最新的IBM QRadar SIEM V7.3.2 Fundamental Analysis - C1000-018免費考試真題

問題1
While creating a new custom property, which is a valid property types selection?

正確答案: B
問題2
An analyst is performing an investigation regarding an Offense. The analyst is uncertain to whom some of the external destination IP addresses in List of Events are registered.
How can the analyst verify to whom the IP addresses are registered?

正確答案: B
說明:(僅 VCESoft 成員可見)
問題3
An analyst is searching for a list of events that meet specific search criteria and wants to display only the source IP and destination IP information for the events.
To get the required information, the analyst can open the Log Activity tab and then:

正確答案: A
問題4
How does an analyst view which rule triggered an Offense in the Offense summary page?

正確答案: B
問題5
How would an analyst efficiently include all the Antivirus logs integrated with QRadar for the last 24 hours?

正確答案: D
問題6
An analyst noticed that from a particular subnet (203.0.113.0/24), all IP addresses are simultaneously trying to reach out to the company's publicly hosted FTP server.
The analyst also noticed that this activity has resulted in a Type B Superflow on the Network Activity tab-Under which category, should the analyst report this issue to the security administrator?

正確答案: C
說明:(僅 VCESoft 成員可見)