
[2022年02月]更新のC1000-018問題集で時間限定!無料アクセスせよ!
C1000-018問題集で2022年最新のIBM C1000-018試験問題
質問 30
An analyst is searching for a list of events that meet specific search criteria and wants to display only the source IP and destination IP information for the events.
To get the required information, the analyst can open the Log Activity tab and then:
- A. select advanced search.
type the corresponding AQL query,
then click search. - B. select search,
then new search,
scroll down and select time range, column definitions, the search parameters then click search. - C. select the field names,
select the start and end time from the drop down fields in the filters section, then click search. - D. click add filter,
select the desired parameters, operators, values and field names,
then click search.
正解: C
質問 31
What is the procedure to re-open a closed Offense?
- A. A closed Offense cannot be re-opened.
- B. Activate the Offense in action/re-open drop down menu in the Admin tab.
- C. Wait for new events/flows that will re-open the closed Offense.
- D. Activate the Offense in the action/re-open drop down menu of the Offense tab.
正解: A
解説:
Explanation
Not possible to reopen a closed offense.
質問 32
Which use case type is appropriate for VPN log sources? (Choose two.)
- A. Securing the Cloud
- B. Critical Data Protection
- C. Insider Threat
- D. Advanced Persistent Threat (APT)
正解: C,D
質問 33
Which component in QRadar collects and creates flow information?
- A. sflow
- B. Qflow
- C. NetFIow
- D. J-Flow
正解: B
解説:
Explanation
https://www.ibm.com/support/pages/qradar-about-flows-and-difference-between-qflow-collector-and-qradar-eve
質問 34
What could be a possible reason that events are routed directly to storage by the custom rule engine (CRE)?
- A. Event Parsing issue
- B. A rule is processing 20,000 EPS
- C. Event normalization issue
- D. System is under high load
正解: D
質問 35
An analyst needs to perform Offense management.
In QRadar SIEM, what is the significance of "Protecting" an offense?
- A. Prevent the Offense from being automatically removed from QRadar.
- B. Escalate the Offense to the QRadar administrator for investigation.
- C. Hide the Offense in the Offense tab to prevent other analysts to see it.
- D. Create an Action Incident response plan for a specific type of cyber attack.
正解: A
解説:
Explanation
Protecting offenses:
You might have offenses that you want to retain regardless of the retention period. You can protect offenses to prevent them from being removed from QRadar after the retention period has elapsed.
質問 36
Which are the supported protocol configurations for Check Point integration with QRadar? (Choose two.)
- A. JDBC
- B. CHECKPOINT REST API
- C. OPSEC/LEA
- D. SFTP
- E. SYSLOG
正解: C,E
質問 37
Which consideration should be given to the position of rule tests that evaluate regular expressions (Regex tests)?
- A. They can only be used in Building Blocks to ensure they are evaluated as infrequently as possible.
- B. They are usually the most specific. As such, they should appear first in the order.
- C. They are usually the most expensive. As such, they should appear last in the order.
- D. They are stateful tests. As such QRadar automatically evaluates them last.
正解: A
質問 38
Which graph types are available for QRadar SIEM reports? (Choose two)
- A. Frequency curve
- B. Histogram
- C. Stacked Bar
- D. Trivial curve
- E. Pie
正解: C,E
解説:
Explanation
https://www.ibm.com/docs/en/qsip/7.4?topic=management-graph-types
質問 39
An analyst has been asked to present a report of all the incidents that have been detected by QRadar in the last
24 hours.
How can the analyst achieve this?
- A. Create a Common saved search from the last 24 hours and then using the Reports tab, create a report to make use of the existing saved search.
- B. Create an Event saved search from the last 24 hours and then using the Log Activity tab, create a report to make use of the existing saved search.
- C. Create an Event saved search from the last 24 hours and then using the Reports tab, create a report to make use of the existing saved search.
- D. Create an Offense saved search from the last 24 hours and then using the Reports tab, create a report to make use of the existing saved search.
正解: C
質問 40
Why would an analyst update host definition building blocks in QRadar?
- A. To reduce false positives.
- B. To stop receiving events from the host.
- C. To close an Offense
- D. To narrow a search.
正解: C
解説:
Explanation
Building blocks to reduce the number of offenses that are generated by high volume traffic servers.
質問 41
What could be a reason that an Event Rule is not triggering as expected?
- A. It contains stateful and stateless tests but is configured to use a Console's CRE Instance instead of the Processor s CRE Instance.
- B. It contains stateless tests but is configured to use the Console's CRE Instance instead of the Processor's CRE Instance.
- C. It contains stateful tests but is configured to use a Processors CRE Instance instead of the Consoles CRE Instance.
- D. It contains stateless tests but is configured to use the Processors CRE Instance instead of the Console's CRE Instance.
正解: B
質問 42
Which QRadar component stored Offenses?
- A. Event Collector
- B. Data Node
- C. Console
- D. Event Processor
正解: B
解説:
Explanation
QRadar Data Node
Data Nodes enable new and existing QRadar deployments to add storage and processing capacity on demand as required. Data Nodes help to increase the search speed in your deployment by providing more hardware resources to run search queries on.
質問 43
How does an analyst view the base64 encoded string of an event's raw payload that contains unprintable characters?
- A. Right click on the event -> view base64 data
- B. Admin -> Under Payload Information, click base64 tab
- C. Copy the raw payload and use an external tool to view base64 data
- D. Log Activity -> Under Payload Information, click base64 tab
正解: A
質問 44
When is the rating of an Offense magnitude re-evaluated?
- A. when the number of vulnerabilities increases
- B. when the threat assessment changes
- C. when new events are added to the Offens
- D. when a port is opened
正解: C
質問 45
The Network Hierarchy is an important part of the system configuration. It can be used to tune out a large number of False Positive Offenses from the standard QRadar rules.
What is the Network Hierarchy?
- A. The Network Hierarchy can be used in all Rules and is accessed from the False Positive button in the Network Activity Tab.
- B. The Network Hierarchy can be used only in Flow Rules and is accessed from the False Positive button in the Network Activity Tab.
- C. There are separate Network Hierarchies for Flow and Event Rules. They are accessed from the False Positive button in the corresponding Activity Tab.
- D. The Network Hierarchy can be used in section of the Admin Tab. accessed from the System Configuration.
正解: C
質問 46
......
IBM C1000-018 認定試験の出題範囲:
| トピック | 出題範囲 |
|---|---|
| トピック 1 |
|
| トピック 2 |
|
| トピック 3 |
|
| トピック 4 |
|
| トピック 5 |
|
| トピック 6 |
|
| トピック 7 |
|
| トピック 8 |
|
| トピック 9 |
|
| トピック 10 |
|
| トピック 11 |
|
IBM C1000-018試験実践テスト問題:https://www.jpntest.com/shiken/C1000-018-mondaishu