C2150-196 Exam Questions
135 real C2150-196 exam questions with expert-verified answers and explanations. Page 2 of 3.
- Question #51
Which three pieces of information must be supplied to properly set up a system user? (Choose three.)
- Question #52
What does using the Integrated Management Module of the IBM Security QRadar SEM V7.1 (QRadar) appliance allow a user to do?
- Question #53
Which family of analysis methods are commonly used with a time series?
- Question #54
What must be done to capture a new name/value pair for a rule that is not parsed as part of a regular Device Support Module?
- Question #55
Which two network setting parameters are optional? (Choose two.)
- Question #56
Prior to installing IBM Security QRadar SIEM V7.1 on customer provided hardware, Red Hat Enterprise Linux must be installed. SELinux must be set to which option?
- Question #57
What are three default charting options available within the Report wizard? (Choose three.)
- Question #58
Whatis the purpose of the offense index?
- Question #59
Which statement is true about the IBM Security QRadar SIEM (QRadar) Network Hierarchy?
- Question #60
From the Admin tab > System and License Management icon, what must be done to install and deploy an IBM Security QRadar SIEMV7.1 license for a set of newly installed hosts?
- Question #61
What does the command qchange_netsetup do?
- Question #62
Which tuning template is available in IBM Security QRadar SIEM V7.1?
- Question #63
What must be done to calculate EPS from the IBM Security QRadar SIEM V7.1 Web interface?
- Question #64
Which statement best describe the data migration process available in IBM Security QRadar SIEM V7.1 (QRadar)?
- Question #65
If an IBM Security QRadar 1790 virtual appliance is added to a configuration, which capability becomes available?
- Question #66
How is a new UDSM device created?
- Question #67
What is a purpose of a rule action?
- Question #68
Which method does WinCollect use to collect Windows 2008 events?
- Question #69
Which statement best describes the expected increase in forensic capabilities when IBM Security QRadar QFlow (QRadar QFlow) is implemented?
- Question #70
After configuring external authentication, which user can still log in to the Web interface if this external resource is not available?
- Question #71
Which action can IBM Security QRadar SIEM V7.1 automatically perform on referencesets?
- Question #72
What can IBM Security QRadar SIEM V7.1 be configured to back up in the Backup and Recovery Wizard?
- Question #73
A QID can belong to how many categories?
- Question #74
What is required toconnect a WinCollect agent to IBM Security QRadar SIEM V7.1?
- Question #75
What does the IP Right Click Menu Extensions plug-in do in IBM SecurityQRadar SIEM V7.1?
- Question #76
How is a Universal DSM configured to collect different data types from various log sources?
- Question #77
Where are firewall event details located using the IBM Security QRadar SIEM V7.1 interface?
- Question #78
Which group of tests is used to test the sequence of rulesthat have been triggered by events or flows?
- Question #79
What are two ways asymmetric flow support can be enabled? (Choose two.)
- Question #80
Categorizing log sources into groups allows clients to efficiently view and track log sources. Which statement best characterize Log Source groups?
- Question #81
Which component processes events against defined custom rules?
- Question #82
Which scenario best describes the actions that take place during a restore?
- Question #83
What is the default setting for Major Updates in Auto Updates > Change Settings > Update Types?
- Question #84
What does the % of Searches Using Property column in the Index Management Page indicate?
- Question #85
When adding a new IBM Security QRadar SIEM managed host, the password is required for which user?
- Question #86
What is the benefit of using server discovery?
- Question #87
A user can be assigned which two permissions? (Choose two.)
- Question #88
Which Admin setting allows the monitoring of system load over 15 minutes?
- Question #89
What are two IT Security Frameworks? (Choose two.)
- Question #90
Where would a user set a searched view as the default view?
- Question #91
Which search parameter in the Log Activity tab must be used to filter events by activity (e.g. SSH Login Succeeded)?
- Question #92
How is an asset's weight used?
- Question #93
Given a multi-host deployment, where are data backups for managed hosts stored?
- Question #94
What is the result of modifying a saved search?
- Question #95
To overwrite an IBM Security QRadar SIEM V7.1 system, what must be typed in when prompted during the re-imaging process?
- Question #96
Where does IBM SecurityQRadar SIEM V7.1 get the severity of an event?
- Question #97
IBM Security QRadar SIEM V7.1 can be forced to run an instant backup by selecting which option?
- Question #98
An IBM Security QRadar SIEM V7.1 (QRadar) ALE agent should be installed on which system to collect Windows logs?
- Question #99
Which statement best describes the supported external storage options in IBM Security QRadar SIEM V7.1(QRadar)?
- Question #100
By default how often are events forwarded from an event collector to an event processor?