Black Friday Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70percent

IBM C1000-140 IBM Security QRadar SIEM V7.4.3 Deployment Exam Practice Test

Demo: 9 questions
Total 62 questions

IBM Security QRadar SIEM V7.4.3 Deployment Questions and Answers

Question 1

When adding a Data Node to an Event Processor, what are the minimum bandwidth and maximum latency requirements?

Options:

A.

1 Gbps link and 10 ms latency

B.

1 Gbps link and 100 ms latency

C.

10 Gbps link and 10 ms latency

D.

10 Gbps link and 100 ms latency

Question 2

On an App Host, to reload an SSL certificate, which service needs to be restarted?

Options:

A.

tomcat

B.

docker

C.

httpd

D.

ecs-ec-ingress

Question 3

In a multidomain and multitenant environment, how is event visibility provided to users?

Options:

A.

An event is in a domain, a domain is attached to a tenant, and a tenant is referenced in the security profile of the user.

B.

An event is allocated to a tenant, a tenant is attached to a domain, and a domain is referenced in the security profile of the user.

C.

An event is allocated to a tenant, and a tenant is referenced in the security profile of the user.

D.

An event is in a domain, and a domain is referenced in the security profile of the user.

Question 4

Which log file helps in QRadar troubleshooting?

Options:

A.

aql.log

B.

ariel-query.log

C.

sim-audit.log

D.

qradar.error

Question 5

Which industry standard security framework is incorporated into the QRadar 7.4.3 environment, which allows the QRadar deployment professional to link rules and building blocks to coverage in the framework?

Options:

A.

Lockheed Martin Cyber Kill Chain

B.

US DoD Diamond Model

C.

NIST Cybersecurity Framework

D.

MITRE ATT&CK

Question 6

A QRadar deployment professional designs a multi-tenant environment where each tenant is permitted a quantity of events per second (EPS).

In a discussion with the service provider (who provides the security monitoring services to each tenant), how should the deployment professional describe the licensing options available?

Options:

A.

Per-tenant EPS limits can be set, but any events over the EPS will be dropped from the pipeline; over-license buffering will not be used to handle EPS spikes.

B.

Per-tenant EPS limits can be set if the tenants are defined by event collectors. Then over-license buffering can be used to handle EPS spikes.

C.

If each domain and tenant is defined by log source groups, the EPS limit can be shared by the log source groups used for each tenant. Over-license buffering is defined at the event collector.

D.

The domain sets EPS limits, so each tenant needs to have only one domain. This way, over-license buffering can be used to handle EPS spikes.

Question 7

Which statement is valid about the SAML authentication feature?

Options:

A.

Users enter local credentials every time they access QRadar.

B.

You cannot use the x509 certificate, only the provided QRadar_SAML certificate.

C.

You can integrate QRadar with your corporate identity server to provide single sign-on.

D.

Authentication is exchanged by using digitally signed HTML documents.

Question 8

A QRadar deployment professional is asked to migrate the configuration of a system from Log Manager to QRadar SIEM.

How should the custom rules, saved searches, and reports be migrated?

Options:

A.

Use the QRadar config backup and restore process to transfer all configurations.

B.

Use the content management tool (CMT) to transfer the security configuration.

C.

The only option is to use the GUI to manually recreate any required content.

D.

Use rsync to transfer the contents of the /store partition to the new system.

Question 9

Where can a deployment professional find updates to DSMs?

Options:

A.

Fix Central

B.

The QRadar Admin console

C.

The Log Source Management app

D.

QRadar on Cloud website

Demo: 9 questions
Total 62 questions