IBM C1000-026 Exam Practice Questions (P. 1)
- Full Access (60 questions)
- Six months of Premium Access
- Access to one million comments
- Seamless ChatGPT Integration
- Ability to download PDF files
- Anki Flashcard files for revision
- No Captcha & No AdSense
- Advanced Exam Configuration
Question #1
An administrator needs to import data into QRadar for a specific use case.
The data that has been provided to the administrator is stored in records that map a key to a value.
Which type of data collection must the administrator create?
The data that has been provided to the administrator is stored in records that map a key to a value.
Which type of data collection must the administrator create?
- AReference set
- BReference map of sets
- CReference map
- DReference map of maps
Correct Answer:
C
Reference:
https://www.ibm.com/support/knowledgecenter/en/SS42VS_7.3.2/com.ibm.qradar.doc/t_qradar_conifig_rul_resp_reference_set.html
C
Reference:
https://www.ibm.com/support/knowledgecenter/en/SS42VS_7.3.2/com.ibm.qradar.doc/t_qradar_conifig_rul_resp_reference_set.html
send
light_mode
delete
Question #2
An administrator needs to know if a custom rule is being correlated correctly.
Which QRadar component is responsible for this process?
Which QRadar component is responsible for this process?
- AQRadar Event Collector
- BQRadar Console
- CMagistrate
- DQRadar Event Processor
Correct Answer:
D
Reference:
https://www.ibm.com/support/pages/qradar-global-correlation
D
Reference:
https://www.ibm.com/support/pages/qradar-global-correlation
send
light_mode
delete
Question #3
An administrator needs to collect logs from the Command Line Interface (CLI).
Which command should the administrator use?
Which command should the administrator use?
- A/opt/bin/qradar/support/get_logs.sh
- B/opt/support/get_logs.sh
- C/opt/support/qradar/get_logs.sh
- D/opt/qradar/support/get_logs.sh
Correct Answer:
D
Reference:
https://www.ibm.com/support/pages/getting-help-what-information-should-be-submitted-qradar-service-request
D
Reference:
https://www.ibm.com/support/pages/getting-help-what-information-should-be-submitted-qradar-service-request
send
light_mode
delete
Question #4
To comply with specific regulations, an administrator has been requested to increase asset retention to 365 days.
In which QRadar section can the administrator find the asset retention settings?
In which QRadar section can the administrator find the asset retention settings?
- AAdmin Tab / Asset Retention
- BAssets Tab / Retention settings
- CAdmin Tab / System settings
- DAssets Tab / Asset Retention
Correct Answer:
C
Reference:
https://www.ibm.com/support/knowledgecenter/en/SS42VS_7.3.2/com.ibm.qradar.doc/t_qradar_adm_asset_tuning_ip_retention.html
C
Reference:
https://www.ibm.com/support/knowledgecenter/en/SS42VS_7.3.2/com.ibm.qradar.doc/t_qradar_adm_asset_tuning_ip_retention.html
send
light_mode
delete
Question #5
A QRadar administrator added High Availability (HA) to the Event Processor and needs to verify the crossover link status between the primary and secondary hosts.
Which commands can be used to verify the crossover status? (Choose two.)
Which commands can be used to verify the crossover status? (Choose two.)
- A/opt/qradar/ha/bin/ha_getstate.sh
- B/opt/qradar/ha/bin/getStatus crossover
- C/opt/qradar/ha/bin/qradar_nettune.pl crossover status
- D/opt/qradar/ha/bin/qradar_nettune.pl linkaggr <interface> status
- E/opt/qradar/ha/bin/ha cstate
- Fcat /proc/drbd
Correct Answer:
CE
Reference:
https://www.ibm.com/support/pages/qradar-verifying-ha-crossover-connections-qradarnettunepl
CE
Reference:
https://www.ibm.com/support/pages/qradar-verifying-ha-crossover-connections-qradarnettunepl
send
light_mode
delete
All Pages