IBM Security QRadar SIEM V7.5 Deployment - C1000-163 模擬練習

Consider this scenario and instruction.
Vulnerability assessment products launch attacks that can result in offense creation. To avoid this behavior and define vulnerability assessment products or any server that you want to ignore as a source, edit the "and when the source IP is one of the following" test to include the IP addresses of the following scanners.
- VA Scanners
- Authorized Scanners
What type of editable building block is described?

正解: D
Which utility is used for checking the integrity of event and flow logs?

正解: D
After working on a QRadar Support case, a set of logs is needed for further review.
Where is the script to gather those logs in case you have no UI access?

正解: D
Which two types of default building blocks do you need to edit to reduce the number of offenses that are generated by high volume traffic servers?

正解: A,E
What is the directory where a backup archive file needs to be placed so that QRadar can automatically import it?

正解: D
An analyst views a dashboard in Pulse, which is not working as expected.
Which aggregation type should be selected to ensure the correct configuration for a Pie Chart?

正解: B
Which two options does a QRadar analyst need to configure in the False Positive window of the QRadar Console to mark an event or flow as False Positive?

正解: C
Where are audit logs located?

正解: B
Which data is processed by the IBM Security QRadar Network Threat Analytics app?

正解: C
What is the minimum bandwidth required between the primary and the secondary nodes of a HA cluster?

正解: D
What is an approach to tuning a "noisy" rule, that is, a rule that generates too many offenses?

正解: D
At the Offense Summary window, the first row of data shows the level of importance that QRadar assigned to the offense.
Which statement is the correct description for Magnitude?

正解: C
Which port is used for bidirectional traffic between WinCollect agent and QRadar Console?

正解: A
All appliances must be on the same version and patch level prior to an upgrade.
How are the patch levels verified for all systems in a deployment?

正解: A
Which script can detemine which QRadar process is consuming the most resources?

正解: A