IBM C2150-612 Exam Practice Questions (P. 1)
- Full Access (54 questions)
- Six months of Premium Access
- Access to one million comments
- Seamless ChatGPT Integration
- Ability to download PDF files
- Anki Flashcard files for revision
- No Captcha & No AdSense
- Advanced Exam Configuration
Question #1
Where can a user add a note to an offense in the user interface?
- ADashboard and Offenses Tab
- BOffenses Tab and Offense Detail Window
- COffenses Detail Window, Dashboard, and Admin Tab
- DDashboard, Offenses Tab, and Offense Detail Window
Correct Answer:
B
References:
IBM Security QRadar SIEM Users Guide. Page: 34
B
References:
IBM Security QRadar SIEM Users Guide. Page: 34
send
light_mode
delete
Question #2
When might a Security Analyst want to review the payload of an event?
- AWhen immediately after login, the dashboard notifies the analyst of payloads that must be investigated
- BWhen "Review payload" is added to the offense description automatically by the "System: Notification" rule
- CWhen the event is associated with an active offense, the payload may contain information that is not normalized or extracted fields
- DWhen the event is associated with an active offense with a magnitude greater than 5, the payload should be reviewed, otherwise it is not necessary
Correct Answer:
C
C
send
light_mode
delete
Question #3
Which key elements does the Report Wizard use to help create a report?
- ALayout, Container, Content
- BContainer, Orientation, Layout
- CReport Classification, Time, Date
- DPagination Option, Orientation, Date
Correct Answer:
A
References:
IBM Security QRadar SIEM Users Guide. Page: 201
A
References:
IBM Security QRadar SIEM Users Guide. Page: 201
send
light_mode
delete
Question #4
How is an event magnitude calculated?
- AAs the sum of the three properties Severity, Credibility and Relevance of the Event
- BAs the sum of the three properties Severity, Credibility and Importance of the Event
- CAs a weighted mean of the three properties Severity, Credibility and Relevance of the Event
- DAs a weighted mean of the three properties Severity, Credibility and Importance of the Event
Correct Answer:
C
C
send
light_mode
delete
Question #5
What is a benefit of using a span port, mirror port, or network tap as flow sources for QRadar?
- AThese sources are marked with a current timestamp.
- BThese sources show the ASN number of the remote system.
- CThese sources show the username that generated the flow.
- DThese sources include payload for layer 7 application analysis.
Correct Answer:
D
References:
https://www.ibm.com/developerworks/community/forums/html/topic?id=dd3861e0-f630-4a53-94c3-b426a47b6e02
D
References:
https://www.ibm.com/developerworks/community/forums/html/topic?id=dd3861e0-f630-4a53-94c3-b426a47b6e02
send
light_mode
delete
All Pages