C1000-163 · Question #106
What are the search options available for searching offense data on the By Networks page?
The correct answer is C. Source IP, Destination IP, Events/Flows, and Magnitude. Option C is correct because the By Networks page in IBM QRadar focuses on network-level offense analysis, and its search fields are Source IP, Destination IP, Events/Flows, and Magnitude - the four fields that let analysts filter offenses by traffic endpoints, volume of…
Question
What are the search options available for searching offense data on the By Networks page?
Options
- ASource IP, Magnitude, VA Risk, and Domain
- BDomain, Destination IP, Magnitude, and Events/Flows
- CSource IP, Destination IP, Events/Flows, and Magnitude
- DNetwork, Magnitude, VA Risk, and Events/Flows
How the community answered
(25 responses)- A4% (1)
- B4% (1)
- C80% (20)
- D12% (3)
Explanation
Option C is correct because the By Networks page in IBM QRadar focuses on network-level offense analysis, and its search fields are Source IP, Destination IP, Events/Flows, and Magnitude - the four fields that let analysts filter offenses by traffic endpoints, volume of activity, and severity.
- Option A is wrong because it includes VA Risk and Domain, neither of which are search fields on the By Networks page; VA Risk belongs to vulnerability-related views.
- Option B is wrong because Domain is not a search option on this page, and it swaps Source IP for Domain.
- Option D is wrong because it lists Network (which is the column you're grouping by, not a search filter) and VA Risk, which again belongs elsewhere.
Memory tip: Think "SDEM" - Source IP, Destination IP, Events/Flows, Magnitude. These four fields describe who sent it, who received it, how much traffic, and how bad it is - exactly what you need when investigating offenses by network.
Topics
Community Discussion
No community discussion yet for this question.