IBM C1000-026 Exam Practice Questions (P. 2)
- Full Access (60 questions)
- Six months of Premium Access
- Access to one million comments
- Seamless ChatGPT Integration
- Ability to download PDF files
- Anki Flashcard files for revision
- No Captcha & No AdSense
- Advanced Exam Configuration
Question #6
Which event routing rule is required to add QRadar Data Store (QDS) capability to a deployment?
- ALog Only (exclude Analytics)
- BDelete data When storage space is required
- CBypass Correlation
- DDelete data immediately after the retention period has expired
Correct Answer:
A
Reference:
https://www.ibm.com/support/knowledgecenter/en/SS42VS_7.3.2/com.ibm.qradar.doc/t_qradar_adm_data_store.html
A
Reference:
https://www.ibm.com/support/knowledgecenter/en/SS42VS_7.3.2/com.ibm.qradar.doc/t_qradar_adm_data_store.html
send
light_mode
delete
Question #7
An administrator is seeing the following system notification:
38750057 `" A protocol source configuration may be stopping events from being collected.
What is a valid user action to this issue?
38750057 `" A protocol source configuration may be stopping events from being collected.
What is a valid user action to this issue?
- ARe-install the QRadar Console
- BReview the /var/log/qradar.log file for more information
- CRestart the QRadar Console
- DReview the /var/log/error.log file for more information
Correct Answer:
D
Reference:
https://www.ibm.com/support/knowledgecenter/en/SS42VS_7.3.0/com.ibm.qradar.doc/38750057.html
D
Reference:
https://www.ibm.com/support/knowledgecenter/en/SS42VS_7.3.0/com.ibm.qradar.doc/38750057.html
send
light_mode
delete
Question #8
An administrator needs to import a list of HR staff logins into a reference set.
Which file type can be used with the import function in the reference set editor window?
Which file type can be used with the import function in the reference set editor window?
- Axml
- Bcsv
- Cxls
- Djson
Correct Answer:
B
Reference:
https://www.ibm.com/support/knowledgecenter/en/SS42VS_7.3.2/com.ibm.qradar.doc/c_qradar_adm_refdata_ui.html
B
Reference:
https://www.ibm.com/support/knowledgecenter/en/SS42VS_7.3.2/com.ibm.qradar.doc/c_qradar_adm_refdata_ui.html
send
light_mode
delete
Question #9
An administrator is about to integrate logs from a custom firewall in a QRadar deployment using syslog. The SIEM has two domains, namely Domain A and
Domain B. While reviewing the following sample logs, the administrator notices a `context` keyword:
May 14 11:05:01 192.168.1.23 20190514 11:05:00 context=contextA permit 192.168.1.24 source: 10.10.1.15; source_port: 64094; destination: 10.10.13.34; service: 53; protocol: udp;
May 13 12:07:01 192.168.1.23 20190513 11:07:00 context=contextB permit 192.168.1.25 source: 10.10.1.15; source_port: 64094; destination: 10.10.13.34; service: 53; protocol: udp;
Which options assign the `contextA` logs to DomainA and the `contextB` logs to domain B? (Choose two.)
Domain B. While reviewing the following sample logs, the administrator notices a `context` keyword:
May 14 11:05:01 192.168.1.23 20190514 11:05:00 context=contextA permit 192.168.1.24 source: 10.10.1.15; source_port: 64094; destination: 10.10.13.34; service: 53; protocol: udp;
May 13 12:07:01 192.168.1.23 20190513 11:07:00 context=contextB permit 192.168.1.25 source: 10.10.1.15; source_port: 64094; destination: 10.10.13.34; service: 53; protocol: udp;
Which options assign the `contextA` logs to DomainA and the `contextB` logs to domain B? (Choose two.)
- ACreate a single log source, create a ג€Contextג€ custom event property, and assign the log to both domains using a custom rule.
- BCreate two individual log sources by configuring a separated logging instance for each context on the firewall and assign each log source to the correct domain.
- CCreate a single log source, create a ג€Contextג€ custom event property, and assign the log to the correct domain using custom event property value.
- DCreate two individual log sources using the context value as log source identifier and assign each log source to the correct domain.
- ECreate a single log source, create a ג€Contextג€ custom event property, and assign the log to the correct domain using a custom rule.
Correct Answer:
BD
BD
send
light_mode
delete
Question #10
An administrator plans to deploy multiple log sources that share a common configuration.
How many log sources can be added at one time?
How many log sources can be added at one time?
- A1000
- B750
- C250
- D500
Correct Answer:
D
Reference:
https://www.ibm.com/support/knowledgecenter/SS42VS_DSM/com.ibm.dsm.doc/t_logsource_bulkadd.html
D
Reference:
https://www.ibm.com/support/knowledgecenter/SS42VS_DSM/com.ibm.dsm.doc/t_logsource_bulkadd.html
send
light_mode
delete
All Pages