IBM C1000-026 Exam Practice Questions (P. 4)
- Full Access (60 questions)
- Six months of Premium Access
- Access to one million comments
- Seamless ChatGPT Integration
- Ability to download PDF files
- Anki Flashcard files for revision
- No Captcha & No AdSense
- Advanced Exam Configuration
Question #16
An administrator needs to upgrade their QRadar environment. The administrator has downloaded the Patchupdate File from Fixcentral and transferred this Image to the Appliance.
Which commands does the administrator need to run to start the upgrade process?
Which commands does the administrator need to run to start the upgrade process?
- A1. cd/medial/updates 2. systemctl stop Qradar 3. Qradar.sh upgrade all 4. systemctl reboot
- B1. mount ג€"o loop ג€"t squashfs XX_patchupdate.sfs /media/updates 2. cd /media/updates 3. /installer
- C1. cd /media/updates 2. yum update XX_patchupdate.sfs
- D1. patch XX_patchupdate.sfs
Correct Answer:
B
B
send
light_mode
delete
Question #17
An administrator has to change the system hardware clock of the QRadar server. The administrator has already restarted the main services (hostservices, tomcat, hostcontext) and needs to synchronize the QRadar Console time with the QRadar managed hosts.
Which command can the administrator use to accomplish this?
Which command can the administrator use to accomplish this?
- A/opt/qradar/support/all_servers.sh systemctl restart systemd-timedated.service
- B/opt/qradar/support/all_servers.sh /opt/qradar/bin/time_sync.sh
- C/sbin/hwclock ג€"systohc /opt/qradar/bin/time_sync.sh
- D/opt/qradar/support/all_servers.sh service ntpd restart
Correct Answer:
B
Reference:
https://www.ibm.com/support/pages/qradar-configuring-ntp-settings-qradar-appliance
B
Reference:
https://www.ibm.com/support/pages/qradar-configuring-ntp-settings-qradar-appliance
send
light_mode
delete
Question #18
An administrator has been tasked to create a saved search that shows a list of multiple login failures for a single user by username. The administrator has done the following:
1. Selected Last Hour in the view option.
2. In the Add filter window, selected the search parameter Custom Rule [Indexed].
3. Selected Equals for Operator.
4. Selected Authentication for Rule Group.
What is the next step the administrator needs to perform for the Rule option?
1. Selected Last Hour in the view option.
2. In the Add filter window, selected the search parameter Custom Rule [Indexed].
3. Selected Equals for Operator.
4. Selected Authentication for Rule Group.
What is the next step the administrator needs to perform for the Rule option?
- ASelect login failures followed by success to the same username
- BSelect multiple login failures from the same source
- CSelect multiple login failures to the same destination
- DSelect multiple login failures for a single username
Correct Answer:
C
C
send
light_mode
delete
Question #19
An administrator needs to extract a property from an intrusion detection system (IDS) log. Using a regular expression, the administrator wants to extract a specific part of the log showing the matching `policy ID` of the IDS.
Which type of property must the administrator create?
Which type of property must the administrator create?
- ACustom event property
- BCustom flow property
- CCustom asset property
- DNormalized event property
Correct Answer:
D
D
send
light_mode
delete
Question #20
A company has two different domains in their IBM QRadar system: Domain_A and Domain_B. An administrator has been tasked to create a rule to look only at events that are tagged with Domain_A and ignore rules that are tagged with the other domains.
What domain text should the administrator use to create this rule?
What domain text should the administrator use to create this rule?
- Ais from domain: Domain_A
- Bfrom domain: Domain_A
- Cdomain is: Domain_A
- Ddomain is one of: Domain_A
Correct Answer:
D
Reference:
https://www.ibm.com/support/knowledgecenter/en/SS42VS_7.3.1/com.ibm.qradar.doc/c_domain_specific_rules_offenses.html
D
Reference:
https://www.ibm.com/support/knowledgecenter/en/SS42VS_7.3.1/com.ibm.qradar.doc/c_domain_specific_rules_offenses.html
send
light_mode
delete
All Pages