C1000-163 Exam Questions
181 real C1000-163 exam questions with expert-verified answers and explanations. Page 2 of 4.
- Question #51
How can an analyst search for all events that include the keyword 'access'?
- Question #52
The Server Discovery function can update which system building block?
- Question #53
Which of these views is provided by the DSM Editor?
- Question #54
Before the creation of a new application instance with QRadar Assistant, with what entity must every application be associated?
- Question #55
As a deployment professional, which product do you recommend to reconstruct the raw network data that is related to a security breach?
- Question #56
Which of the following utilities can be run on Qradar?
- Question #57
QRadar rules can utilize reference data to further correlate results. Which term is a valid reference data type?
- Question #58
What QRadar Assistant app do?
- Question #59
For the management of applications with Qradar Assistant, which of these is not an option?
- Question #60
What is used to extract fields, define custom properties, categorize events, and define new QID definitions?
- Question #61
Which of these statements is true about network objects?
- Question #62
Retention buckets are sequenced in order. If a record matches all the filter criteria of multiple buckets, where is the record stored?
- Question #63
To review the internal changes done in Qradar, what log source in log activity tab must be selected?
- Question #64
While reviewing the performance of a QRadar distributed environment, you notice an abnormal number of events that were generated in the past 24 hours: 38750088 - Performance degrad...
- Question #65
Consider this description: Edit the and when either the source or destination IP is one of the following test to include the broadcast addresses of the network. This change removes...
- Question #66
In a multidomain and multitenant environment, how is event visibility provided to users?
- Question #67
Which utility is used for checking the integrity of event and flow logs?
- Question #68
A QRadar 3128 (All-in-One) typically processes up to __________ EPS and __________ FPM.
- Question #69
Which statement is valid about the SAML authentication feature?
- Question #70
A company is developing a QRadar app. They are already running apps on an App Host. Which of these proposed scenarios do you suggest?
- Question #71
If you face problems with HA, what folder do you look in to figure out?
- Question #72
Where is a custom log source type created?
- Question #73
Which IP address is used to log in to the active HA QRadar appliance?
- Question #74
Which QRadar app displays time series graphs for queries?
- Question #75
Which of these items forwards data to a QRadar Packet Capture appliance?
- Question #76
Which additional license is required to use the Am I Affected scan in the IBM Security QRadar Threat Intelligence app?
- Question #77
Which type of network hierarchy can be configured in QRadar?
- Question #78
Which module can be used when the management network access is not possible?
- Question #79
How do you log in to a managed host command line after you install QRadar?
- Question #80
What custom property types does QRadar support?
- Question #81
If it is not tuned properly, custom rules can cause performance issues. Which tool allows you to troubleshoot if a rule causes performance issues?
- Question #82
QRadar uses rules to monitor the events and flows in your network to detect security threats. When the events and flows meet the test criteria that is defined in the rules, an offe...
- Question #83
If a security analyst needs to filter Events according to when they occurred, which parameter should be used?
- Question #84
An organization's QRadar deployment was reviewed. It was determined that more storage is needed. Which appliance should be deployed to meet this need?
- Question #85
How are extensions added to a QRadar deployment?
- Question #86
Where are audit logs located?
- Question #87
An offense remains in a dormant state for __________days.
- Question #88
Under ATT&CK Actions, which option can be used to show an overview of the tactics covered in QRadar Use Case Manager?
- Question #89
Where can Building Blocks be updated in QRadar?
- Question #90
Access to the QRadar network services is controlled first on hosts with __________.
- Question #91
During an App Host migration, a deployment professional needs to ensure that all the apps are stopped. Which task will stop the apps from running?
- Question #92
On a Console migration, after the config backup restoration, what is required to ensure that the required configuration is migrated to the new appliance?
- Question #93
When multiple repositories are configured for authentication, what must a user do when they log in?
- Question #94
An authentication token is generated on the QRadar Console for WinCollect agent installation. What kind of WinCollect agent needs an authentication token?
- Question #95
Which direction value means that an undefined local Source IP accesses an external resource?
- Question #96
A QRadar analyst was asked to provide a selection of events for further investigation by somebody who does not have access to the QRadar system. Which of these approaches provides...
- Question #97
Upon initial configuration, a company asks their deployment professional to move backups to an external device. They are concerned about the percentage of storage space that is use...
- Question #98
The ____________ provides the current version, patch, and other system information for a QRadar system.
- Question #99
There are frequent network interruptions from a particular network zone called "Underground" to the network where QRadar components are installed. Some important applications, thou...
- Question #100
How can a QRadar user visualize the rules for MITRE ATT&CK coverage in Use Case Manager?