does not equal active

  4. D

    Log source status does not equal error

Show answer and explanation

Correct answer: A

Question 9 Single choice

An analyst needs to investigate why an Offense was created.

How can the analyst investigate?

  1. A

    Review the Offense summary to investigate the flow and event details.

  2. B

    Review the X-Force rules to investigate the Offense flow and event details.

  3. C

    Review pages of the Asset tab to investigate Offense details.

  4. D

    Review the Vulnerability Assessment tab to investigate Offense details.

Show answer and explanation

Correct answer: A

Question 10 Single choice

An analyst wants to analyze the long-term trending of data from a search.

Which chart would be used to display this data on a dashboard?

  1. A

    Bar Graph

  2. B

    Time Series chart

  3. C

    Pie Chart

  4. D

    Scatter Chart

Show answer and explanation

Correct answer: A

Explanation

Explanation:
You could use a bar graph if you want to track change over time as long as the changes are significant.

References:
https://www.statisticshowto.com/probability-and-statistics/descriptive-statistics/bar-chart-bar-graph-examples/