C1000-018問題集で2021年最新のIBM C1000-018試験問題 [Q30-Q46]

Share

C1000-018問題集で2021年最新のIBM C1000-018試験問題

無料で使えるC1000-018ブレーン問題集でダウンロード(C1000-018テスト問題集無料更新された)

質問 30
An analyst noticed that from a particular subnet (203.0.113.0/24), all IP addresses are simultaneously trying to reach out to the company's publicly hosted FTP server.
The analyst also noticed that this activity has resulted in a Type B Superflow on the Network Activity tab-Under which category, should the analyst report this issue to the security administrator?

  • A. Syn Flood
  • B. Network Scan
  • C. DDoS
  • D. Port Scan

正解: C

 

質問 31
What does the Assets tab provide?
A unified view of the information that is known about:

  • A. triggered Offenses.
  • B. network devices.
  • C. events and flows.
  • D. log sources.

正解: C

 

質問 32
The SOC team complained that they have can only see one Offense in the Offenses tab.
space of 10 minutes, but the analyst How can the analyst ensure only one email is sent in this circumstance?

  • A. Ensure that the Rule Action Limiter is configured the same way as the Rule Response Limiter.
  • B. Disable Automated Offense Notification - by email, in Advanced System Settings.
  • C. Add a Response Limiter to the Rule, configured to execute only once every 30 minutes.
  • D. Configure the postfix mail server on the Console to suppress duplicate items

正解: D

 

質問 33
An analyst is encountering a large number of false positive results. Legitimate internal network traffic contains valid flows and events which are making it difficult to identify true security incidents.
What can the analyst do to reduce these false positive indicators?

  • A. Filter the network traffic to receive only security related events.
  • B. Create X-Force rules to detect false positive events.
  • C. Create an anomaly rule to detect false positives and suppress the event.
  • D. Modify rules and/or Building Block to suppress false positive activity.

正解: A

 

質問 34
When an Offense is triggered, it only shows the events that triggered the Offense. The analyst wants to investigate further to see more events around the incident, not only those that triggered the Offense. The analyst clicks on the event count and sees the events belonging to the Offense.
How can the analyst processed to see a more detailed picture of what occurred?

  • A. Right-click and filter on the Destination IP.
  • B. Right-click on the destination IP, and choose More Options, then Raw Events.
  • C. Right-click on the source IP, and choose More Options, then Information, and then Search Events
  • D. Right-click on the source IP, and choose View in DSM Editor.

正解: C

 

質問 35
While creating a new custom property, which is a valid property types selection?

  • A. Flow Based
  • B. AQL Based
  • C. Regular Expressions Based
  • D. Event Based

正解: C

 

質問 36
An analyst has created a custom property from the events for searching for critical information. The analyst also needs to reduce the number of event logs and data volume that is searched when looking for the critical information to maintain the efficiency and performance of QRadar.
Which feature should the analyst use?

  • A. Event Management
  • B. Log Management
  • C. Index Management
  • D. Database Management

正解: A

 

質問 37
What is required to create an anomaly rule?

  • A. baseline anomalies
  • B. triggered flows
  • C. a grouped saved search
  • D. triggered events

正解: D

 

質問 38
What steps are needed to add an Annotation to an event or flow that triggered a Rule?

  • A. When creating a Rule, a custom Annotation can be automatically applied to events and flows that originate from specified Sources.
  • B. Events and Flows cannot be Annotated, the only information allowed in an event or flow is data that was included in the original payload.
  • C. When creating a Rule, a custom Annotation can be specified to automatically be applied to the event or flow that triggered the Rule.
  • D. Annotations can be manually added to an Offense. These Annotations are then automatically applied to all events or flows which triggered the rule creating that Offense.

正解: C

 

質問 39
From which tab in QRadar SIEM can an analyst search vulnerability data and remediate vulnerabilities?

  • A. Assets
  • B. Admin
  • C. Dashboard
  • D. Log Activity

正解: A

解説:
Explanation
When IBM Security QRadar Vulnerability Manager is enabled, you can perform vulnerability assessment tasks on the Vulnerabilities tab. From the Assets tab, you can run IBM Security QRadar Vulnerability Manager scans on selected assets.

 

質問 40
An analyst investigates an Offense that will need more research to outline what has occurred. The analyst marks a 'Follow up' flag on the Offense.
What happens to the Offense after it is tagged with a 'Follow up' flag?

  • A. Other analysts in QRadar get an email to look at the Offense.
  • B. A flag icon is displayed for the Offense in the Offense view.
  • C. Only the analyst issuing the follow up flag can now close the Offense.
  • D. New events or flows will not be applied to the Offense.

正解: B

解説:
Explanation
The offense now displays the follow-up icon in the Flag column.

 

質問 41
The Network Hierarchy is an important part of the system configuration. It can be used to tune out a large number of False Positive Offenses from the standard QRadar rules.
What is the Network Hierarchy?

  • A. The Network Hierarchy can be used in all Rules and is accessed from the False Positive button in the Network Activity Tab.
  • B. The Network Hierarchy can be used only in Flow Rules and is accessed from the False Positive button in the Network Activity Tab.
  • C. There are separate Network Hierarchies for Flow and Event Rules. They are accessed from the False Positive button in the corresponding Activity Tab.
  • D. The Network Hierarchy can be used in section of the Admin Tab. accessed from the System Configuration.

正解: C

 

質問 42
An analyst wants to analyze the long-term trending of data from a search.
Which chart would be used to display this data on a dashboard?

  • A. Scatter Chart
  • B. Bar Graph
  • C. Pie Chart
  • D. Time Series chart

正解: D

解説:
Explanation
Time series charts are graphical representations of your activity over time.
Peaks and valleys that are displayed in the charts depict high and low volume activity. Time series charts are useful for short-term and long term trending of data.
https://www.ibm.com/docs/en/qsip/7.4?topic=management-time-series-chart-overview

 

質問 43
To provide insight into why QRadar considers the event to be threatening, what does QRadar add to the Offense that users cannot edit or delete?

  • A. Source IP
  • B. Attack path
  • C. Annotations
  • D. Location

正解: C

解説:
Explanation
https://www.ibm.com/docs/en/qsip/7.4?topic=investigations-investigating-offense-by-using-summary-informatio Annotations provide insight into why QRadar considers the event or observed traffic to be threatening.
QRadar can add annotations when it adds events or flows to an offense. The oldest annotation shows information that QRadar added when the offense was created. Users cannot add, edit, or delete annotations.

 

質問 44
An analyst working with QRadar SIEM has been assigned a new Offense and is preparing a custom report on the Offense summary page. From this page, the analyst wants to navigate to the Log Activity or Network Activity page to export the Event/Flow data (Action -> export to CSV).
How can the analyst do this? (Choose two)

  • A. Click the Events / Flows icon.
  • B. Click the Summary icon.
  • C. In the Event/Flow count section, click the link to open the page.
  • D. In the Source IP(s) session, click the link to open the page.
  • E. Click the View Attack Path icon.

正解: C,D

 

質問 45
Which consideration should be given to the position of rule tests that evaluate regular expressions (Regex tests)?

  • A. They can only be used in Building Blocks to ensure they are evaluated as infrequently as possible.
  • B. They are usually the most specific. As such, they should appear first in the order.
  • C. They are usually the most expensive. As such, they should appear last in the order.
  • D. They are stateful tests. As such QRadar automatically evaluates them last.

正解: A

 

質問 46
......

検証済みのC1000-018問題集と解答で合格保証で試験問題集テストエンジン:https://www.jpntest.com/shiken/C1000-018-mondaishu

弊社を連絡する

我々は12時間以内ですべてのお問い合わせを答えます。

オンラインサポート時間:( UTC+9 ) 9:00-24:00
月曜日から土曜日まで

サポート:現在連絡