C1000-163 Exam Questions
181 real C1000-163 exam questions with expert-verified answers and explanations. Page 4 of 4.
- Question #151
In the Backup Recovery Configuration section, what is the default retention period?
- Question #152
To install the 7.x WinCollect Configuration Console, which of these actions is a prerequisite?
- Question #153
From which tabs can a QRadar custom rule be created?
- Question #154
Where can one share, find available apps, discover what they are used for, discover what they look like, and learn what other users say about apps?
- Question #155
On a Microsoft Windows 2019 server, a WinCollect agent is installed, which polls events locally. Its profile is set to Maximum EPS and the average EPS is 5000. What is the minimum...
- Question #156
Which version of sFlow does QRadar support when defining a new flow source?
- Question #157
Which are the time criteria in AQL queries?
- Question #158
Which script can detemine which QRadar process is consuming the most resources?
- Question #159
What is the purpose of assigning QRadar Use Case Manager to a user role?
- Question #160
Which two types of default building blocks do you need to edit to reduce the number of offenses that are generated by high volume traffic servers?
- Question #161
A QRadar deployment professional wants to integrate a dynamic data set like asset information so that QRadar can use the latest information in the new data set to correlate the rul...
- Question #162
A QRadar deployment professional wants to add entries from a .csv file to the Reference Set. Which script that is included in QRadar can be used?
- Question #163
What is the minimum disk size for a QRadar virtual appliance installation?
- Question #164
What is the hostcontext service?
- Question #165
Reports can be organized into groups for efficient utilization. What report groups are available by default in QRadar?
- Question #166
Which three (3) statements are capabilities of the Network Hierarchy in QRadar?
- Question #167
Which log source should be used to filter QRadar audit events?
- Question #168
Consider this scenario and instruction. Vulnerability assessment products launch attacks that can result in offense creation. To avoid this behavior and define vulnerability assess...
- Question #169
Which of the following changes require standard deployment?
- Question #170
A deployment professional is initially tuning a QRadar deployment. The Log Activity tab shows that there are some external events from a remote network to another remote network. W...
- Question #171
Which two (2) file formats are available for exporting offenses?
- Question #172
A large multinational corporation is expanding its QRadar deployment to new countries. They decided to implement a geographically distributed deployment. What may be a benefit of h...
- Question #173
How are Events that are associated with an offense listed?
- Question #174
An organization wants QRadar to have rules, dashboards, and reports to detect and report on cryptocurrency mining activity. What can be installed in QRadar to meet this requirement...
- Question #175
When prioritizing offenses to investigate, what metric is provided on the Offenses tab specifically to help influence which offenses to investigate first?
- Question #176
Which of these is a tenant administrator responsible for?
- Question #177
What is the directory where a backup archive file needs to be placed so that QRadar can automatically import it?
- Question #178
At the Offense Summary window, the first row of data shows the level of importance that QRadar assigned to the offense. Which statement is the correct description for Magnitude?
- Question #179
A QRadar deployment professional is asked to plan a hardware migration for an Event Processor in HA. Two new appliances are ready to be used, and they use the same IP addresses. Wh...
- Question #180
Which type of information is considered as identity data for QRadar Assets?
- Question #181
What can an analyst use in QRadar to quickly find information about IP addresses and URLs while analyzing an offense or event?