Q: 1
How can you configure a log source to provide events to different domains?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 2
What Iwo things are required for an administrator to deobfuscate data in QRadar?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 3
A ORadar administrator needs to upgrade the system to patch a vulnerability. In what order does the
administrator upgrade the managed hosts?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 4
Which two (2) data sources can be assigned to a domain in the Domain Management function?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 5
In the QRadar GUI. you notice that no new offenses were generated today. A review of the
notifications shows:
MPC: Unable to create new offense. The maximum number of active offenses has been reached.
What is the default value of the maximum number?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 6
Which field is mandatory when you use the DSM Editor to map an event to a OID?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 7
You are using the command line interface (CLI) and need to fix a storage issue. What command do
you use to verify disk usage levels?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 8
From which site can you download software updates for QRadar?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 9
You want to use a quick filter search to look for certain elements:
. 10.100.100.*
• BlueCoat
• TCP_REFRESH_MIS
Which string provides the correct results?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Question 1 of 20 · Page 1 / 2