C2150-195 Exam Questions
114 real C2150-195 exam questions with expert-verified answers and explanations. Page 2 of 3.
- Question #51
What are three time range options in the New/Edit search dialog box? (Choose three.)
- Question #52
How can a user pause live streamingevents?
- Question #53
Which two pages or tabs are added to the IBM Security QRadar V7.0 MR4 (QRadar) Log Management product after it has been upgraded to QRadar SIEM? (Choose two.)
- Question #54
If a user wants to search for Windows user login failures, which high/low level category should beused?
- Question #55
On the Offense Summary page, which filter is executed when the Flows icon or the link with the number offlows is clicked on?
- Question #56
On the Offenses tab, which option displays offenses by access, exploit, or malware?
- Question #57
What does it mean if events are coming in as stored?
- Question #58
If a report author shares a report withanother IBM Security QRadar V7 0 MR4 user, what type of report access is granted to the other user?
- Question #59
What is a QID identifier?
- Question #60
Which event search group contains default PCI searches?
- Question #61
What is the rule for using the Quick Filter to group terms using logical expressions such as AND, OR, and NOT?
- Question #62
How can a report be set up with restricted user access?
- Question #63
How many default dashboards are included in IBM Security QRadar V7.0 MR4?
- Question #64
Which flow source is most often sampled?
- Question #65
On the Offense summary page, which filter is executed when the Events icon or the link with the number of events is clicked?
- Question #66
What is a prerequisite to create a report that contains at least onebar chart?
- Question #67
Using Quick Filter, what is a correct search term to find Blocked related activities in the payload?
- Question #68
How does a user search for events by high/low level category?
- Question #69
Offenses can be exported to which two file formats? (Choose two.)
- Question #70
In the All Offenses dialog box, which column are the offenses sorted by default?
- Question #71
In what formats can you export viewer data?
- Question #72
How might you use a Building Block?
- Question #74
What is a custom property?
- Question #75
What does the ecs process do?
- Question #76
Where are QID values displayed?
- Question #77
A user is complaining of slow traffic on aspecific network segment. An administrator is investigating the source of the congestion using the IBM Security QRadar V7.0 MR4 (QRadar) D...
- Question #78
Which function queries for offenses using specific criteria and displays those offenses that match the criteria?
- Question #79
What is the most likely issue with creating a custom property with a bad regex?
- Question #80
What are two examples of an exact search phrase for finding Firewall deny events using the Quick Filter? (Choose two.)
- Question #81
How can the time zone be changed for an existing report?
- Question #82
Which search property is required for a user to create a Time Series chart?
- Question #83
Which two components are only part of the IBM Security QRadar V7.0 MR4 (QRadar) SIEM and cannot be found in the QRadar Log Management? (Choose two.)
- Question #84
Which search parameter in the Log Activity tab must be used to filter events by activity (e.g. SSH Login Succeeded)?
- Question #85
What two tasks can be performed from the Assets tab? (Choose two.)
- Question #86
Click the Exhibit button. What is the appropriate regex to extract the TirneWritten field value from the payload?
- Question #87
Where would a user look to see the entire payload of an event?
- Question #88
Which tab displays correlated security alerts in IBM SecurityQRadar V7.0 MR4?
- Question #89
How can a user quickly reload the default filter in their current tab?
- Question #90
How is an asset's weight used?
- Question #91
What is the main difference between a QFlow record versus a netflow capable router or switch?
- Question #92
Which statement about log source identifiers is true for the same log source identifier to be used more than once?
- Question #93
What is an Offense Type?
- Question #94
Which statement is most accurate regarding the information that NetFlow provides?
- Question #95
How can a user quickly add a filter?
- Question #96
In the default Log Activity screen the right-click >False Positive menu is available in which column?
- Question #97
If an IBM Security QRadar V7.0 MR4operator wants to detect a specific data string in the flow content, which search parameter should be used as a filter?
- Question #98
What are two IT Security Frameworks? (Choose two.)
- Question #99
Which colored icon must be selected in the chart to change the chart type when viewing a grouped search?
- Question #100
Where would a user set a searched view as the default view?
- Question #101
What effect does the Offense Retention period have on closed offenses and who can modify this period?