Free IBM C1000-018 Exam Questions (page: 4)

A new analyst is tasked to identify potential false positive Offenses, then send details of those Offenses to the Security Operations Center (SOC) manager for review by using the send email notification feature.

  1. Total number of sources, top five categories, total number of destinations. Contributing CRE rules total number of packets.
  2. Total number of sources, top five sources by magnitude, total number of destinations, destination networks, total number of packets.
  3. Total number of sources, top five sources by magnitude, total number of destinations, destination networks, total number of events.
  4. Total number of sources, top five number of categories, total number of destinations, destination networks, total number of packets.

Answer(s): D



What is the reason for this system notification?
"Time synchronization to primary or Console has failed"

  1. Deny ntpdate communication on port 423.
  2. Deny ntpdate communication on port 223.
  3. Deny ntpdate communication on port 323.
  4. Deny ntpdate communication on port 123

Answer(s): D

Explanation:

38750129 - Time synchronization to primary or Console has failed.
The managed host cannot synchronize with the console or the secondary HA appliance cannotsynchronize with the primary appliance.
Administrators must allow ntpdatecommunication on port 123.


Reference:

https://www.coursehero.com/file/p35nlom9/Process-exceeds-allowed-run-time-38750122-Process-takes-too-long-to-execute-The/



From which tab in QRadar SIEM can an analyst search vulnerability data and remediate vulnerabilities?

  1. Log Activity
  2. Admin
  3. Dashboard
  4. Assets

Answer(s): D

Explanation:

When IBM Security QRadar Vulnerability Manager is enabled, you can perform vulnerability assessment tasks on the Vulnerabilities tab. From the Assets tab, you can run IBM Security QRadar Vulnerability Manager scans on selected assets.


Reference:

http://www.siem.su/docs/ibm/Administration_and_introduction/User_Guide.pdf



Which component in QRadar collects and creates flow information?

  1. sflow
  2. NetFIow
  3. Qflow
  4. J-Flow

Answer(s): C


Reference:

https://www.ibm.com/support/pages/qradar-about-flows-and-difference-between-qflow-collector-and-qradar-event-collector






Post your Comments and Discuss IBM C1000-018 exam prep with other Community members:

C1000-018 Exam Discussions & Posts