Skip to main content

C2150-400 Real Exam Questions

IBM Security Qradar SIEM Implementation v 7.2.1

175 questions available · Page 1 of 18

Updated Exam DumpsVerified AnswersPass Guarantee

Get Complete Exam Dumps
Question 1 Single choice

Which action can be performed on a license key?

  1. A

    Reuse allocation of a license

  2. B

    Revert allocation of a license

  3. C

    Revoke allocation of a license

  4. D

    Recover allocation of license

Show answer and explanation

Correct answer: B

Question 2 Multiple choice

What is QRadar QFlow Collector combined with QRadar SIEM designed to do?

  1. A

    Collect Netflow records

  2. B

    Layer 7 application visibility

  3. C

    Receive Syslog messages

  4. D

    Ensure secure message collection

Show answer and explanation

Correct answers: A, B

Question 3 Single choice

Which offboard storage solution must only be used to mount the /store/backup file system?

  1. A

    FTP

  2. B

    NFS

  3. C

    iSCSI

  4. D

    Fibre Channel

Show answer and explanation

Correct answer: B

Question 4 Multiple choice

In which three ways can you create Log Sources? (Choose three.)

  1. A

    Bulkload

  2. B

    Manually

  3. C

    Automatically

  4. D

    Scripting

  5. E

    Autoupdate

  6. F

    QRadar Enterprise template

Show answer and explanation

Correct answers: B, D, E

Question 5 Single choice

What is used to collect security events in a QRadar Distributed Deployment?

  1. A

    QRadar 3124 Console

  2. B

    QRadar 1724 Processor

  3. C

    QRadar 1624 Processor

  4. D

    QRadar 1310 QFlow Collector

Show answer and explanation

Correct answer: D

Question 6 Single choice

Which QRadar component requires the use of a NAPATECH card?

  1. A

    QRadar 3105 Console

  2. B

    QRadar 1705 Processor

  3. C

    QRadar 1605 Processor

  4. D

    QRadar QFlow Collector 1310

Show answer and explanation

Correct answer: D

Question 7 Single choice

You have created an LSX log parser document to process the unknown log events from your unsupported log source. The events are coming up with Log source type GenericDSM and the correct Log Source
Event ID.

What is the next step in this process?

  1. A

    Create the high level and low level categories from the map id action

  2. B

    Map the custom log records to your own custom high level and low level categories

  3. C

    Create the high level and low level categories from the Rules section in the Offense tab

  4. D

    Run the qidmap.pl script to create high level and low level categories from the command line

Show answer and explanation

Correct answer: D

Question 8 Single choice

Which option will display the rule that triggered an offense from Offense Details screen?

  1. A

    Display > Rules

  2. B

    Display > Sources

  3. C

    Offenses tab > Rules

  4. D

    Display > Annotations

Show answer and explanation

Correct answer: A

Question 9 Single choice

Where is an email address from which you want to receive email alerts on QRadar SIEM located?

  1. A

    Admin > System settings > Alert Email From Address

  2. B

    Admin > Console settings > Alert Email From Address

  3. C

    Admin > System settings > Administrative Email Address

  4. D

    Admin > Console settings > Administrative Email Address

Show answer and explanation

Correct answer: A

Question 10 Single choice

Which Log Source Type should be used to add a Log Source with Log Source Extension?

  1. A

    Any

  2. B

    Custom

  3. C

    Universal DSM

  4. D

    Log Source Extension

Show answer and explanation

Correct answer: D