Free C1000-162 sample questions
Real questions from the IBM Security QRadar SIEM V7.5 Administration practice bank, with the correct answer and an explanation for each one. No junk, no filler.
Try them in the simulator Same questions, with study, timed and flashcard modes.
Showing 10 of 20 free sample questions.
A threat hunter is using an AQL query to find evidence of a slow data exfiltration attempt where small amounts of data were sent to multiple external IP addresses over a long period. The current query is returning too many results and timing out. Which TWO of the following AQL query modifications would most effectively optimize the search and narrow the results to the most relevant indicators? (Select TWO)
While analyzing an offense, a security analyst needs to quickly determine if an IP address flagged as a source of malicious activity is part of a known botnet. Which QRadar feature provides the most direct and context-rich method for this investigation?
A new log source for a custom in-house application is sending events to QRadar, but they are all appearing as 'Unknown'. The application logs contain a unique 'transactionID' field that is critical for correlating user activity. The security team has recommended creating a custom event property to extract this ID. After the custom property is created and deployed, what is the immediate next step an analyst should take to make this field usable in searches and rules?
True or False: The primary purpose of a Building Block in QRadar is to trigger an offense and generate a notification when its conditions are met.
A security analyst is building a report to show the top 10 internal hosts that have communicated with countries on a 'High-Risk Geo-Locations' reference set over the past 30 days. Which QRadar feature is essential for creating this report?
A hospital's security team is trying to reduce the number of false positive offenses generated by a rule that detects 'Multiple Login Failures from Dormant Account'. The rule correctly identifies login failures but often triggers on accounts that are not truly dormant, such as those used by on-call staff who log in infrequently. What is the most effective way to tune this rule to improve its accuracy?
An analyst wants to create a QRadar Pulse dashboard that provides an at-a-glance view of all active offenses, color-coded by magnitude, and a real-time chart of event rates from critical servers. Which Pulse dashboard items would be most appropriate to build this view? (Select TWO)
A junior analyst is investigating an offense and notices that several contributing events are labeled as 'Stored'. What does this indicate about those events?
An analyst is using the Log Activity tab to investigate a potential malware infection on a user's workstation. They need to find all events related to DNS queries for a specific suspicious domain, 'malicious-domain.com', that occurred in the last 24 hours. What is the most efficient way to perform this search using the quick filter bar?
10 more free samples are waiting
Create a free account to unlock the whole C1000-162 sample bank, or get full access to all 235 practice questions in the simulator.