IBM
C2150-196 · Question #22
When creating a new IBM Security QRadar SIEMV7.1 user account, the administrator did not give access to the log source group (called MS Domain Security Logs) that contains Microsoft Security Event…
The correct answer is D. The search will run but since the user was not given access to the MS Domain Security Logs. See the full explanation below for the reasoning.
Question
When creating a new IBM Security QRadar SIEMV7.1 user account, the administrator did not give access to the log source group (called MS Domain Security Logs) that contains Microsoft Security Event logs. What happens if the user attempts to run a shared saved search for failed login attempts to a domain?
Options
- AThe user is not able to see any results from that search.
- BSince the user is part of the domain, they are able to see the data in the search results.
- CThe user is notified that they do not have the proper permissions to run that search and are
- DThe search will run but since the user was not given access to the MS Domain Security Logs
How the community answered
(35 responses)- A9% (3)
- B11% (4)
- C3% (1)
- D77% (27)
Community Discussion
No community discussion yet for this question.