[Jan-2022] IBM C1000-018 Exam Practice Test Questions - ValidDumps
Updated Certification Exam C1000-018 Dumps - Practice Test Questions
NEW QUESTION 11
An analyst needs to create a dashboard item that can be shared with other users. What is the main step in this process?
- A. Create and share the search criteria that the dashboard Item will use.
- B. Enable a new custom dashboard and share it with users.
- C. Have users index the shared search criteria for reuse.
- D. Ask the administrator to modify the shared search criteria and test the dashboard.
Answer: B
NEW QUESTION 12
Which are the supported protocol configurations for Check Point integration with QRadar? (Choose two.)
- A. OPSEC/LEA
- B. CHECKPOINT REST API
- C. JDBC
- D. SFTP
- E. SYSLOG
Answer: A,E
NEW QUESTION 13
What information is displayed in the default "Log Activity" page? (Choose two.)
- A. Event Name
- B. QID
- C. Log Source
- D. Protocol
- E. Qmap
Answer: A,C
Explanation:
Explanation
By default, the Log Activity tab displays the following parameters when you view normalized events:
NEW QUESTION 14
What happens to a Closed Offense after the offense retention period which defaults to 30 days7
- A. It is manually deleted by the administrator
- B. It is hidden from view.
- C. It is automatically archived.
- D. It is deleted from the system.
Answer: C
NEW QUESTION 15
What event information within an offense would provide the analyst with a deep insight as to how it was created?
- A. Event Magnitude
- B. Event Category
- C. Event QID
- D. Event Payload
Answer: A
NEW QUESTION 16
An analyst is reviewing a rule that is configured to create an Offense indexed by a uri domain name. But even after validating all the rule conditions, an Offense is not generated.
What could be the reason for this kind of behaviour?
- A. Normalized property Source IP is empty in the events.
- B. Normalized property url domain name is empty in the events.
- C. Custom property url domain name is empty in the events.
- D. Custom property Eventname is empty in the events.
Answer: D
NEW QUESTION 17
What is the reason for this system notification?
"Time synchronization to primary or Console has failed"
- A. Deny ntpdate communication on port 323.
- B. Deny ntpdate communication on port 123
- C. Deny ntpdate communication on port 423.
- D. Deny ntpdate communication on port 223.
Answer: A
NEW QUESTION 18
From which tab in QRadar SIEM can an analyst search vulnerability data and remediate vulnerabilities?
- A. Log Activity
- B. Dashboard
- C. Admin
- D. Assets
Answer: A
NEW QUESTION 19
An analyst has manually created a new log source in QRadar.
What is the Low Level Category that will be applied to all events sent from this log log source type is applied?
- A. Stored
- B. Unavailable
- C. Not Found
- D. Unknown
Answer: C
NEW QUESTION 20
An analyst is searching for a list of events that meet specific search criteria and wants to display only the source IP and destination IP information for the events.
To get the required information, the analyst can open the Log Activity tab and then:
- A. select search,
then new search,
scroll down and select time range, column definitions, the search parameters then click search. - B. select the field names,
select the start and end time from the drop down fields in the filters section, then click search. - C. select advanced search.
type the corresponding AQL query,
then click search. - D. click add filter,
select the desired parameters, operators, values and field names,
then click search.
Answer: B
NEW QUESTION 21
An analyst wants to analyze the long-term trending of data from a search.
Which chart would be used to display this data on a dashboard?
- A. Bar Graph
- B. Scatter Chart
- C. Pie Chart
- D. Time Series chart
Answer: D
Explanation:
Explanation
Time series charts are graphical representations of your activity over time.
Peaks and valleys that are displayed in the charts depict high and low volume activity. Time series charts are useful for short-term and long term trending of data.
https://www.ibm.com/docs/en/qsip/7.4?topic=management-time-series-chart-overview
NEW QUESTION 22
An analyst needs to create a new custom dashboard to view dashboard items that meet a particular requirement.
What are the main steps in the process?
- A. Request the administrator to create the custom dashboard with required items.
- B. Locate existing dashboard and modify to include indexed items required and save.
- C. Select New Dashboard and enter unique name, description, add items and save.
- D. Select New Dashboard and copy name, add description, items and save.
Answer: A
Explanation:
Explanation
To create or edit your dashboards, log in as an administrator, click the Dashboards tab, and then click the gear icon. In edit mode, you can create new dashboards, add and remove widgets, edit display values in existing widgets, and reorder tabs.
NEW QUESTION 23
Which QRadar component stores Event data?
- A. App Host
- B. Event Processor
- C. Event Collector
- D. Flow Collector
Answer: A
NEW QUESTION 24
The administrator had set up several scheduled reports that can be executed by analysts every Monday, and the first day of each month. On Thursday, an executive requests one of the weekly reports.
If the analyst executes the report on Thursday, what information will the report contain?
- A. Data from Thursday from the previous week to Wednesday from the current week
- B. Data from Monday to Sunday from the previous week.
- C. Data from Monday to Thursday from the current week.
- D. Data from Monday to Wednesday from the current week.
Answer: C
NEW QUESTION 25
An auditor has requested a report for all Offenses that have happened in the past month. This report generates at the end of every month but the auditor needs to have it for a meeting that is in the middle of the month.
What will happen to the scheduled report if the analyst manually generates this report?
- A. The report still generates on the schedule initially configured.
- B. The scheduled report needs to be reconfigured.
- C. The report will get duplicated so the analyst can then run one manually.
- D. The analyst needs to delete the scheduled report and create a new one.
Answer: D
Explanation:
Explanation
Shared schedules must be deleted manually using the Schedules page in the web portal or the Shared Schedules folder in Management Studio. If you delete a shared schedule that is in use, all references to it are replaced with report-specific schedules.
If you delete a shared schedule that is used by multiple reports and subscriptions, the report server will create individual schedules for each report and subscription that previously used the shared schedule. Each new individual schedule will contain the date, time, and recurrence pattern that was specified in the shared schedule. Note that Reporting Services does not provide central management of individual schedules. If you delete a shared schedule, you will now have to maintain the schedule information for each individual item.
NEW QUESTION 26
When an Offense is triggered, it only shows the events that triggered the Offense. The analyst wants to investigate further to see more events around the incident, not only those that triggered the Offense. The analyst clicks on the event count and sees the events belonging to the Offense.
How can the analyst processed to see a more detailed picture of what occurred?
- A. Right-click and filter on the Destination IP.
- B. Right-click on the source IP, and choose View in DSM Editor.
- C. Right-click on the source IP, and choose More Options, then Information, and then Search Events
- D. Right-click on the destination IP, and choose More Options, then Raw Events.
Answer: C
NEW QUESTION 27
An analyst is investigating a series of events that triggered an Offense. The analyst wants to get more detailed information about the IP address from the reference set.
How can the analyst accomplish this?
- A. Click on Searches tab then perform a Quick Search
- B. Click on Searches tab then perform an Advanced Search
- C. Click on Log Activity tab then perform an Advanced Search
- D. Click on Log Activity tab then perform a Quick Search
Answer: B
NEW QUESTION 28
An analyst observed a port scan attack on an internal network asset from a remote network.
Which filter would be useful to determine the compromised host?
- A. Source or Destination IP
- B. Destination IP [Indexed]
- C. Any IP
- D. Source IP [Indexed]
Answer: C
NEW QUESTION 29
An analyst wants to analyze the long-term trending of data from a search.
Which chart would be used to display this data on a dashboard?
- A. Time Series chart
- B. Bar Graph
- C. Scatter Chart
- D. Pie Chart
Answer: D
NEW QUESTION 30
QRadar collects information from numerous log sources and other agents. Sometimes these agents stop reporting to QRadar for a variety of reasons. There is a default rule in QRadar to help identify these cases called the Device Stopped Sending Events (DSSE) Rule.
What does the DSSE Rule do?
- A. It listens for log sources that send out regular health events and triggers the Rule when encountered
- B. It checks for Rules which have fired due to an absence of Events.
- C. It runs when there is an absence of Events.
- D. It checks for log sources which are reporting that they have not had any communication in a certain amount of time.
Answer: B
NEW QUESTION 31
An analyst is investigating an Offense and has found that the issue is that a firewall appears to be misconfigured and has permitted traffic that should be prevented to pass.
As part of the firewall rule change process, the analyst needs to send the offense details to the firewall team to demonstrate that the firewall permitted traffic that should have been blocked.
How would the analyst send the Offense summary to an email mailbox?
- A. Search for the events linked to the Offense in the Log Activity tab; Select all events and copy them using CTRL-C then paste into an email client.
- B. Open the Offense in the Offenses tab, select 'Email' from the 'Action' menu item and, optionally, add some extra information.
- C. Find the CRE Event in the Log Activity tab, open the event detail and select 'Email linked Offense details' from the 'Action' menu.
- D. Identify the Offense in the Offense list, right click on the Offense and select 'Custom Action Script';
'Offense Mailer'
Answer: A
NEW QUESTION 32
Which QRadar timestamp specifies when the event was received from the log source?
- A. Log Source time
- B. Start time
- C. Storage time
- D. Collect time
Answer: B
Explanation:
Explanation
https://www.ibm.com/mysupport/s/question/0D50z00006PEG2mCAH/why-do-i-see-different-time-stamps-for-q
NEW QUESTION 33
An analyst notices that there are a number of invalid Offenses being created from a network node. This node has been determined to be in Domain 2 and has the following log sources sending it events: (3Com 8800 Series Switch from 172.18.1.1, Cisco ACE Firewall from 172.18.1.2, FireEye from 172.18.1.3, and Palo Alto PA Series from 172.18.1.8).
The analyst should create a False Positive Building Block that has a filter:
- A. "when the local network is Domain 2 and when the source IP is in 172.18.0.0/16"
- B. "when the destination IP is in 172.18.0.0/16"
- C. "when the remote IP is one of the following 172.18.1.1, 172.18.1.2. 1.3 172. 18.18.1.8
- D. "when the local network is Domain 2 and when the source IP is in 172.18.0.0/16"
Answer: D
NEW QUESTION 34
......
IBM C1000-018 Exam Syllabus Topics:
| Topic | Details |
|---|---|
| Topic 1 |
|
| Topic 2 |
|
| Topic 3 |
|
| Topic 4 |
|
| Topic 5 |
|
| Topic 6 |
|
| Topic 7 |
|
| Topic 8 |
|
Updated Verified C1000-018 dumps Q&As - Pass Guarantee or Full Refund: https://pass4sure.validdumps.top/C1000-018-exam-torrent.html