Question 6 of 60

Which event routing rule is required to add QRadar Data Store (QDS) capability to a deployment?

Answer

Suggested Answer

The suggested answer is A.

Reference:
https://www.ibm.com/support/knowledgecenter/en/SS42VS_7.3.2/com.ibm.qradar.doc/t_qradar_adm_data_store.html
Question 7 of 60

An administrator is seeing the following system notification:

38750057 `" A protocol source configuration may be stopping events from being collected.What is a valid user action to this issue?

Answer

Suggested Answer

The suggested answer is D.

Reference:
https://www.ibm.com/support/knowledgecenter/en/SS42VS_7.3.0/com.ibm.qradar.doc/38750057.html
Question 8 of 60

An administrator needs to import a list of HR staff logins into a reference set.

Which file type can be used with the import function in the reference set editor window?

Answer

Suggested Answer

The suggested answer is B.

Reference:
https://www.ibm.com/support/knowledgecenter/en/SS42VS_7.3.2/com.ibm.qradar.doc/c_qradar_adm_refdata_ui.html
Question 9 of 60

An administrator is about to integrate logs from a custom firewall in a QRadar deployment using syslog. The SIEM has two domains, namely Domain A and

Domain B. While reviewing the following sample logs, the administrator notices a `context` keyword:

May 14 11:05:01 192.168.1.23 20190514 11:05:00 context=contextA permit 192.168.1.24 source: 10.10.1.15; source_port: 64094; destination: 10.10.13.34; service: 53; protocol: udp;

May 13 12:07:01 192.168.1.23 20190513 11:07:00 context=contextB permit 192.168.1.25 source: 10.10.1.15; source_port: 64094; destination: 10.10.13.34; service: 53; protocol: udp;

Which options assign the `contextA` logs to DomainA and the `contextB` logs to domain B? (Choose two.)

Answer

Suggested Answer

The suggested answer is B, D.

Question 10 of 60

An administrator plans to deploy multiple log sources that share a common configuration.

How many log sources can be added at one time?

Answer

Suggested Answer

The suggested answer is D.

Reference:
https://www.ibm.com/support/knowledgecenter/SS42VS_DSM/com.ibm.dsm.doc/t_logsource_bulkadd.html