Skip to main content

C2150-612 Real Exam Questions

IBM Security QRadar SIEM V7.2.6 Associate Analyst

105 questions available · Page 1 of 11

Updated Exam DumpsVerified AnswersPass Guarantee

Get Complete Exam Dumps
Question 1 Single choice

Which type of tests are recommended to be placed first in a rule to increase efficiency?

  1. A

    Custom property tests

  2. B

    Normalized property tests

  3. C

    Reference set lookup tests

  4. D

    Payload contains regex tests

Show answer and explanation

Correct answer: B

Question 2 Multiple choice

Which three options are available on the New Search on the My Offenses and All Offenses pages? (Choose three.)

  1. A

    Notes

  2. B

    Source IP

  3. C

    Magnitude

  4. D

    Attack Name

  5. E

    Malware Name

  6. F

    Specific Interval

Show answer and explanation

Correct answers: B, D, F

Explanation

References:
https://www.ibm.com/support/knowledgecenter/en/SS42VS_7.3.1/com.ibm.qradar.doc/
t_qradar_search_my_all_off_pages.html

Question 3 Single choice

A mapping of a username to a user's manager can be stored in a Reference Table and output in a search

or a report.

Which mechanism could be used to do this?

  1. A

    Quick Search filters can select users based on their manager's name.

  2. B

    Reference Table lookup values can be accessed in an advanced search.

  3. C

    Reference Table lookup values can be accessed as custom event properties.

  4. D

    Reference Table lookup values are automatically used whenever a saved search is run.

Show answer and explanation

Correct answer: B

Question 4 Single choice

Which key elements does the Report Wizard use to help create a report?

  1. A

    Layout, Container, Content

  2. B

    Container, Orientation, Layout

  3. C

    Report Classification, Time, Date

  4. D

    Pagination Option, Orientation, Date

Show answer and explanation

Correct answer: A

Explanation

References:
IBM Security QRadar SIEM Users Guide. Page: 201

Question 5 Single choice

Which log source and protocol combination delivers events to QRadar in real time?

  1. A

    Sophos Enterprise console via JDBC

  2. B

    McAfee ePolicy Orchestrator via JDBC

  3. C

    McAfee ePolicy Orchestrator via SNMP

  4. D

    Solaris Basic Security Mode (BSM) via Log File Protocol

Show answer and explanation

Correct answer: C

Question 6 Single choice

How does flow data contribute to the Asset Database?

  1. A

    Correlated Flows are used to populate the Asset Database.

  2. B

    It provides administrators visibility on how systems are communicating on the network.

  3. C

    Flows are used to enrich the Asset Database except for the assets that were discovered by scanners.

  4. D

    It delivers vulnerability and ports information collected from scanners responsible for evaluating network assets.

Show answer and explanation

Correct answer: C

Question 7 Single choice

What is the purpose of coalescing?

  1. A

    To reduce the number of events which count against EPS licenses

  2. B

    To reduce the amount of data received by QRadar event collectors

  3. C

    To reduce the amount of data going through the pipeline and stored onto disk

  4. D

    To reduce the number of offenses generated by QRadar as part of the tuning process

Show answer and explanation

Correct answer: A

Explanation

References:
https://developer.ibm.com/answers/questions/438469/out-eps-licence-is-10k-im-attaching-two-screenshot/

Question 8 Multiple choice

Which two are top level options when right clicking on an IP Address within the Offense Summary page? (Choose two.)

  1. A

    WHOIS

  2. B

    Navigate

  3. C

    DNS Lookup

  4. D

    Information

  5. E

    Asset Summary Page

Show answer and explanation

Correct answers: B, D

Question 9 Single choice

Which QRadar rule could detect a possible potential data loss?

  1. A

    Apply "Potential data loss" on event of flows which are detected by the local system and when any IP is part of any of the following XForce premium Premium_Malware

  2. B

    Apply "Potential data loss" on flows which are detected by the local system and when at least 1000 flows are seen with the same Destination IP and different Source IP in 2 minutes

  3. C

    Apply "Potential data loss" on events which are detected by the local system and when the event category for the event is one of the following Authentication and when any of Username are contained in any of Terminated_User

  4. D

    Apply "Potential data loss" on flows which are detected by the local system and when the source bytes is greater than 200000 and when at least 5 flows are seen with the same Source IP, Destination IP, Destination Port in 12 minutes

Show answer and explanation

Correct answer: D

Question 10 Single choice

Which information can be found under the Network Activity tab?

  1. A

    Flows

  2. B

    Events

  3. C

    Reports

  4. D

    Offenses

Show answer and explanation

Correct answer: A