C1000-163 Exam Questions
181 real C1000-163 exam questions with expert-verified answers and explanations. Page 1 of 4.
- Question #1
What are unknown events?
- Question #2
What does it mean when a custom rule is partially matched in QRadar?
- Question #3
Which QRadar log file contains information about the rates of EPS?
- Question #4
For a Source IP based offense, which field helps determine relative importance of the targets to the business?
- Question #5
Which of the following is used to process flows in Qradar?
- Question #6
A deployment professional needs to migrate test rules developed in a test QRadar deployment to a production QRadar deployment. Which approach can be used to migrate the rules?
- Question #7
An analyst reviewed an active offense that was many attackers, generating many events in the same category, targeting many systems. Upon further analysis, the analyst determined th...
- Question #8
Where can a deployment professional find updates to DSMs?
- Question #9
What must a deployment professional select when defining a new flow source?
- Question #10
Several counts of the system notification message 38750088 - Performance degradation that were detected in the Event pipeline showed in a report. In this case, what does the Event...
- Question #11
What is correct order to stop Qradar Services?
- Question #12
On a QRadar appliance, you might see a warning that you cannot connect to port 32006. Which command you will use for determining port information?
- Question #13
Which regex statement extracts the DNS host from the cs-host value from the payload?
- Question #14
This partial Network diagram was provided to a QRadar deployment professional who is trying to determine if the deployment requires the definition of multiple domains. How many dom...
- Question #15
Which two options does a QRadar analyst need to configure in the False Positive window of the QRadar Console to mark an event or flow as False Positive?
- Question #16
A QRadar deployment professional is asked to migrate the configuration of a system from Log Manager to QRadar SIEM. How should the custom rules, saved searches, and reports be migr...
- Question #17
Which two statements are prerequisites for an to upgrade of QRadar? (Choose two.)
- Question #18
A QRadar deployment professional has been asked to merge two QRadar deployments (AIO_A and AIO_B) into one new environment (AIO_C). Each environment consists of an All-in-One appli...
- Question #19
In a multitenant environment, what is prevented by assigning log sources to a specific domain?
- Question #20
Which two of these authentication types are valid for RADIUS authentication? (Choose two.)
- Question #21
What happens to events and flows when data bursts exceed the license?
- Question #22
While reviewing apps in QRadar Assistant, an analyst wants to view the apps that work properly. What sort option should the analyst choose?
- Question #23
To increase the amount of storage for IBM Security QRadar, data is moved to an offboard storage device. Which method for adding external storage must be used for /store/ariel?
- Question #24
Which item can be used in the configuration of a domain in QRadar?
- Question #25
Where does QRadar display R2R events?
- Question #26
Which tool can be used to check the connections to all managed hosts and verify the versions of ECS and ECS-Ingress services after an upgrade?
- Question #27
A QRadar user wants to edit a building block to include geographic locations that they want to prevent from accessing their network. The user will edit the "and when the source is...
- Question #28
Which are stored events?
- Question #29
There are 10 retention buckets in Qradar SIEM. The default is placed in the last line with retention policy of 30 days. Action is set to delete the data immediately after retention...
- Question #30
Which data is processed by the IBM Security QRadar Network Threat Analytics app?
- Question #31
Which command can be used to check the amount of available physical and swap memory?
- Question #32
One data gateway appliance can collect up to ____ number of EPS.
- Question #33
Which of these is a benefit of the QRadar Assistant Guide Center?
- Question #34
What is an approach to tuning a "noisy" rule, that is, a rule that generates too many offenses?
- Question #35
The ____________command removes a directory and all files in it.
- Question #36
The Server Discovery process updates building blocks based on which of these?
- Question #37
After a successful upgrade, which two actions does a deployment professional perform to complete the installation?
- Question #38
Which of these procedures duplicates a report from the Reports tab?
- Question #39
A security analyst uses Use Case Manager > Active Rules and detects which TOP rule- generating offenses are triggered due to inbound traffic that is dropped by the firewall. The co...
- Question #40
What are the types of reference data collections in QRadar?
- Question #41
Which component processes unallocated syslog messages, identifies the DSMs that are installed on the system, and then assigns the appropriate log source type to a new log source?
- Question #42
What does QRadar attempt to do when the system generates "Accumulator is falling behind" warnings?
- Question #43
What information is provided by using the Sharing MITRE-mapping files in Use Case Manager?
- Question #44
What demarcation is added to a custom event property to let you know that this value is held in memory for a set amount of time?
- Question #45
Which statement about the Extensions Management tool in QRadar is true?
- Question #46
An administrator needs to add, delete and modify user accounts. When deleting a user, what dependency checks are carried out?
- Question #47
Which app can be used to find the state (active, standby, offline, or unknown) of each appliance, the number of notifications for each host, the host name and appliance type, disk...
- Question #48
Which port is used by appliances that provide syslog events to send event data to QRadar components?
- Question #49
Which port is used for bidirectional traffic between WinCollect agent and QRadar Console?
- Question #50
What must be created before the Use Case Manager app can be used?