nerdexam
IBM

C1000-163 · Question #82

QRadar uses rules to monitor the events and flows in your network to detect security threats. When the events and flows meet the test criteria that is defined in the rules, an offense is created to…

The correct answer is B. Offense investigations. See the full explanation below for the reasoning.

Question

QRadar uses rules to monitor the events and flows in your network to detect security threats. When the events and flows meet the test criteria that is defined in the rules, an offense is created to show that a security attack or policy breach is suspected. Knowing that an offense occurred is only the first step; identifying the root cause of the offense requires analysis. These statements refer to what kind of Offense Management?

Options

  • AOffense indexing
  • BOffense investigations
  • COffense retention
  • DOffense actions

How the community answered

(26 responses)
  • A
    8% (2)
  • B
    85% (22)
  • C
    4% (1)
  • D
    4% (1)

Community Discussion

No community discussion yet for this question.

Full C1000-163 Practice