Free C1000-140 Exam Braindumps (page: 3)

Page 2 of 16

Which item can be used in the configuration of a domain in QRadar?

  1. The tenant that owns the log source that the event is allocated to
  2. The network the event comes from
  3. A custom event property in an event
  4. The type of the log source that the event is allocated to

Answer(s): A



What approach does QRadar take when it imposes EPS license (not hardware) limits on events that temporarily spike above that limit?

  1. Excessive events in a spike cause a System Notification that advises the customer to increase their EPS license allocation.
  2. QRadar EPS license allocation is implemented with a hard cutoff to ensure resources are not saturated.
  3. During the spike, excess events are written to a queue, and they are processed after the EPS rate drops.
  4. QRadar EPS licensing is measured as an average over a 24-hour period, which allows spikes to be handled gracefully.

Answer(s): D



What is an approach to tuning a "noisy" rule, that is, a rule that generates too many offenses?

  1. Determine whether the rule matches too many conditions in the traffic.
  2. In the offense output, scroll down and review the "Excessive" flags.
  3. Confirm that the rule is enabled.
  4. Use the QRadar Pulse app to map noisy offense output.

Answer(s): A



Which of these statements is true about network objects?

  1. A network object can have multiple CIDR ranges assigned to it.
  2. A network object must have at least one CIDR range per QRadar domain.
  3. A network object represents a single asset that is connected to a network.
  4. A network object is a group of assets that are connected to a network.

Answer(s): C






Post your Comments and Discuss IBM C1000-140 exam with other Community members:

C1000-140 Discussions & Posts