IBM
C1000-163 · Question #82
QRadar uses rules to monitor the events and flows in your network to detect security threats. When the events and flows meet the test criteria that is defined in the rules, an offense is created to…
The correct answer is B. Offense investigations. See the full explanation below for the reasoning.
Question
QRadar uses rules to monitor the events and flows in your network to detect security threats. When the events and flows meet the test criteria that is defined in the rules, an offense is created to show that a security attack or policy breach is suspected. Knowing that an offense occurred is only the first step; identifying the root cause of the offense requires analysis. These statements refer to what kind of Offense Management?
Options
- AOffense indexing
- BOffense investigations
- COffense retention
- DOffense actions
How the community answered
(26 responses)- A8% (2)
- B85% (22)
- C4% (1)
- D4% (1)
Community Discussion
No community discussion yet for this question.