[2022年02月] 最新のIBM Certified Associate Analyst C1000-018試験解答豪華セット問題集
IBMコンテンツをマスターしてC1000-018試験合格保証つき問題集!
質問 58
An analyst is reviewing a rule that is configured to create an Offense indexed by a uri domain name. But even after validating all the rule conditions, an Offense is not generated.
What could be the reason for this kind of behaviour?
- A. Normalized property url domain name is empty in the events.
- B. Custom property url domain name is empty in the events.
- C. Normalized property Source IP is empty in the events.
- D. Custom property Eventname is empty in the events.
正解: D
質問 59
An analyst wants to analyze the long-term trending of data from a search.
Which chart would be used to display this data on a dashboard?
- A. Scatter Chart
- B. Bar Graph
- C. Time Series chart
- D. Pie Chart
正解: D
質問 60
How can an analyst verify if any host in the deployment is vulnerable to CVE ID; CVE-2010-000?
- A. Use the asset search feature, select vulnerability external reference from the list of search parameters, select CVE and then type: $CVE-2010000
- B. Use the asset search feature, select vulnerability external reference from the list of search parameters, select CVE and then type: $2010-000
- C. Use the asset search feature, select vulnerability external reference from the list of search parameters, select CVE and then type: 2010-000
- D. Use the asset search feature, select vulnerability external reference from the list of search parameters, select CVE and then type: CVE-2010000
正解: A
質問 61
An analyst needs to investigate why an Offense was created.
How can the analyst investigate?
- A. Review the Vulnerability Assessment tab to investigate Offense details.
- B. Review pages of the Asset tab to investigate Offense details.
- C. Review the Offense summary to investigate the flow and event details.
- D. Review the X-Force rules to investigate the Offense flow and event details.
正解: C
質問 62
An analyst is performing an investigation regarding an Offense. The analyst is uncertain to whom some of the external destination IP addresses in List of Events are registered.
How can the analyst verify to whom the IP addresses are registered?
- A. Right-click on the destination address, More Options, then Information, and then DNS Lookup
- B. Right-click on the destination address, More Options, then Navigate, and then Destination Summary
- C. Right-click on the destination address, More Options, then IP Owner
- D. Right-click on the destination address, More Options, then Information, and then WHOIS Lookup
正解: B
解説:
Explanation
Navigate > View Destination Summary Displays the offenses that are associated with the selected destination IP address.
質問 63
An analyst investigates an Offense that will need more research to outline what has occurred. The analyst marks a 'Follow up' flag on the Offense.
What happens to the Offense after it is tagged with a 'Follow up' flag?
- A. Other analysts in QRadar get an email to look at the Offense.
- B. A flag icon is displayed for the Offense in the Offense view.
- C. Only the analyst issuing the follow up flag can now close the Offense.
- D. New events or flows will not be applied to the Offense.
正解: B
解説:
Explanation
The offense now displays the follow-up icon in the Flag column.
質問 64
When an Offense is triggered, it only shows the events that triggered the Offense. The analyst wants to investigate further to see more events around the incident, not only those that triggered the Offense. The analyst clicks on the event count and sees the events belonging to the Offense.
How can the analyst processed to see a more detailed picture of what occurred?
- A. Right-click and filter on the Destination IP.
- B. Right-click on the destination IP, and choose More Options, then Raw Events.
- C. Right-click on the source IP, and choose View in DSM Editor.
- D. Right-click on the source IP, and choose More Options, then Information, and then Search Events
正解: C
質問 65
An analyst is investigating access to sensitive data on a Linux system. Data is accessible from the /secret directory and can be viewed using the 'sudo oaf command. The specific file /secret/file_08-txt was known to be accessed in this way. After searching in the Log Activity Tab, the following results are shown.
When interpreting this, the analyst is having trouble locating events which show when the file was accessed.
Why could this be?
- A. The 'LinuxServer @ centos' log source has not been configured to send the relevant events to QRadar.
- B. The 'LinuxServer @ cantos' log source has boon configured as a Faise Positive and the specific event for that file has been dropped.
- C. The ;LinuxServer @ centos; log source has coalesscing conigured and the specific event for that file has been discardedd.
- D. The 'LinuxServer @ centos' log source has coalescing configured and the specific event for that file can only be accessed by clicking on the 'Event Count' value.
正解: D
質問 66
What is the reason for this system notification?
"Time synchronization to primary or Console has failed"
- A. Deny ntpdate communication on port 223.
- B. Deny ntpdate communication on port 123
- C. Deny ntpdate communication on port 423.
- D. Deny ntpdate communication on port 323.
正解: B
解説:
Explanation
38750129 - Time synchronization to primary or Console has failed.
The managed host cannot synchronize with the console or the secondary HA appliance cannotsynchronize with the primary appliance.
Administrators must allow ntpdatecommunication on port 123.
質問 67
An analyst is investigating access to sensitive data on a Linux system. Data is accessible from the /secret directory and can be viewed using the 'sudo oaf command. The specific file /secret/file_08-txt was known to be accessed in this way. After searching in the Log Activity Tab, the following results are shown.
When interpreting this, the analyst is having trouble locating events which show when the file was accessed.
Why could this be?
- A. The 'LinuxServer @ centos' log source has not been configured to send the relevant events to QRadar.
- B. The 'LinuxServer @ cantos' log source has boon configured as a Faise Positive and the specific event for that file has been dropped.
- C. The ;LinuxServer @ centos; log source has coalesscing conigured and the specific event for that file has been discardedd.
- D. The 'LinuxServer @ centos' log source has coalescing configured and the specific event for that file can only be accessed by clicking on the 'Event Count' value.
正解: D
質問 68
Which are the supported protocol configurations for Check Point integration with QRadar? (Choose two.)
- A. JDBC
- B. CHECKPOINT REST API
- C. OPSEC/LEA
- D. SFTP
- E. SYSLOG
正解: C,E
質問 69
When looking at Common rules, the parameters available to the tests refer to attributes of events and flows.
Which attributes are available?
Common rule tests can operate on:
- A. a subset of the attributes of events and flows.
- B. all attributes of events and flows.
- C. all flow attributes, but no event attributes.
- D. all event attributes, but no flow attributes.
正解: D
質問 70
What does the Assets tab provide?
A unified view of the information that is kwon about:
- A. triggered Offenses.
- B. network devices.
- C. events and flows.
- D. log sources.
正解: C
解説:
Explanation
https://www.ibm.com/docs/en/qradar-on-cloud?topic=administration-asset-management
質問 71
The Network Hierarchy is an important part of the system configuration. It can be used to tune out a large number of False Positive Offenses from the standard QRadar rules.
What is the Network Hierarchy?
- A. The Network Hierarchy can be used in all Rules and is accessed from the False Positive button in the Network Activity Tab.
- B. The Network Hierarchy can be used only in Flow Rules and is accessed from the False Positive button in the Network Activity Tab.
- C. There are separate Network Hierarchies for Flow and Event Rules. They are accessed from the False Positive button in the corresponding Activity Tab.
- D. The Network Hierarchy can be used in section of the Admin Tab. accessed from the System Configuration.
正解: C
質問 72
Where can an analyst working with Offenses add a regular expression test into an existing rule?
- A. Top
- B. Left
- C. Bottom
- D. Right
正解: A
質問 73
What is a valid offense naming mechanism?
This information should:
- A. be included in the naming of the associated offense(s).
- B. replace the naming of the associated offense(s).
- C. set or replace the naming of the associated offense(s).
- D. set the naming of the associated offense(s).
正解: D
解説:
Explanation
Under "Offense Naming", check "This information should
contribute to the name of the associated offense(s)".
質問 74
An analyst notices that there are a number of invalid Offenses being created from a network node. This node has been determined to be in Domain 2 and has the following log sources sending it events: (3Com 8800 Series Switch from 172.18.1.1, Cisco ACE Firewall from 172.18.1.2, FireEye from 172.18.1.3, and Palo Alto PA Series from 172.18.1.8).
The analyst should create a False Positive Building Block that has a filter:
- A. "when the local network is Domain 2 and when the source IP is in 172.18.0.0/16"
- B. "when the local network is Domain 2 and when the source IP is in 172.18.0.0/16"
- C. "when the destination IP is in 172.18.0.0/16"
- D. "when the remote IP is one of the following 172.18.1.1, 172.18.1.2. 1.3 172. 18.18.1.8
正解: A
質問 75
What is the reason for this system notification?
"Time synchronization to primary or Console has failed"
- A. Deny ntpdate communication on port 223.
- B. Deny ntpdate communication on port 123
- C. Deny ntpdate communication on port 423.
- D. Deny ntpdate communication on port 323.
正解: B
解説:
Explanation
https://www.ibm.com/docs/en/qradar-on-cloud?topic=appliances-time-synchronization-failed The managed host cannot synchronize with the console or the secondary HA appliance cannot synchronize with the primary appliance.
Administrators must allow ntpdate communication on port 123. When time synchronization is incorrect, data might not be reported correctly to the console. The longer the systems go without synchronization, the higher the risk that a search for data, report, or offense might return an incorrect result. Time synchronization is critical to successful requests from managed host and appliances
質問 76
When an analyst sees the system notification "The appliance exceeded the EPS or FPM allocation within the last hour", how does the analyst resolve this issue? (Choose two.)
- A. Delete the volume of events and flows received in the last hour.
- B. Tune the system to reduce the volume of events and flows that enter the event pipeline.
- C. Tune the system to reduce the time window from 60 minutes to 30 minutes.
- D. Adjust the license pool allocations to increase the EPS and FPM capacity for the appliance.
- E. Adjust the resource pool allocations to increase the EPS and FPM capacity for the appliance.
正解: B,D
解説:
Explanation
User response
Adjust the license pool allocations to increase the EPS and FPM capacity for the appliance.
Tune the system to reduce the volume of events and flows that enter the event pipeline.
質問 77
Which consideration should be given to the position of rule tests that evaluate regular expressions (Regex tests)?
- A. They can only be used in Building Blocks to ensure they are evaluated as infrequently as possible.
- B. They are usually the most specific. As such, they should appear first in the order.
- C. They are usually the most expensive. As such, they should appear last in the order.
- D. They are stateful tests. As such QRadar automatically evaluates them last.
正解: A
質問 78
An analyst working with QRadar SIEM has been assigned a new Offense and is preparing a custom report on the Offense summary page. From this page, the analyst wants to navigate to the Log Activity or Network Activity page to export the Event/Flow data (Action -> export to CSV).
How can the analyst do this? (Choose two)
- A. Click the Events / Flows icon.
- B. Click the Summary icon.
- C. In the Event/Flow count section, click the link to open the page.
- D. In the Source IP(s) session, click the link to open the page.
- E. Click the View Attack Path icon.
正解: C,D
質問 79
After working with an Offense, an analyst set the Offense as hidden. What does the analyst need to do to view the Offense at a later time?
- A. Search for all Offenses owned by the analyst
- B. In the al Offenses view, select Actions, then select show hidden Offenses.
- C. In the all Offenses view, at the top of the view, select ''Show hidden'' from the ''Select an option'' drop- down.
- D. Click Clear Filter next to the "Exclude Hidden Offenses".
正解: B
質問 80
From which tab in QRadar SIEM can an analyst search vulnerability data and remediate vulnerabilities?
- A. Log Activity
- B. Assets
- C. Admin
- D. Dashboard
正解: A
質問 81
QRadar collects information from numerous log sources and other agents. Sometimes these agents stop reporting to QRadar for a variety of reasons. There is a default rule in QRadar to help identify these cases called the Device Stopped Sending Events (DSSE) Rule.
What does the DSSE Rule do?
- A. It checks for Rules which have fired due to an absence of Events.
- B. It runs when there is an absence of Events.
- C. It checks for log sources which are reporting that they have not had any communication in a certain amount of time.
- D. It listens for log sources that send out regular health events and triggers the Rule when encountered
正解: C
質問 82
......
あなたを合格させるIBM C1000-018試験専門問題集はここにある:https://www.jpntest.com/shiken/C1000-018-mondaishu